WPS 1.1
Released 17 years, 5 months ago. June 2007
Copyright © MegaSecurity
By W32_Cr4Ck3r
Informations
From | Iran |
Author | W32_Cr4Ck3r |
Family | WPS |
Category | Information Stealer |
Version | WPS 1.1 |
Released Date | Jun 2007, 17 years, 5 months ago. |
Language | Visual Basic |
Additional Information
Server
Dropped File:
c:\WINDOWS\system32\regsvr.exe
Size: 28,917 bytes
Added to Registry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "regsvr"
Data: C:\WINDOWS\System32\regsvr.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Explorer.exe"
Data: C:\WINDOWS\System32\Explorer.exe
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List "C:\WINDOWS\System32\regsvr.exe"
Data: C:\WINDOWS\System32\regsvr.exe:*:Enabled:Microsoft
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List "C:\WINDOWS\System32\regsvr.exe"
Data: C:\WINDOWS\System32\regsvr.exe:*:Enabled:Microsoft
Tested on Windows XP
December 26, 2007
If you recognize any personal information on this page and wish to have it removed or redacted, please contact us at jplesueur@phrozen.io. We are committed to protecting your privacy in accordance with GDPR regulations.