The malware updates %CD% to the path of the running module and sets HKLM\Software\WanaCrypt0r\wd to %CD%. The malware then https://windll.com/dll/microsoft-corporation/d3drm loads the XIA resource and…
The malware updates %CD% to the path of the running module and sets HKLM\Software\WanaCrypt0r\wd to %CD%. The malware then https://windll.com/dll/microsoft-corporation/d3drm loads the XIA resource and…