Soheil-PS 1.0
(Trojan-Dropper.Win32.VB.mp)

by Soheil

Written in Visual Basic

Made in The Middle East





Server:
dropped files:
c:\WINDOWS\system\shell32.dll    Size: 114 bytes 
c:\WINDOWS\system\svchost.exe    Size: 49,664 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell"
old data: Explorer.exe 
new data: Explorer.exe C:\WINDOWS\system\svchost.exe 



tested on Windows XP
August 23, 2006

MegaSecurity