A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #4098  by EP_X0FF
 Wed Dec 22, 2010 12:52 pm
Well it is some sort of spy. It is written on Delphi and trying to connect 80.87.207.139.
Also it creates registry key HKU\SOFTWARE\svchcost\registry.

If you rerun this program it will fail to initialize properly and will create new sub key for already created key (e.g. HKEY_CURRENT_USER\SOFTWARE\svchcost\registry\SOFTWARE\svchcost\registry\)

Some sort of total script-kiddie trash.

edit:

changed topic title to be more descriptive
Last edited by EP_X0FF on Thu Dec 23, 2010 4:19 pm, edited 1 time in total. Reason: edit