Техническая информация
- [<HKLM>\SYSTEM\CurrentControlSet\Services\dcrypt] 'Start' = '00000000'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\dcrypt] 'ImagePath' = 'system32\drivers\dcrypt.sys'
- C:\programs\dcrypt\dccon.exe
- C:\programs\dcrypt\dcrypt.exe
- C:\programs\dcrypt\dcapi.dll
- %WINDIR%\syswow64\drivers\dcrypt.sys
- C:\programs\dcrypt\dcrypt.reg
- %HOMEPATH%\desktop\disk cryptor.lnk
- %APPDATA%\microsoft\windows\start menu\programs\disks\disk cryptor.lnk
- ClassName: 'EDIT' WindowName: ''
- 'C:\programs\dcrypt\dcrypt.exe'
- '%WINDIR%\syswow64\reg.exe' import C:\Programs\DCrypt\DCrypt.reg