Техническая информация
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'empty'
- Диспетчера задач (Taskmgr)
- %HOMEPATH%\desktop\api-hashmap.html
- %HOMEPATH%\desktop\archer.avi
- %HOMEPATH%\desktop\default.bmp
- %HOMEPATH%\desktop\dial.bmp
- %HOMEPATH%\desktop\february_catalogue__2015.doc
- %HOMEPATH%\desktop\file_p_00000000_1371597592.docx
- %HOMEPATH%\desktop\iisstart.html
- %HOMEPATH%\desktop\ovp25012015.doc
- %HOMEPATH%\desktop\sdksampleprivdeveloper.cer
- %HOMEPATH%\desktop\sdksampleunprivdeveloper.cer
- %HOMEPATH%\desktop\split.avi
- %HOMEPATH%\desktop\testcertificate.cer
- %HOMEPATH%\desktop\tree_view.html
- %ProgramFiles%\system32\readme.txt
- %HOMEPATH%\desktop\._cache_dcqpkx.exe
- %HOMEPATH%\desktop\ransomware.txt
- %ProgramFiles%\system32\ransomware2.0.exe
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- DNS ASK cd#.##scordapp.com
- DNS ASK microsoft.com
- '%ProgramFiles%\system32\ransomware2.0.exe'