@bartblaze @erikloman Current ransomware spread by Dorifel disables UAC and adds itself to Winlogon\Shell, Policies\Explorer\Run and RunOnce
@erikloman @markloman This new ransomware, does it also use the lsass.exe/rundll.exe trick? (+ .lnk in StartUp folder)
-
-
-
@markloman@bartblaze@erikloman also seeing Windows NT\Windows "Load" key referencing .lnk. different infection? - Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.