Attachments
pass:infected
(208.67 KiB) Downloaded 58 times
(208.67 KiB) Downloaded 58 times
A forum for reverse engineering, OS internals and malware analysis
NarfBang wrote:SHA256:This is French ransomware.
ce9c7f46cad1e40cb9e411736b5bc66412f61ee2aa6d638e4413ea4efdfde648
"HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load" "" "" ""
+ "C:\DOCUME~1\owner\LOCALS~1\Temp\4A7DE4666052AD44198A.exe," "" "" "File not found: C:\DOCUME~1\owner\LOCALS~1\Temp\4A7DE4666052AD44198A.exe,"