Техническая информация
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'Peter'sRansomware' = '<Полный путь к файлу>'
- %HOMEPATH%\desktop\508softwareandos.doc
- %HOMEPATH%\desktop\aoc_saq_d_v3_merchant.docx
- %HOMEPATH%\desktop\applicantform_en.doc
- %HOMEPATH%\desktop\archer.avi
- %HOMEPATH%\desktop\cveuropeo.doc
- %HOMEPATH%\desktop\fi51.doc
- %HOMEPATH%\desktop\hanni_umami_chapter.doc
- %HOMEPATH%\desktop\holycrosschurchinstructions.docx
- %HOMEPATH%\desktop\lisp_success.doc
- %HOMEPATH%\desktop\508softwareandos.doc.peter
- %HOMEPATH%\desktop\aoc_saq_d_v3_merchant.docx.peter
- %HOMEPATH%\desktop\applicantform_en.doc.peter
- %HOMEPATH%\desktop\archer.avi.peter
- %HOMEPATH%\desktop\cveuropeo.doc.peter
- %HOMEPATH%\desktop\fi51.doc.peter
- %HOMEPATH%\desktop\hanni_umami_chapter.doc.peter
- %HOMEPATH%\desktop\holycrosschurchinstructions.docx.peter
- %HOMEPATH%\desktop\lisp_success.doc.peter
- %HOMEPATH%\encrypt_date.txt