ESK
(Trojan-Spy.Win32.KeyLogger.eh)

by ?

Released in October 2004

Made in Poland


Server:
dropped file:
c:\WINDOWS\system32\svchost32.exe
size: 175,735 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "SVCHOST"
data: C:\WINDOWS\system32\svchost32.exe 



tested on Windows XP
June 17, 2005

MegaSecurity