Техническая информация
- [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] 'Peter'sRansomware' = '<Полный путь к файлу>'
- %HOMEPATH%\desktop\correct.avi
- %HOMEPATH%\desktop\cveuropeo.doc
- %HOMEPATH%\desktop\dashborder_96.bmp
- %HOMEPATH%\desktop\hadac_newsletter_july_2010_final.docx
- %HOMEPATH%\desktop\holycrosschurchinstructions.docx
- %HOMEPATH%\desktop\issi2013_template_for_posters.docx
- %HOMEPATH%\desktop\ovp25012015.doc
- %HOMEPATH%\desktop\toolbar.bmp
- %HOMEPATH%\desktop\weeklysheet1215.doc
- %HOMEPATH%\desktop\correct.avi.peter
- %HOMEPATH%\desktop\cveuropeo.doc.peter
- %HOMEPATH%\desktop\dashborder_96.bmp.peter
- %HOMEPATH%\desktop\hadac_newsletter_july_2010_final.docx.peter
- %HOMEPATH%\desktop\holycrosschurchinstructions.docx.peter
- %HOMEPATH%\desktop\issi2013_template_for_posters.docx.peter
- %HOMEPATH%\desktop\ovp25012015.doc.peter
- %HOMEPATH%\desktop\toolbar.bmp.peter
- %HOMEPATH%\desktop\weeklysheet1215.doc.peter
- %HOMEPATH%\encrypt_date.txt