exitthematrix wrote:Does the exe send any TCP data encoded with that key in the registy?↑This is actually a problem, I think that was the key, but have no crypted data catched to test this key itself.. (expected to be seen in network traffic) since somehow this thig is so shy and didn't send anything yet (even now still running)
I even make the script to run the malware process using net start|stop and it works well to start/stop this two evil services, YET still no networking happen yet, rgds!