Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'empty'
- Диспетчера задач (Taskmgr)
- %HOMEPATH%\desktop\contoso.cer
- %HOMEPATH%\desktop\contosoroot_1.cer
- %HOMEPATH%\desktop\delete.avi
- %HOMEPATH%\desktop\dial.bmp
- %HOMEPATH%\desktop\fi51.doc
- %HOMEPATH%\desktop\hadac_newsletter_july_2010_final.docx
- %HOMEPATH%\desktop\holycrosschurchinstructions.docx
- %HOMEPATH%\desktop\ovp25012015.doc
- %HOMEPATH%\desktop\pmd.cer
- %HOMEPATH%\desktop\sdszfo.docx
- %HOMEPATH%\desktop\testcertificate.cer
- %ProgramFiles%\system32\readme.txt
- %HOMEPATH%\desktop\._cache_dcqpkx.exe
- %HOMEPATH%\desktop\ransomware2.0.txt
- %ProgramFiles%\system32\ransomware2.0.exe
- 'gi##ub.com':443
- 'ra#.####ubusercontent.com':443
- DNS ASK gi##ub.com
- DNS ASK ra#.####ubusercontent.com
- '%ProgramFiles%\system32\ransomware2.0.exe'