Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'PDF File' = '%APPDATA%\Locker.exe'
- '<SYSTEM32>\attrib.exe' +s +h %HOMEPATH%\Desktop\YOUR_FILES_ARE_LOCKED\.{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0} /S /D
- '<SYSTEM32>\attrib.exe' +s +h %HOMEPATH%\Desktop\YOUR_FILES_ARE_LOCKED\.{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}\*.* /S /D
- '<SYSTEM32>\cmd.exe' /cattrib +s +h %HOMEPATH%\Desktop\YOUR_FILES_ARE_LOCKED\.{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0} /S /D
- '<SYSTEM32>\cmd.exe' /cren %HOMEPATH%\Desktop\YOUR_FILES_ARE_LOCKED\ YOUR_FILES_ARE_LOCKED.{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}
- '<SYSTEM32>\cmd.exe' /cattrib +s +h %HOMEPATH%\Desktop\YOUR_FILES_ARE_LOCKED\.{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}\*.* /S /D
- <Полный путь к файлу>
- из <Полный путь к файлу> в %APPDATA%\Locker.exe
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''