@erikloman @markloman This new ransomware, does it also use the lsass.exe/rundll.exe trick? (+ .lnk in StartUp folder)
@loteck Sounds like something else, do you have MD5s or other characteristics? (cc @markloman @erikloman)
-
-
@bartblaze@loteck@erikloman The Windows NT\Windows\Load value with the *.LNK dos 8.3 short filename is actually Dorifel -
@markloman Thanks!
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.