IMP-PS 1.0
(Trojan-PSW.Win32.Agent.ay)

by Mahdi Hezavehi

Written in Delphi

Released in July 2006


Server:
dropped files:
c:\WINDOWS\smlogitech.vbs
size: 179 bytes 

deleted file:
c:\WINDOWS\system32\Restore\MachineGuid.txt

added to registry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Explorer32"
data: C:\WINDOWS\xplorer.exe 

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_DLLCACH\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DllCach
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\C
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_DLLCACH\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DllCach


tested on Windows XP
July 04, 2006

MegaSecurity