<< Back to Top Threats
K7 Detection Name Affected OS Prevalence AV Definition Version
Trojan ( 005674fe1 ) Windows Low 12.134.50637
MD5

03811e1b647a0bb48724049897df8f2b

SHA256

8b1cf43214d6f657bba5dac7083f1ae6394b45d58d5ec8ff580d34cb1b775034

File Size

10,659,161 bytes

Packer Information

NA

First Seen

04-01-2024

Last Seen

23-04-2024

Aliases

Packed.VMProtect.RG

Behavior Details

1. Dropped files:
     03811e1b647a0bb48724.dat.tmp
  Under the folder
       C:\Users\<user_name>\AppData\Local\Temp\is-DG4MP.tmp

2. Dropped files:
     _setup64.tmp
  Under the folder
       C:\Users\<user_name>\AppData\Local\Temp\is-22CI6.tmp\_isetup

3. Creates Registry:

  Adds registry data
     \x80\x07\x00\x00\x02\xa5\xa9\x13\x1e`\xda\x01

  Under the key:
	 HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000\Owner

  Adds registry data
     \xfb\xf4\x1fXo\xb3h/\xd6x\xfd|d\x08\xbb\xe6\xfcg\xe36\xa6\xd8OT\x99\x1f\xe4lh\xad N

  Under the key:
	 HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000\SessionHash

  Adds registry data
     1

  Under the key:
	 HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000\Sequence

Removal Instructions

1. Update the copy of K7 security to the latest version.
2. Scan the system completely and remove the detected files.
3. Open Windows registry editor.
4. Delete the registry data
     \x80\x07\x00\x00\x02\xa5\xa9\x13\x1e`\xda\x01

   Under the key:
    HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000\Owner

5. Delete the registry data
     \xfb\xf4\x1fXo\xb3h/\xd6x\xfd|d\x08\xbb\xe6\xfcg\xe36\xa6\xd8OT\x99\x1f\xe4lh\xad N

   Under the key:
    HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000\SessionHash

6. Delete the registry data
     1

   Under the key:
    HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000\Sequence
7. Close the Windows registry.
8. Restart the machine.