Svchost 0.2 beta
(Not detected by KAV on February 24, 2008)

by F-king

Written in Visual C++

Released in June 2003

Made in China

more versions




Server:
dropped file:
c:\WINDOWS\SYSTEM\rundlls32.exe 

size: 20.480 bytes

port: 0 TCP

restart:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "RunDll32s" 

fast closing DOS-box is visible

tested on Windows XP

MegaSecurity