H.D.E. Spy 2.1.5
(Trojan-PSW.Win32.VB.ge)

by Shell32.dll

Written in Visual Basic

Released in August 2005

Made in Turkey


Server:
dropped files:
c:\Program Files\Common Files\System\aemail.zpd         Size: 84,641 bytes 
c:\Program Files\Common Files\System\Office10.exe       Size: 73,728 bytes 
c:\Program Files\Common Files\System\picformat32.zpd    Size: 40,960 bytes 
c:\Program Files\Common Files\System\picformat32.zpo    Size: 6,767 bytes 
c:\WINDOWS\system32\Aemail.dll                          Size: 184,320 bytes 
c:\WINDOWS\system32\picformat32.ocx                     Size: 36,864 bytes 
c:\WINDOWS\system32\zlib.dll                            Size: 53,248 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "MS Office"
data: C:\Program Files\Common Files\System\Office10.exe 


tested on Windows XP
February 24, 2006

MegaSecurity