NoResume

Released 17 years, 2 months ago. September 2007

Copyright © MegaSecurity

By Lenk


Informations
From China
Author Lenk
Family NoResume
Category Remote Access
Version NoResume
Released Date Sep 2007, 17 years, 2 months ago.
Language Delphi
Additional Information
Server
Dropped Files:
c:\WINDOWS\system32\LstConfig.Dat    Size: 93 bytes 
c:\WINDOWS\system32\LstDll.dll       Size: 90,112 bytes 
c:\WINDOWS\system32\MsInet.exe       Size: 188,001 bytes 

Added to Registry:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NoResumeSrv "ImagePath"
data: C:\WINDOWS\System32\MsInet.exe -Service 	

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NoResumeSrv "ImagePath"
data: C:\WINDOWS\System32\MsInet.exe -Service 
	
		
	
tested on Windows XP
September 09, 2007

If you recognize any personal information on this page and wish to have it removed or redacted, please contact us at jplesueur@phrozen.io. We are committed to protecting your privacy in accordance with GDPR regulations.