XTK 1.0
(Trojan-Spy.Win32.XTK.10)

by XT

Released in May 2005



Server:
dropped files:
c:\WINDOWS\WindowsUpdate.exe    Size: 80,355 bytes 
c:\WINDOWS\XTKLog.txt 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "WindowsUpdate"
data: C:\Windows\WindowsUpdate.exe 



tested on Windows XPP
April 07, 2007

MegaSecurity