This crypto ransomware encrypts user data with AES + RSA and then demands a 0.1 BTC ransom to get the files back. Original title: Tripoli ransomware. The extension is appended to encrypted files: .crypted

Files related to this Ransomware:
HOW_FIX_FILES.htm – name of the file with the requirement Ransom
<random> .exe – random name of a malicious file
Locations:
\ Desktop \ ->
\ User_folders \ ->
\% TEMP% \ ->

