Ransom Foreign (France) - fill displays with blue color and ransom message.
https://www.virustotal.com/file/0b61f6b9a3b6d9a32fbb3d0a752c27f31919806d7fcb7719e380f529c6a87f40/analysis/
Internal name "reallock"
C:\Documents and Settings\AD-User\\Visual Studio 2008\Projects\reallock\Release\reallock.pdb
Self-explaining strings from inside
Enter valid code and enable you internet.
ERROR on send data.If you have not internet,check you internet.PRESS SPACE for configure internet.
Press SPACE for hide
PLEASE WAIT
(enter VALID code only)
(press ENTER on finish)
Wrong,Input Again!!
Software\Microsoft\Windows\CurrentVersion
<unknown>
taskmgr.exe
taskkill /f /im taskmgr.exe
WinInet
http://www.readkash.com
GET
ERROR
WindowsRegzin
WindowsRegzinid
locksrv/resp.php?func=check&id=
&smg=
WindowsRegzinidreg
Windows
Software\Microsoft\Windows\CurrentVersion\Run
locksrv/resp.php?func=reg&id=
&kod=
taskkill /f /im explorer.exe
cmd.exe /C start explorer.exe
block
\Local Settings\Application Data\winsh.exe
block
block