avkhackteam keylogger
(Trojan-Spy.Win32.KeyLogger.qe)

by avkhackteam


Released in May 2007


Server
dropped file:
c:\WINDOWS\Resources\server.exe
size: 143,161 bytes 

port: 337 TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Microsoft Updater"
data: C:\WINDOWS\Resources\server.exe 



tested on Windows XP
May 30, 2007

MegaSecurity