Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SNDAMicroGameHelper] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\DWeather 天气预报服务] 'Start' = '00000002'
- '%PROGRAM_FILES%\DWeather\Microgame_Setup.exe' /S
- '<LS_APPDATA>\Microgame\sdGamePush.exe' /stopservice
- '%PROGRAM_FILES%\DWeather\dwthsvc.exe'
- '%PROGRAM_FILES%\DWeather\dwthsvc.exe' -i
- '%PROGRAM_FILES%\DWeather\dwthsvc.exe' -s
- '<SYSTEM32>\svchost.exe' -k SNDAMicroGameHelper
- '<SYSTEM32>\regsvr32.exe' /s "<LS_APPDATA>\Microgame\SNDAMicroGameHelper.dll"
- '<SYSTEM32>\regsvr32.exe' /u /s "<LS_APPDATA>\Microgame\SNDAMicroGameHelper.dll"
- <LS_APPDATA>\Microgame\SNDAMicroGameHelper.dll
- <LS_APPDATA>\Microgame\sdGamePush.exe
- %TEMP%\nsk6.tmp\System.dll
- %PROGRAM_FILES%\DWeather\uninst.exe
- <LS_APPDATA>\Microgame\uninst.exe
- <LS_APPDATA>\Microgame\cfg.ini
- %PROGRAM_FILES%\DWeather\dwthsvc.exe
- %TEMP%\nso3.tmp\System.dll
- %TEMP%\nst2.tmp
- %TEMP%\nsf5.tmp
- %PROGRAM_FILES%\DWeather\Microgame_Setup.exe
- %PROGRAM_FILES%\DWeather\dwthsvc.log
- %TEMP%\nso3.tmp\System.dll
- %PROGRAM_FILES%\DWeather\Microgame_Setup.exe
- %TEMP%\nsk6.tmp\System.dll
- 'www.ku##zip.com':80
- www.ku##zip.com/microgame/config.txt
- DNS ASK www.ku##zip.com