WinterLove 4.0

Released 19 years, 3 months ago. June 2005

Copyright © MegaSecurity

By plunix


Informations
From China
Author plunix
Family WinterLove
Category Remote Access
Version WinterLove 4.0
Released Date Jun 2005, 19 years, 3 months ago.
Language Microsoft Visual C++
Additional Information
Server:
dropped file:
c:\WINNT\system32\server.dll
size: 70,656 bytes 

port: 3043 TCP

added to registry:
HKEY_LOCAL_MACHINE\SAM\SAM\Domains
HKEY_LOCAL_MACHINE\SAM\SAM\RXACT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MYSRVSHELL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MySrvShell
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYSRVSHELL
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MySrvShell


tested on Windows XP
July 15, 2005

If you recognize any personal information on this page and wish to have it removed or redacted, please contact us at jplesueur@phrozen.io. We are committed to protecting your privacy in accordance with GDPR regulations.