Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'senrmodk70.exe' = '"%APPDATA%\3D852781C134E6EBEEFD8C25A1F9094D\senrmodk70.exe"'
- %HOMEPATH%\Start Menu\Programs\Startup\Zentom System Guard.lnk
- %APPDATA%\3D852781C134E6EBEEFD8C25A1F9094D\senrmodk70.exe 7070010300
- %HOMEPATH%\Start Menu\Programs\Zentom System Guard\Zentom System Guard.lnk
- %HOMEPATH%\Start Menu\Zentom System Guard.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Zentom System Guard.lnk
- %HOMEPATH%\Start Menu\Programs\Zentom System Guard\Uninstall.lnk
- %HOMEPATH%\Desktop\Zentom System Guard.lnk
- %APPDATA%\3D852781C134E6EBEEFD8C25A1F9094D\enemies-names.txt
- %APPDATA%\3D852781C134E6EBEEFD8C25A1F9094D\senrmodk70.exe
- %APPDATA%\3D852781C134E6EBEEFD8C25A1F9094D\hookdll.dll
- %APPDATA%\3D852781C134E6EBEEFD8C25A1F9094D\local.ini
- 'fi##tu.in':80
- fi##tu.in/index.php?pr###################################################################################################
- fi##tu.in/
- DNS ASK s.##rstu.in
- DNS ASK fi##tu.in
- '<IP-адрес в локальной сети>':1036
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'msctls_updown32' WindowName: ''
- ClassName: 'Indicator' WindowName: ''