EP_X0FF wrote:retrogad wrote:Hey
i am looking for samples that use SVCHOST :inject,manipulate,loading from svchost etc
anything that use svchost
i know only about Conficker ,Bamital i know only injects itslef to svhost
anything else ?
SpyEye, TDL, lots of others.
sorry,i need to explain more...
i DONT look for those who INJECT themself into SVCHOST running process memory,but run as service - pretendes to be a svchost,uploading DLL to legit svchost,modify svchost ,create new svchost services ,or enter values in registry that belongs only to system files,or simply damage svchost file or something FOR EXAMPLE : (i really looking for those)
SSearch.biz
home search assistant
conficker --- > i have tried to execute the samples on this forum,but no success,the conficker modify folder options but doesnt even try to communicate,and doesnt add a new service to svchost,something strange...
i have run as is : c:\ rundll32 conficker.vmx,ahaezedrn
its like half not working...