SH-45000 v2.0.3
(Backdoor.Win32.AutoIt.r)

by shadow-hacker

Released in March 2009




Server
Dropped File:
c:\WINDOWS\system32\msisvchost.exe
Size: 619,543 bytes 

Added to Registry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "msisvchost"
Data: C:\Windows\system32\msisvchost.exe 




Tested on Windows XP
April 08, 2009

MegaSecurity