Acidsena
(Backdoor.Win32.Acidsena)

by ?

Written in Visual Basic


Server:
dropped file:
C:\WINDOWS\SYSTEM\RUNDLL32.EXE 

size: 116 KB

startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run "Emxuldn" 
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "Eqlevgj" 
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices "Aht" 

MegaSecurity