Comment I tried it myself... (Score 2, Informative) 166
...from the Metasploit framework. That exploint was a champ. 99.9% guaranteed remote trojan installation. In fact, it was enough just to HOVER OVER the file in a directory so that Explorer would try to get its properties - and ooops.