Техническая информация
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'Peter'sRansomware' = '<Полный путь к файлу>'
- %HOMEPATH%\desktop\000814251_video_01.avi
- %HOMEPATH%\desktop\thlps_keeper_mayer_1965.docx
- %HOMEPATH%\desktop\sdszfo.docx
- %HOMEPATH%\desktop\iisstart.html
- %HOMEPATH%\desktop\howto-index.html
- %HOMEPATH%\desktop\holycrosschurchinstructions.docx
- %HOMEPATH%\desktop\dialmap.bmp
- %HOMEPATH%\desktop\dial.bmp
- %HOMEPATH%\desktop\tree_view.html
- %HOMEPATH%\desktop\default.bmp
- %HOMEPATH%\desktop\dashborder_120.bmp
- %HOMEPATH%\desktop\applicantform_en.doc
- %HOMEPATH%\desktop\api-hashmap.html
- %HOMEPATH%\desktop\aoc_saq_d_v3_merchant.docx
- %HOMEPATH%\desktop\alert.html
- %HOMEPATH%\desktop\adhd_and_obesity.docx
- %HOMEPATH%\desktop\508softwareandos.doc
- %HOMEPATH%\desktop\dashborder_192.bmp
- %HOMEPATH%\desktop\trivial-merge.html
- %HOMEPATH%\desktop\000814251_video_01.avi.peter
- %HOMEPATH%\desktop\508softwareandos.doc.peter
- %HOMEPATH%\desktop\adhd_and_obesity.docx.peter
- %HOMEPATH%\desktop\alert.html.peter
- %HOMEPATH%\desktop\aoc_saq_d_v3_merchant.docx.peter
- %HOMEPATH%\desktop\api-hashmap.html.peter
- %HOMEPATH%\desktop\applicantform_en.doc.peter
- %HOMEPATH%\encrypt_date.txt