Shang 1.5
(Backdoor.Win32.Shang.15)

by ?

Made in China


Server:
dropped file:
C:\WINDOWS\LoadwinPowerProfile.exe 

size: 152 KB

port: 22554 TCP

startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run 

Added:
c:\WINDOWS\SYSTEM\userloadbak.exe 

MegaSecurity