Redshots MSN 1.0
(Backdoor.Win32.RShot.e for Client)
(Not detected by KAV for Server on May 11, 2007)

by Redshots

Written in Visual Basic

Released in March 2006

more versions





Server:
dropped file:
c:\WINDOWS\iexplorer.exe
size: 122,880 bytes 

added to registry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\system "disabletaskmgr"
data: 01, 00, 00, 00 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "iexplorer"
data: c:\windows\iexplorer.exe 



tested on Windows XP
March 20, 2006

MegaSecurity