IE-AU PS 1.3.5
(Trojan-PSW.Win32.VB.ig)
(Not detected by KAV for Server on May 07, 2006)

by Pwin pooya

Written in Visual Basic

Made in The Middle East

more versions





Server:
dropped files:
c:\WINDOWS\system32\regsvr.exe
size: 31,232 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "regsvr.exe"
data: C:\WINDOWS\System32\regsvr.exe sysdir 	




tested on Windows XP
May 07, 2006

MegaSecurity