Shalan 1.06
(HackTool.Win32.VB.age)
(Trojan-PSW.Win32.VB.fl)

by Red Move

Written in Visual Basic, compressed with UPX

Released in December 2005

more versions


Shalan is a pass sender that can send Yahoo Messenger & ICQ passwords to you.

--------
Features
--------
+ Both email and cgi logger notificatDon.
+ Fake message at double click on server.
+ Run file at double click on server.
+ Able to change icon.
+ Binder.
+ Firewall bypassing.
+ Undetectable by anti viruses.
+ Not shown in msconfig.
+ Diabolic startup
+ Server size is about 13.5 KB

Version 1.06 - December/22/2005
   * Mail Sending bug fixed.
   

Red Move


Server:
dropped file:
c:\WINDOWS\system32\Mscng.exe
size: 13,362 bytes 

startup:
HKEY_CLASSES_ROOT\exefile\shell\open\command "(Default)"
old data: "%1" %* 
new data: Mscng.exe opext "%1" %* 

tested on Windows XP
January 23, 2006

MegaSecurity