simo downloader 2008
(Trojan-Downloader.Win32.VB.dth)

by sina mohammadi

Written in Visual Basic

Released in March 2008

Made in Iran





Server
Size: 42,029 bytes

Dropped File:
c:\WINDOWS\1stsys.sys
Size: 19 bytes 

Added to Registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Norton"
Data: C:\WINDOWS\system32\WtSiy.exe 



Tested on Windows XP
September 04, 2008

MegaSecurity