Techware Labs Header

Forums have moved

See this announcement for more details, or just go directly there.

Prev Previous Post   Next Post Next
  #10  
Old 12-09-2003, 08:40 AM
Rockywuff
 
Posts: n/a
Default

I had the same problem with a false svchost.exe. In my case it spawned a ton of IEXPLORER.EXE processes which in the end caused my computer to become very unstable.

The real svchost is (under win2k) located at \winnt\system32\svchost.exe (with a backup copy in \winnt\system32\dllcache\svchost.exe), but the fake was placed in \winnt\svchost.exe. The fake was also about 2kb smaller than the real one, and didn't have any identity information, which the real one has.

It had created a registry key under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run so it would start each time the computer booted, and when run it attempts to download "http://download.online-dialer.com/connect.php?od-stnd22", which appears to be a modem hijacker or "porn dialer".

I have not yet figured out which program it came in with.
Reply With Quote
 


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 02:07 PM. Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Forum style by ForumMonkeys.