Техническая информация
- [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] 'Peter'sRansomware' = '<Полный путь к файлу>'
- %HOMEPATH%\desktop\000814251_video_01.avi
- %HOMEPATH%\desktop\1189.jpeg
- %HOMEPATH%\desktop\168.jpg
- %HOMEPATH%\desktop\508softwareandos.doc
- %HOMEPATH%\desktop\alert.html
- %HOMEPATH%\desktop\aoc_saq_d_v3_merchant.docx
- %HOMEPATH%\desktop\dashborder_120.bmp
- %HOMEPATH%\desktop\dialmap.bmp
- %HOMEPATH%\desktop\fi51.doc
- %HOMEPATH%\desktop\glidescope_review_rev_010.docx
- %HOMEPATH%\desktop\hanni_umami_chapter.doc
- %HOMEPATH%\desktop\parnas_01.jpeg
- %HOMEPATH%\desktop\pushkin.jpeg
- %HOMEPATH%\desktop\region-north-karelia.jpg
- %HOMEPATH%\desktop\split.avi
- %HOMEPATH%\desktop\000814251_video_01.avi.peter
- %HOMEPATH%\desktop\1189.jpeg.peter
- %HOMEPATH%\desktop\168.jpg.peter
- %HOMEPATH%\desktop\508softwareandos.doc.peter
- %HOMEPATH%\encrypt_date.txt
- %ALLUSERSPROFILE%\microsoft\search\data\applications\windows\mss.log
- '<SYSTEM32>\searchprotocolhost.exe' Global\UsGthrFltPipeMssGthrPipe7_ Global\UsGthrCtrlFltPipeMssGthrPipe7 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "%...
- '<SYSTEM32>\searchfilterhost.exe' 0 508 512 520 65536 516