r00tDefaced Trojan
(Not detected by KAV on March 07, 2009)

by shadow-hacker

Released in February 2009





Server
Dropped File:
c:\WINDOWS\system32\msisvchost.exe 
Size: 614,828 bytes

Startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "msisvchost" 
Data: C:\Windows\system32\msisvchost.exe 



Tested on Windows XP
March 07, 2009

MegaSecurity