Техническая информация
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'Wilder'sRansomware' = '<Полный путь к файлу>'
- %HOMEPATH%\desktop\508softwareandos.doc
- %HOMEPATH%\desktop\coffee.bmp
- %HOMEPATH%\desktop\dashborder_96.bmp
- %HOMEPATH%\desktop\glidescope_review_rev_010.docx
- %HOMEPATH%\desktop\hadac_newsletter_july_2010_final.docx
- %HOMEPATH%\desktop\holycrosschurchinstructions.docx
- %HOMEPATH%\desktop\issi2013_template_for_posters.docx
- %HOMEPATH%\desktop\lisp_success.doc
- %HOMEPATH%\desktop\tileimage.bmp
- %HOMEPATH%\desktop\toolbar.bmp
- %HOMEPATH%\desktop\uep_form_786_bulletin_1726i602.doc
- %HOMEPATH%\desktop\weeklysheet1215.doc
- %HOMEPATH%\desktop\508softwareandos.doc.wilder
- %HOMEPATH%\desktop\coffee.bmp.wilder
- %HOMEPATH%\desktop\dashborder_96.bmp.wilder
- %HOMEPATH%\desktop\glidescope_review_rev_010.docx.wilder
- %HOMEPATH%\desktop\hadac_newsletter_july_2010_final.docx.wilder
- %HOMEPATH%\desktop\holycrosschurchinstructions.docx.wilder
- %HOMEPATH%\desktop\issi2013_template_for_posters.docx.wilder
- %HOMEPATH%\desktop\lisp_success.doc.wilder
- %HOMEPATH%\desktop\tileimage.bmp.wilder
- %HOMEPATH%\desktop\toolbar.bmp.wilder
- %HOMEPATH%\desktop\uep_form_786_bulletin_1726i602.doc.wilder
- %HOMEPATH%\desktop\weeklysheet1215.doc.wilder
- %HOMEPATH%\encrypt_date.txt