Promotion 2.0
(Trojan.Win32.Genome.ahom)
(Trojan-Downloader.Win32.Delf.aqt)

by ?

Written in Delphi

Released in May 2007

Made in China


Server:
dropped file:
c:\Program Files\Common Files\Microsoft Shared\MSInfo\iejore.exe
size: 32,044 bytes 

added to registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell"
old data: Explorer.exe 
new data: Explorer.exe C:\Program Files\Common Files\Microsoft Shared\MSINFO\iejore.exe 



tested on Windows XP
May 14, 2007

MegaSecurity