Non-Gentleman

Released 17 years, 5 months ago. April 2007

Copyright © MegaSecurity

By ?


Non-Gentleman
Informations
From China
Author ?
Family Non-Gentleman
Category Remote Access
Version Non-Gentleman
Released Date Apr 2007, 17 years, 5 months ago.
Additional Information
Server:
dropped files:
c:\Documents and Settings\%user%\Local Settings\Temp\E_4\HideProc.dll
size: 28,672 bytes 

c:\Documents and Settings\%user%\Local Settings\Temp\E_4\rhmisc.dll
size: 57,344 bytes 

c:\WINDOWS\��.exe
size: 809,241 bytes 

c:\WINDOWS\smss.exe
size: 809,241 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Userinit"
old data: C:\WINDOWS\system32\userinit.exe, 
new data: C:\WINDOWS\system32\userinit.exe,��, 




tested on Windows XP
April 06, 2007

If you recognize any personal information on this page and wish to have it removed or redacted, please contact us at jplesueur@phrozen.io. We are committed to protecting your privacy in accordance with GDPR regulations.