ransomeware sample i found on a friends pc.
Uses only HKCU startup and drops at appdata\local\skype\skypePM.exe

https://www.virustotal.com/file/433fd0a ... 332259209/
//it's not graftor ( my fault )
Uses only HKCU startup and drops at appdata\local\skype\skypePM.exe

https://www.virustotal.com/file/433fd0a ... 332259209/
//it's not graftor ( my fault )
Attachments
pw: infected
(128.29 KiB) Downloaded 73 times
(128.29 KiB) Downloaded 73 times
Last edited by MindfreaK on Tue Mar 20, 2012 8:18 pm, edited 1 time in total.