Home Malware Programs Malware Chat Watch

Chat Watch

Posted: March 28, 2006

Chat Watch is a commercial malware software designed especially to record private online chat conversations made using ICQ, AIM, MSN Messenger, Windows Messenger, Yahoo! Messenger and few other applications. The software can send the log to a configurable e-mail address. Chat Watch is able to hide its running processes by disabling standard computer tools. It may also completely deny access to all installed messengers. The threat must be manually installed. It runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 cw.exe
    2 smtp.ocx

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRuncwatch
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}9CCD14D6-ABE0-44BF-8F04-29E59D2CDA5D42F1591E-830C-11D2-BBDE-0055003B26DE1AB22F59-FB66-4A06-BCA9-EA5A6D5785E0
Loading...