It installs itself as this service:
ServiceName "svchost "
DisplayName Generic Host Process for Win32 Services
Binary "C:\WINDOWS\system32\svchost.exe "
StartType Automatic at system startup
Account LocalSystem
and then run this other file: "C:\WINDOWS\system32\lsass.exe " (perhaps a ftp server?)
service and two files are hidden and the last character in their names I think is [alt+0160]













