Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\bandac] 'ImagePath' = '%APPDATA%\135296\bandac.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\bandac] 'Start' = '00000002'
- '%APPDATA%\135296\bandac.exe' -i
- '%APPDATA%\135296\bandac.exe'
- '%APPDATA%\135296\RLServiceB.exe' BootDoThings
- '%TEMP%\is-TVG3T.tmp\<File name>.tmp' /SL5="$30092,1080013,56832,<Full path to file>"
- '%APPDATA%\135296\awdec.exe' <Full path to file>
- '%APPDATA%\135296\bandac.exe' -u
- '<SYSTEM32>\net.exe' start bandac
- '<SYSTEM32>\net1.exe' start bandac
- '<SYSTEM32>\regsvr32.exe' /s "%APPDATA%\135296\DataView.dll"
- '<SYSTEM32>\regsvr32.exe' /s "%APPDATA%\135296\DataView64.dll"
- %APPDATA%\135296\resource\is-JC28M.tmp
- %APPDATA%\135296\resource\is-CH68S.tmp
- %APPDATA%\135296\resource\is-28GD5.tmp
- %APPDATA%\135296\resource\is-B22DM.tmp
- %APPDATA%\135296\resource\is-M5EDU.tmp
- %APPDATA%\135296\resource\is-S5AI6.tmp
- %APPDATA%\135296\resource\is-ABQ80.tmp
- %APPDATA%\135296\resource\is-1S5QU.tmp
- %APPDATA%\135296\resource\is-O6S2G.tmp
- %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\_metadata\is-LT01M.tmp
- %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\_metadata\is-2QVMI.tmp
- %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\_locales\en\is-BNNNK.tmp
- %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\_locales\zh_CN\is-EIOGO.tmp
- %APPDATA%\135296\resource\is-0699H.tmp
- %APPDATA%\135296\resource\is-GTS0Q.tmp
- %APPDATA%\135296\resource\is-BF80A.tmp
- %APPDATA%\135296\resource\is-TLBNA.tmp
- %APPDATA%\135296\resource\is-79L1K.tmp
- %APPDATA%\135296\xmlconfig\is-0PH4I.tmp
- %APPDATA%\135296\xmlconfig\is-UD65O.tmp
- %APPDATA%\135296\resource\DirectUI\is-MQP7J.tmp
- %APPDATA%\135296\resource\DirectUI\is-I4HVC.tmp
- %ALLUSERSPROFILE%\Desktop\јтФјИХАъ.lnk
- %TEMP%\2e69d\mainClient.exe
- %APPDATA%\135296\is-CKLFT.tmp
- %APPDATA%\135296\is-508O0.tmp
- %APPDATA%\135296\resource\DirectUI\is-5FB4M.tmp
- %APPDATA%\135296\resource\is-P6KH7.tmp
- %APPDATA%\135296\resource\is-TTINO.tmp
- %APPDATA%\135296\resource\is-SQ6I1.tmp
- %APPDATA%\135296\resource\is-HUNKB.tmp
- %APPDATA%\135296\resource\is-N9DCM.tmp
- %APPDATA%\135296\resource\DirectUI\is-CBPC5.tmp
- %APPDATA%\135296\resource\is-VRM7M.tmp
- %APPDATA%\135296\resource\is-D2E3L.tmp
- %APPDATA%\135296\is-HV7NR.tmp
- %APPDATA%\135296\extensions\is-PMTVT.tmp
- %APPDATA%\135296\is-BPHSU.tmp
- %APPDATA%\135296\is-TIS9S.tmp
- %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\is-2PR9J.tmp
- %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\is-R32JK.tmp
- %APPDATA%\135296\extensions\is-CP6JG.tmp
- %APPDATA%\135296\extensions\is-2IODK.tmp
- %APPDATA%\135296\is-10CJ6.tmp
- %TEMP%\is-2ELLI.tmp\ISTask.dll
- %APPDATA%\135296\is-I4E47.tmp
- %TEMP%\is-TVG3T.tmp\<File name>.tmp
- %TEMP%\is-2ELLI.tmp\_isetup\_shfoldr.dll
- %APPDATA%\135296\is-5NALP.tmp
- %APPDATA%\135296\is-N6D4A.tmp
- %APPDATA%\135296\is-R63NO.tmp
- %APPDATA%\135296\is-N90CN.tmp
- %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\is-3KBT4.tmp
- %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\is-95ANV.tmp
- %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\is-GP8G1.tmp
- %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\is-KIDBH.tmp
- %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\is-B6SED.tmp
- %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\res\is-OOUTD.tmp
- %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\res\is-RGEE8.tmp
- %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\is-INKHJ.tmp
- %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\is-S6D7M.tmp
- %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\_metadata\is-SOF87.tmp
- %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\is-FPD84.tmp
- %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\res\is-E3NQI.tmp
- %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\is-9PQ0P.tmp
- %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\is-9S6O9.tmp
- %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\_locales\zh_CN\is-P86R4.tmp
- %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\_metadata\is-M4F0J.tmp
- %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\res\is-AS772.tmp
- %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\_locales\en\is-370MM.tmp
- %APPDATA%\135296\DataView64.dll
- %APPDATA%\135296\DataView.dll
- from %APPDATA%\135296\resource\is-B22DM.tmp to %APPDATA%\135296\resource\btn_cancel.png
- from %APPDATA%\135296\resource\is-28GD5.tmp to %APPDATA%\135296\resource\btn_alpha.png
- from %APPDATA%\135296\resource\is-O6S2G.tmp to %APPDATA%\135296\resource\btnBK.png
- from %APPDATA%\135296\resource\is-JC28M.tmp to %APPDATA%\135296\resource\btn_close.png
- from %APPDATA%\135296\resource\is-1S5QU.tmp to %APPDATA%\135296\resource\btn_today.png
- from %APPDATA%\135296\resource\is-ABQ80.tmp to %APPDATA%\135296\resource\btn_ok.png
- from %APPDATA%\135296\resource\is-CH68S.tmp to %APPDATA%\135296\resource\btn_min.png
- from %APPDATA%\135296\resource\is-GTS0Q.tmp to %APPDATA%\135296\resource\browser.png
- from %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\_metadata\is-LT01M.tmp to %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\_metadata\computed_hashes.json
- from %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\_locales\zh_CN\is-EIOGO.tmp to %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\_locales\zh_CN\messages.json
- from %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\_locales\en\is-BNNNK.tmp to %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\_locales\en\messages.json
- from %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\_metadata\is-2QVMI.tmp to %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\_metadata\verified_contents.json
- from %APPDATA%\135296\resource\is-0699H.tmp to %APPDATA%\135296\resource\box_check.png
- from %APPDATA%\135296\resource\is-TLBNA.tmp to %APPDATA%\135296\resource\arrow_right.png
- from %APPDATA%\135296\resource\is-BF80A.tmp to %APPDATA%\135296\resource\arrow_left.png
- from %APPDATA%\135296\resource\is-M5EDU.tmp to %APPDATA%\135296\resource\Calendar.ico
- from %APPDATA%\135296\resource\DirectUI\is-5FB4M.tmp to %APPDATA%\135296\resource\DirectUI\scrollArrowUp.bmp
- from %APPDATA%\135296\resource\DirectUI\is-CBPC5.tmp to %APPDATA%\135296\resource\DirectUI\scrollArrowDown.bmp
- from %APPDATA%\135296\resource\is-N9DCM.tmp to %APPDATA%\135296\resource\wtl.exe.manifest
- from %APPDATA%\135296\resource\DirectUI\is-MQP7J.tmp to %APPDATA%\135296\resource\DirectUI\scrollBar.bmp
- from %APPDATA%\135296\xmlconfig\is-UD65O.tmp to %APPDATA%\135296\xmlconfig\riliclient.xml
- from %APPDATA%\135296\xmlconfig\is-0PH4I.tmp to %APPDATA%\135296\xmlconfig\install.xml
- from %APPDATA%\135296\resource\DirectUI\is-I4HVC.tmp to %APPDATA%\135296\resource\DirectUI\srollBk.bmp
- from %APPDATA%\135296\resource\is-D2E3L.tmp to %APPDATA%\135296\resource\return.png
- from %APPDATA%\135296\resource\is-SQ6I1.tmp to %APPDATA%\135296\resource\logo.png
- from %APPDATA%\135296\resource\is-79L1K.tmp to %APPDATA%\135296\resource\License.txt
- from %APPDATA%\135296\resource\is-S5AI6.tmp to %APPDATA%\135296\resource\comboxBk.png
- from %APPDATA%\135296\resource\is-HUNKB.tmp to %APPDATA%\135296\resource\mainBk.png
- from %APPDATA%\135296\resource\is-VRM7M.tmp to %APPDATA%\135296\resource\radio.png
- from %APPDATA%\135296\resource\is-TTINO.tmp to %APPDATA%\135296\resource\now_start.png
- from %APPDATA%\135296\resource\is-P6KH7.tmp to %APPDATA%\135296\resource\menuButton.png
- from %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\res\is-RGEE8.tmp to %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\res\icon.gif
- from %APPDATA%\135296\extensions\is-CP6JG.tmp to %APPDATA%\135296\extensions\sec_setting.json
- from %APPDATA%\135296\extensions\is-PMTVT.tmp to %APPDATA%\135296\extensions\jySougou.sext
- from %APPDATA%\135296\is-HV7NR.tmp to %APPDATA%\135296\RLServiceB.exe
- from %APPDATA%\135296\extensions\is-2IODK.tmp to %APPDATA%\135296\extensions\setting.json
- from %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\is-3KBT4.tmp to %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\calmath.js
- from %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\is-R32JK.tmp to %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\background.js
- from %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\is-2PR9J.tmp to %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\background.html
- from %APPDATA%\135296\is-TIS9S.tmp to %APPDATA%\135296\mainClient.exe
- from %APPDATA%\135296\is-N90CN.tmp to %APPDATA%\135296\DataView.dll
- from %APPDATA%\135296\is-R63NO.tmp to %APPDATA%\135296\bandac.exe
- from %APPDATA%\135296\is-I4E47.tmp to %APPDATA%\135296\awdec.exe
- from %APPDATA%\135296\is-5NALP.tmp to %APPDATA%\135296\DataView64.dll
- from %APPDATA%\135296\is-BPHSU.tmp to %APPDATA%\135296\jywebHelper.dll
- from %APPDATA%\135296\is-10CJ6.tmp to %APPDATA%\135296\istask.dll
- from %APPDATA%\135296\is-N6D4A.tmp to %APPDATA%\135296\fixfunction.dll
- from %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\is-9PQ0P.tmp to %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\contentscript.js
- from %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\is-95ANV.tmp to %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\calmath.js
- from %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\is-B6SED.tmp to %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\background.js
- from %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\is-KIDBH.tmp to %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\background.html
- from %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\is-GP8G1.tmp to %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\contentscript.js
- from %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\res\is-OOUTD.tmp to %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\res\crx.png
- from %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\is-S6D7M.tmp to %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\popup.html
- from %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\is-INKHJ.tmp to %APPDATA%\135296\extensions\int2\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\manifest.json
- from %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\_metadata\is-SOF87.tmp to %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\_metadata\verified_contents.json
- from %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\res\is-E3NQI.tmp to %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\res\crx.png
- from %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\is-FPD84.tmp to %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\popup.html
- from %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\is-9S6O9.tmp to %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\manifest.json
- from %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\res\is-AS772.tmp to %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\res\icon.gif
- from %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\_metadata\is-M4F0J.tmp to %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\_metadata\computed_hashes.json
- from %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\_locales\zh_CN\is-P86R4.tmp to %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\_locales\zh_CN\messages.json
- from %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\_locales\en\is-370MM.tmp to %APPDATA%\135296\extensions\chrome\ccikkllbpgbmnpajbjkjipmopnhfonnp\4.0.2_0\_locales\en\messages.json
- %APPDATA%\135296\DataView64.dll
- %APPDATA%\135296\DataView.dll
- 'www.jy##li.com':80
- http://www.jy##li.com/client.do/?me#######################################################################################
- http://www.jy##li.com/client.do/?&m##############################################################################################################################################################...
- DNS ASK www.jy##li.com
- ClassName: 'Shell_TrayWnd' WindowName: ''