Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsApplication1' = 'C:\RansomOA9\Ransom.exe'
- %WINDIR%\explorer.exe
- C:\ransomoa9\ransom.exe
- C:\ransomoa9\ransom.pdb
- C:\ransomoa9\ransom.xml
- C:\ransomoa9\u.mp3
- C:\ransomoa9\interop.wmplib.dll
- %LOCALAPPDATA%\microsoft\media player\currentdatabase_372.wmdb
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'WMPlayerApp' WindowName: ''
- ClassName: 'Progman' WindowName: ''
- ClassName: 'Proxy Desktop' WindowName: ''
- 'C:\ransomoa9\ransom.exe'
- '%WINDIR%\explorer.exe'