A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #31404  by tomatto007
 Tue Apr 03, 2018 8:16 am
ikolor wrote: Wed Mar 28, 2018 4:26 pm Thanks

https://www.virustotal.com/#/file/2b83f ... /detection
VALUES ADDED:
HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\MONETKEYDEF: ""%LOCAL APPDATA%\MICROSOFT\WINDOWS\MONETKEYDEF.EXE""
HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\DECRYPTAPURCHASE: ""%LOCAL APPDATA%\MICROSOFT\WINDOWS\DECRYPTAPURCHASE.EXE""

FILES ADDED:
%LOCAL APPDATA%\MICROSOFT\WINDOWS\MONETKEYDEF.EXE
%LOCAL APPDATA%\MICROSOFT\WINDOWS\DECRYPTAPURCHASE.EXE