It creates a process by injecting itself into "svchost.exe". This backdoor also shows rootkit behavior and attempts to establish a remote connection with the web server: hxxp://1XX.1XX.XX0.XX:80
“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4