@erikloman @markloman This new ransomware, does it also use the lsass.exe/rundll.exe trick? (+ .lnk in StartUp folder)
-
-
Replying to @bartblaze
@bartblaze@erikloman Current ransomware spread by Dorifel disables UAC and adds itself to Winlogon\Shell, Policies\Explorer\Run and RunOnce2 replies 0 retweets 0 likes -
Replying to @markloman
@markloman@bartblaze@erikloman also seeing Windows NT\Windows "Load" key referencing .lnk. different infection?1 reply 0 retweets 0 likes -
Replying to @loteck
@loteck Sounds like something else, do you have MD5s or other characteristics? (cc@markloman@erikloman)1 reply 0 retweets 0 likes -
Replying to @bartblaze
@bartblaze@loteck@erikloman The Windows NT\Windows\Load value with the *.LNK dos 8.3 short filename is actually Dorifel1 reply 0 retweets 0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.