Red Rabit 1.0
(Trojan-Dropper.Win32.Agent.xq)

by Asm

Released in April 2007

Made in China


Server
dropped file:
c:\WINDOWS\system32\scvhost.exe
size: 7,168 bytes 

startup:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\GetSysService "ImagePath"
data: C:\WINDOWS\System32\scvhost.exe 



tested on Windows XP
September 07, 2007

MegaSecurity