Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] 'AppInit_DLLs' = '%PROGRAM_FILES%\bandoo\bndhook.dll '
- [<HKLM>\SYSTEM\ControlSet001\Services\Bandoo Coordinator] 'Start' = '00000002'
- %PROGRAM_FILES%\Bandoo\BndCore.exe -Embedding /RegServer
- %PROGRAM_FILES%\Bandoo\Bandoo.exe /Start /Service
- %TEMP%\GLJ2.tmp %PROGRAM_FILES%\Bandoo\CrashRpt.dll %PROGRAM_FILES%\Bandoo\Plugins\IE\ieplugin.dll %PROGRAM_FILES%\Bandoo\GIFAnimator.dll %PROGRAM_FILES%\Bandoo\FlashAnimator.dll
- %TEMP%\BandooFiles\files.exe "-o%TEMP%\BandooFiles" -y
- %PROGRAM_FILES%\Bandoo\BandooUI.exe cookie http://ba##oo.com
- [<HKLM>\Software\Yahoo\pager]
- [<HKLM>\SOFTWARE\Microsoft\MSNMessenger]
- %PROGRAM_FILES%\Bandoo\~GLH0010.TMP
- %PROGRAM_FILES%\Bandoo\~GLH000f.TMP
- %PROGRAM_FILES%\Bandoo\~GLH0011.TMP
- %PROGRAM_FILES%\Bandoo\~GLH0013.TMP
- %ALLUSERSPROFILE%\Application Data\Bandoo\~GLH0012.TMP
- %PROGRAM_FILES%\Bandoo\~GLH000b.TMP
- %PROGRAM_FILES%\Bandoo\~GLH000a.TMP
- %PROGRAM_FILES%\Bandoo\~GLH000c.TMP
- %PROGRAM_FILES%\Bandoo\~GLH000e.TMP
- %PROGRAM_FILES%\Bandoo\~GLH000d.TMP
- %PROGRAM_FILES%\Bandoo\Resources\~GLH001a.TMP
- %PROGRAM_FILES%\Bandoo\Resources\~GLH0019.TMP
- %PROGRAM_FILES%\Bandoo\Resources\~GLH001b.TMP
- %PROGRAM_FILES%\Bandoo\Resources\~GLH001d.TMP
- %PROGRAM_FILES%\Bandoo\Resources\~GLH001c.TMP
- %PROGRAM_FILES%\Bandoo\~GLH0015.TMP
- %PROGRAM_FILES%\Bandoo\~GLH0014.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\MSN\~GLH0016.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\IE\~GLH0018.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\Yahoo\~GLH0017.TMP
- %PROGRAM_FILES%\Bandoo\~GLH0009.TMP
- %TEMP%\BandooFiles\Static\libungif4.dll
- %TEMP%\BandooFiles\Bin\InstallerHelper.dll
- %TEMP%\BandooFiles\Bin\msnplugin.dll
- %TEMP%\BandooFiles\Bin\Resources.dll
- %TEMP%\BandooFiles\Bin\OEPlugin.dll
- %TEMP%\BandooFiles\Bin\CrashRpt.dll
- %TEMP%\BandooFiles\Bin\BndHook.dll
- %TEMP%\BandooFiles\Bin\FlashAnimator.dll
- %TEMP%\BandooFiles\Bin\ieplugin.dll
- %TEMP%\BandooFiles\Bin\GIFAnimator.dll
- %PROGRAM_FILES%\Bandoo\~GLH0005.TMP
- %PROGRAM_FILES%\Bandoo\~GLH0006.TMP
- %PROGRAM_FILES%\Bandoo\~GLH0008.TMP
- %PROGRAM_FILES%\Bandoo\~GLH0007.TMP
- %TEMP%\BandooFiles\Bin\YahooPlugin.dll
- %TEMP%\BandooFiles\Static\uitools.dll
- %TEMP%\~GLH0002.TMP
- %PROGRAM_FILES%\Bandoo\~GLH0004.TMP
- <SYSTEM32>\~GLH0003.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\Yahoo\Resources\Toolbar\Images\~GLH0039.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\Yahoo\Resources\Toolbar\Images\~GLH0038.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\Yahoo\Resources\Toolbar\Images\~GLH003a.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\MSN\Resources\HTML\~GLH003c.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\MSN\Resources\HTML\~GLH003b.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\Yahoo\Resources\Toolbar\Images\~GLH0034.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\Yahoo\Resources\Toolbar\Images\~GLH0033.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\Yahoo\Resources\Toolbar\Images\~GLH0035.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\Yahoo\Resources\Toolbar\Images\~GLH0037.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\Yahoo\Resources\Toolbar\Images\~GLH0036.TMP
- %ALLUSERSPROFILE%\Start Menu\Programs\Bandoo\Bandoo Extensions.lnk
- %ALLUSERSPROFILE%\Start Menu\Programs\Bandoo\License Agreement.lnk
- %ALLUSERSPROFILE%\Application Data\Bandoo\config.xml
- %ALLUSERSPROFILE%\Application Data\Bandoo\CrashReportInfo.xml
- %ALLUSERSPROFILE%\Application Data\Bandoo\WPSubsystems.xml
- %PROGRAM_FILES%\Bandoo\Plugins\Yahoo\Resources\HTML\~GLH003e.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\Yahoo\Resources\HTML\~GLH003d.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\IE\Resources\~GLH003f.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\IE\Resources\HTML\~GLH0041.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\IE\Resources\HTML\~GLH0040.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\Yahoo\Resources\Toolbar\Images\~GLH0032.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\MSN\Resources\Toolbar\Images\~GLH0024.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\MSN\Resources\Toolbar\Images\~GLH0023.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\MSN\Resources\Toolbar\Images\~GLH0025.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\MSN\Resources\Toolbar\Images\~GLH0027.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\MSN\Resources\Toolbar\Images\~GLH0026.TMP
- %PROGRAM_FILES%\Bandoo\Resources\~GLH001f.TMP
- %PROGRAM_FILES%\Bandoo\Resources\~GLH001e.TMP
- %PROGRAM_FILES%\Bandoo\Resources\~GLH0020.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\MSN\Resources\Toolbar\Images\~GLH0022.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\MSN\Resources\Toolbar\~GLH0021.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\Yahoo\Resources\Toolbar\Images\~GLH002e.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\Yahoo\Resources\Toolbar\~GLH002d.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\Yahoo\Resources\Toolbar\Images\~GLH002f.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\Yahoo\Resources\Toolbar\Images\~GLH0031.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\Yahoo\Resources\Toolbar\Images\~GLH0030.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\MSN\Resources\Toolbar\Images\~GLH0029.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\MSN\Resources\Toolbar\Images\~GLH0028.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\MSN\Resources\Toolbar\Images\~GLH002a.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\Yahoo\Resources\Toolbar\~GLH002c.TMP
- %PROGRAM_FILES%\Bandoo\Plugins\MSN\Resources\Toolbar\Images\~GLH002b.TMP
- %TEMP%\BandooFiles\Bin\resources\searchplugins\WebSearch.xml
- %TEMP%\BandooFiles\Bin\resources\plugins\Yahoo\Toolbar\BandooToolbarV9.xml
- %TEMP%\BandooFiles\Static\WPSubsystems.xml
- %TEMP%\BandooFiles\Bin\resources\plugins\MSN\HTML\blank.html
- %TEMP%\BandooFiles\Bin\resources\plugins\IE\HTML\blank.html
- %TEMP%\BandooFiles\Bin\resources\BandooMessages.xml
- %TEMP%\BandooFiles\Bin\resources\plugins\OE\images\wink_play.jpg
- %TEMP%\BandooFiles\Bin\resources\plugins\MSN\Toolbar\BandooToolbar.xml
- %TEMP%\BandooFiles\Bin\resources\plugins\OE\Toolbar\BandooToolbar.xml
- %TEMP%\BandooFiles\Bin\resources\plugins\Yahoo\Toolbar\BandooToolbar.xml
- %TEMP%\BandooFiles\Bin\resources\tutorial\tutorial.html
- %TEMP%\BandooFiles\Bin\resources\plugins\Yahoo\HTML\error.html
- %TEMP%\BandooFiles\Bin\resources\plugins\IE\bandoo.js
- %TEMP%\BandooFiles\Static\licenseBandoo.rtf
- %TEMP%\BandooFiles\Bin\resources\Plugins.ini
- %TEMP%\BandooFiles\Bin\resources\plugins\Yahoo\HTML\blank.html
- %TEMP%\BandooFiles\Bin\resources\plugins\OE\HTML\blank.html
- %TEMP%\BandooFiles\Bin\resources\plugins\IE\HTML\error.html
- %TEMP%\BandooFiles\Bin\resources\plugins\OE\HTML\error.html
- %TEMP%\BandooFiles\Bin\resources\plugins\MSN\HTML\error.html
- %TEMP%\BandooFiles\Bin\resources\tutorial\images\screen.jpg
- %TEMP%\BandooFiles\Bin\resources\nudge0.wav
- %TEMP%\BandooFiles\~GLH0001.TMP
- %TEMP%\BandooFiles\Bin\resources\nudge1.wav
- %TEMP%\BandooFiles\Bin\resources\nudge3.wav
- %TEMP%\BandooFiles\Bin\resources\nudge2.wav
- %TEMP%\GLJ2.tmp
- %TEMP%\GLC1.tmp
- %TEMP%\GLK3.tmp
- %TEMP%\~GLH0000.TMP
- %TEMP%\GLG5.tmp
- %TEMP%\BandooFiles\Bin\resources\downloadingBandoo.gif
- %TEMP%\BandooFiles\Bin\resources\tutorial\images\contentBg.gif
- %TEMP%\BandooFiles\Bin\resources\tutorial\images\Bandoo\startMenuTopText.gif
- %TEMP%\BandooFiles\Bin\resources\tutorial\images\what_next.gif
- %TEMP%\BandooFiles\Bin\resources\tutorial\images\topBg.gif
- %TEMP%\BandooFiles\Bin\resources\nudge5.wav
- %TEMP%\BandooFiles\Bin\resources\nudge4.wav
- %TEMP%\BandooFiles\Bin\resources\tutorial\images\Bandoo\installation_page_frame.swf
- %TEMP%\BandooFiles\Bin\resources\tutorial\images\close.gif
- %TEMP%\BandooFiles\Bin\resources\tutorial\images\bottomBg.gif
- %TEMP%\BandooFiles\Bin\resources\plugins\Yahoo\Toolbar\Images\1054.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\Yahoo\Toolbar\Images\1053.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\Yahoo\Toolbar\Images\1055.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\Yahoo\Toolbar\Images\1057.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\Yahoo\Toolbar\Images\1056.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\OE\Toolbar\Images\1014.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\MSN\Toolbar\Images\1013.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\MSN\Toolbar\Images\1014.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\Yahoo\Toolbar\Images\1052.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\Yahoo\Toolbar\Images\1051.dat
- %TEMP%\BandooFiles\Bin\FFoxPackage.exe
- %TEMP%\BandooFiles\Bin\ExtensionsManager.exe
- %TEMP%\BandooFiles\Static\FFSettings.exe
- %TEMP%\BandooFiles\Bin\BandooLmx.dll
- %TEMP%\BandooFiles\Bin\PreUninstall.exe
- %TEMP%\BandooFiles\Bin\Bandoo.exe
- %TEMP%\BandooFiles\Bin\resources\searchplugins\WebSearch.src
- %TEMP%\BandooFiles\Bin\BandooGo.exe
- %TEMP%\BandooFiles\Bin\BndCore.exe
- %TEMP%\BandooFiles\Bin\BandooUI.exe
- %TEMP%\BandooFiles\Bin\resources\plugins\OE\Toolbar\Images\1013.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\Yahoo\Toolbar\Images\1003.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\MSN\Toolbar\Images\1002.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\OE\Toolbar\Images\1003.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\Yahoo\Toolbar\Images\1004.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\MSN\Toolbar\Images\1003.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\OE\Toolbar\Images\1001.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\Yahoo\Toolbar\Images\1001.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\MSN\Toolbar\Images\1001.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\OE\Toolbar\Images\1002.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\Yahoo\Toolbar\Images\1002.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\OE\Toolbar\Images\1011.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\MSN\Toolbar\Images\1006Bandoo.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\MSN\Toolbar\Images\1011.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\MSN\Toolbar\Images\1012.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\OE\Toolbar\Images\1012.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\Yahoo\Toolbar\Images\1005.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\MSN\Toolbar\Images\1004.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\MSN\Toolbar\Images\1005.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\OE\Toolbar\Images\1006Bandoo.dat
- %TEMP%\BandooFiles\Bin\resources\plugins\Yahoo\Toolbar\Images\1006.dat
- 'se####e.bandoo.com':80
- se####e.bandoo.com/install_statistics.php?ve#####################################################################################################################################
- DNS ASK se####e.bandoo.com
- '<IP-адрес в локальной сети>':1034
- ClassName: 'Shell_TrayWnd' WindowName: ''