Files
RegistryEntries
%local user%\random\<random>.exe
RegistryEntries
Key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zentom System Guard
Key: HKEY_CURRENT_USER\Software\ZentomSystemGuard
Key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Value: libstaf5cd0.exe
Data: "C:\Documents and Settings\VPCTest\Application Data\2E23C32608288CFD80A95B5DA1D2184C\libstaf5cd0.exe"
Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Value: *KB5800200.exe
Data: "C:\Documents and Settings\VPCTest\Application Data\Adobe\plugs\KB5800200.exe"
