Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'BeeWeather' = '"%PROGRAM_FILES%\BeeWeather13062718\BeeWeather.exe" -system'
- '%PROGRAM_FILES%\BeeWeather13062718\BeeWeather.exe' -install
- '%TEMP%\is-6B4ML.tmp\Х¬ДРУ°Тф_91_5869_.tmp' /SL5="$100E2,841445,72192,C:\Х¬ДРУ°Тф_91_5869_.exe"
- 'C:\Х¬ДРУ°Тф_91_5869_.exe'
- %PROGRAM_FILES%\BeeWeather13062718\Images\future\is-TF76N.tmp
- %PROGRAM_FILES%\BeeWeather13062718\Images\large\is-CD29G.tmp
- %PROGRAM_FILES%\BeeWeather13062718\Images\small\is-2E6VL.tmp
- %PROGRAM_FILES%\BeeWeather13062718\is-K0KI0.tmp
- %PROGRAM_FILES%\BeeWeather13062718\is-EUN3A.tmp
- %PROGRAM_FILES%\BeeWeather13062718\is-TUU1G.tmp
- %PROGRAM_FILES%\BeeWeather13062718\is-26F4N.tmp
- %ALLUSERSPROFILE%\Desktop\BeeWeather.lnk
- %PROGRAM_FILES%\BeeWeather13062718\unins000.msg
- %PROGRAM_FILES%\BeeWeather13062718\unins000.dat
- %ALLUSERSPROFILE%\Start Menu\Programs\BeeWeather\4472ѕшЙ«µзУ°Нш.url
- %ALLUSERSPROFILE%\Start Menu\Programs\BeeWeather\BeeWeather НшХѕ.url
- %ALLUSERSPROFILE%\Start Menu\Programs\BeeWeather\BeeWeather.lnk
- %ALLUSERSPROFILE%\Start Menu\Programs\BeeWeather\ЕдЦГ\Р¶ФШ BeeWeather.lnk
- %TEMP%\is-NH6JH.tmp\_isetup\_iscrypt.dll
- %TEMP%\is-NH6JH.tmp\WaterLib.dll
- %TEMP%\is-NH6JH.tmp\UpdateIcon.dll
- %TEMP%\is-NH6JH.tmp\_isetup\_shfoldr.dll
- C:\Х¬ДРУ°Тф_91_5869_.exe
- %TEMP%\is-6B4ML.tmp\Х¬ДРУ°Тф_91_5869_.tmp
- %TEMP%\is-NH6JH.tmp\_isetup\_RegDLL.tmp
- %HOMEPATH%\Desktop\ѕшЙ«µзУ°.lnk
- %APPDATA%\Sogou.ico
- %HOMEPATH%\Desktop\Internet Sogou.lnk
- %APPDATA%\ѕшЙ«µзУ°.ico
- %TEMP%\is-NH6JH.tmp\License.txt
- %TEMP%\is-NH6JH.tmp\Unis.ico
- %TEMP%\is-6B4ML.tmp\RCX1.tmp
- %TEMP%\is-NH6JH.tmp\_isetup\_iscrypt.dll
- %TEMP%\is-NH6JH.tmp\WaterLib.dll
- %TEMP%\is-NH6JH.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-NH6JH.tmp\_isetup\_RegDLL.tmp
- %TEMP%\is-NH6JH.tmp\UpdateIcon.dll
- %PROGRAM_FILES%\BeeWeather13062718\BeeWeather.exe
- %TEMP%\is-6B4ML.tmp\Х¬ДРУ°Тф_91_5869_.tmp
- %TEMP%\is-NH6JH.tmp\Unis.ico
- %TEMP%\is-NH6JH.tmp\License.txt
- from %PROGRAM_FILES%\BeeWeather13062718\Images\future\is-TF76N.tmp to %PROGRAM_FILES%\BeeWeather13062718\Images\future\n99.png
- from %PROGRAM_FILES%\BeeWeather13062718\is-K0KI0.tmp to %PROGRAM_FILES%\BeeWeather13062718\BeeWeather.exe
- from %PROGRAM_FILES%\BeeWeather13062718\Images\small\is-2E6VL.tmp to %PROGRAM_FILES%\BeeWeather13062718\Images\small\n99.png
- from %PROGRAM_FILES%\BeeWeather13062718\Images\large\is-CD29G.tmp to %PROGRAM_FILES%\BeeWeather13062718\Images\large\n99.png
- from %PROGRAM_FILES%\BeeWeather13062718\is-26F4N.tmp to %PROGRAM_FILES%\BeeWeather13062718\BeeWeather.exe
- from %TEMP%\is-6B4ML.tmp\RCX1.tmp to %TEMP%\is-6B4ML.tmp\Х¬ДРУ°Тф_91_5869_.tmp
- from %TEMP%\is-6B4ML.tmp\Х¬ДРУ°Тф_91_5869_.tmp to %TEMP%\is-6B4ML.tmp\Х¬ДРУ°Тф_91_5869_.tmp.tmp
- from %PROGRAM_FILES%\BeeWeather13062718\is-TUU1G.tmp to %PROGRAM_FILES%\BeeWeather13062718\WaterLib.dll
- from %PROGRAM_FILES%\BeeWeather13062718\is-EUN3A.tmp to %PROGRAM_FILES%\BeeWeather13062718\unins000.exe
- 'localhost':1087
- 'localhost':1088
- 'localhost':1085
- 'localhost':1086
- 'localhost':1091
- 'localhost':1092
- 'localhost':1089
- 'localhost':1090
- 'localhost':1079
- 'localhost':1080
- 'localhost':1077
- 'localhost':1078
- 'localhost':1083
- 'localhost':1084
- 'localhost':1081
- 'localhost':1082
- 'localhost':1093
- 'localhost':1104
- 'localhost':1105
- 'localhost':1102
- 'localhost':1103
- 'localhost':1108
- 'localhost':1109
- 'localhost':1106
- 'localhost':1107
- 'localhost':1096
- 'localhost':1097
- 'localhost':1094
- 'localhost':1095
- 'localhost':1100
- 'localhost':1101
- 'localhost':1098
- 'localhost':1099
- 'be#####unt.43994.com':80
- 'localhost':1055
- 'localhost':1051
- 'localhost':1052
- 'localhost':1058
- 'localhost':1059
- 'localhost':1056
- 'localhost':1057
- 'localhost':1039
- 'localhost':1040
- 'localhost':1036
- 'pp#.#3994.com':80
- 'sp#.#ianqi.com':80
- 'localhost':1048
- 'im#.#sers.51.la':80
- 'localhost':1043
- 'localhost':1060
- 'localhost':1071
- 'localhost':1072
- 'localhost':1069
- 'localhost':1070
- 'localhost':1075
- 'localhost':1076
- 'localhost':1073
- 'localhost':1074
- 'localhost':1063
- 'localhost':1064
- 'localhost':1061
- 'localhost':1062
- 'localhost':1067
- 'localhost':1068
- 'localhost':1065
- 'localhost':1066
- pp#.#3994.com/applist/Version183.php
- pp#.#3994.com/applist/Update.xml
- sp#.#ianqi.com/index.php?c=#################
- pp#.#3994.com/applist/index183.php
- im#.#sers.51.la/15738692.asp
- DNS ASK sp#.#ianqi.com
- DNS ASK be#####unt.43994.com
- DNS ASK pp#.#3994.com
- DNS ASK im#.#sers.51.la
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'Progman' WindowName: 'Program Manager'
- ClassName: 'TNewButton' WindowName: '????(&F)'
- ClassName: 'TWizardForm' WindowName: '???????? - BeeWeather'
- ClassName: 'TNewButton' WindowName: '??????(&N) >'