Soheil-PS

Copyright © MegaSecurity

By Soheil


Soheil-PS
Informations
From The Middle East
Author Soheil
Family Soheil-PS
Category Information Stealer
Version Soheil-PS
Language Visual Basic
Additional Information
Server:
dropped files:
c:\WINDOWS\system\shell32.dll    Size: 114 bytes 
c:\WINDOWS\system\svchost.exe    Size: 49,664 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell"
old data: Explorer.exe 
new data: Explorer.exe C:\WINDOWS\system\svchost.exe 



tested on Windows XP
August 23, 2006

If you recognize any personal information on this page and wish to have it removed or redacted, please contact us at jplesueur@phrozen.io. We are committed to protecting your privacy in accordance with GDPR regulations.