Shade 2.0
(Trojan-PSW.Win32.Agent.iu for Client)
(Backdoor.Win32.Hupigon.dup)

by Hackcsy

Released in April 2007

Made in China





Server
dropped file:
c:\WINDOWS\system32\iexplorer.exe
size: 300,952 bytes 

added to registry:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FyServer_2003 "ImagePath"
data: C:\WINDOWS\System32\iexplorer.exe -NetSata 

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FyServer_2003 "ImagePath"
data: C:\WINDOWS\System32\iexplorer.exe -NetSata 	
	
tested on Windows XP
June 16, 2007

MegaSecurity