Fabian, thanks for your reply, I can see the picture now .
Cheers !
Cheers !
A forum for reverse engineering, OS internals and malware analysis
Sent by the malware:
new
Reply from the server:
581:f6DC4Emmjjh0z
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
bdgid REG_SZ f6DC4Emmjjh0z
id REG_SZ 581
Could not find decryption key. Maybe a new variant?
An error occurred when trying to decrypt file <source file> to <destination file>!
Exception occurred while processing file <source file>:
Class: EFCreateError - Exception: Cannot create file "<destination file>".
The process cannot access the file because it is being used by another process