Pixcher Bot 1.1
(Backdoor.Win32.Agent.aih)
(Backdoor.Win32.Small.cjz)

by ?

Released in October 2006

Made in Russia


Server:
dropped file:
c:\WINDOWS\troi.exe
size: 11,776 bytes 

added to registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell"
old data: Explorer.exe 
new data: Explorer.exe troi.exe

tested on Windows XP
February 15, 2007

MegaSecurity