Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'siboni24acv.exe' = '"%APPDATA%\AC6EDE350CD5C68828D4ED8A2D6A56CD\siboni24acv.exe"'
- %HOMEPATH%\Start Menu\Programs\Startup\Zentom System Guard.lnk
- %APPDATA%\AC6EDE350CD5C68828D4ED8A2D6A56CD\siboni24acv.exe 7071624301
- %HOMEPATH%\Start Menu\Programs\Zentom System Guard\Zentom System Guard.lnk
- %HOMEPATH%\Start Menu\Zentom System Guard.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Zentom System Guard.lnk
- %HOMEPATH%\Start Menu\Programs\Zentom System Guard\Uninstall.lnk
- %HOMEPATH%\Desktop\Zentom System Guard.lnk
- %APPDATA%\AC6EDE350CD5C68828D4ED8A2D6A56CD\enemies-names.txt
- %APPDATA%\AC6EDE350CD5C68828D4ED8A2D6A56CD\siboni24acv.exe
- %APPDATA%\AC6EDE350CD5C68828D4ED8A2D6A56CD\hookdll.dll
- %APPDATA%\AC6EDE350CD5C68828D4ED8A2D6A56CD\local.ini
- 'to##seeu.in':80
- to##seeu.in/index.php?pr##########################################################################################################
- to##seeu.in/
- DNS ASK s.###iseeu.in
- DNS ASK to##seeu.in
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''