Threat Search: 

ThreatExpert's Statistics for Win32/Shlnom [AhnLab]:

Win32/Shlnom [AhnLab] is also known as:
Threat AliasNumber of Incidents
Troj/Agent-FXF [Sophos]7
Trojan-Spy.Win32.Agent.afn [Kaspersky Lab]7
W32.Xema.A!inf [Symantec]7
W32/Xema [McAfee]6
TrojanDropper:Win32/Dunik!rts [Microsoft]2
Trojan-Spy.Agent!sd6 [PC Tools]2
TrojanSpy.Agent.DKZR [PC Tools]2
Trojan-Spy.Win32.Agent.qj [Ikarus]2
Virus.Trojan.Win32.VB [Ikarus]1

Win32/Shlnom [AhnLab] has the following possible country of origin:
OriginNumber of Incidents
China3

Win32/Shlnom [AhnLab] is known to be created as:
%System%\shlmon.exe
Note: %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).