by Cr4sh
Written in Microsoft Visual C++
Released in January 2006
Made in Russia
Server: dropped file: c:\WINDOWS\system32\svcroot.exe size: 45,056 bytes startup: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" old data: Explorer.exe new data: Explorer.exe svcroot.exe HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "svcroot" data: C:\WINDOWS\System32\svcroot.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "svcroot" data: C:\WINDOWS\System32\svcroot.exe tested on Windows XP July 16, 2007MegaSecurity