Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'empty'
- Диспетчера задач (Taskmgr)
- %HOMEPATH%\desktop\000814251_video_01.avi
- %HOMEPATH%\desktop\about.htm
- %HOMEPATH%\desktop\about.html
- %HOMEPATH%\desktop\adadsi.html
- %HOMEPATH%\desktop\alert.htm
- %HOMEPATH%\desktop\dashborder_192.bmp
- %HOMEPATH%\desktop\default.bmp
- %HOMEPATH%\desktop\february_catalogue__2015.doc
- %HOMEPATH%\desktop\howto-index.html
- %HOMEPATH%\desktop\iisstart.html
- %HOMEPATH%\desktop\sdksampleprivdeveloper.cer
- %HOMEPATH%\desktop\split.avi
- %HOMEPATH%\desktop\testee.cer
- %HOMEPATH%\desktop\tree_view.htm
- %HOMEPATH%\desktop\tree_view.html
- %ProgramFiles%\system32\readme.txt
- %HOMEPATH%\desktop\._cache_dcqpkx.exe
- %HOMEPATH%\desktop\ransomware2.0.txt
- %ProgramFiles%\system32\rasomware2.0.exe
- 'gi##ub.com':443
- 'ra#.####ubusercontent.com':443
- DNS ASK gi##ub.com
- DNS ASK ra#.####ubusercontent.com
- '%ProgramFiles%\system32\rasomware2.0.exe'