Home Malware Programs Trackware Digi Watcher

Digi Watcher

Posted: March 28, 2006

Watcher is a legitimate commercial software, which uses a PC's webcam to secretly monitor the user. However, it can also be used by malicious persons for obvious illegal purposes. The application does not carry any destructive payload and attempts to hide its presence in the computer. It can upload gathered data to a predefined FTP server or send it to a configurable e-mail address. Watcher must be manually installed. It automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 dgw2avi.exe
    2 keyhook.dll
    3 watcher.exe
    4 watcherntservice.exe
    5 watcherservice.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT.dgwHKEY_CLASSES_ROOTApplicationswatcher.exeHKEY_CLASSES_ROOTDWButton.DWButtonCtrl.1HKEY_CLASSES_ROOTdgw_auto_fileHKEY_CURRENT_USERApplicationsWatcher.exeHKEY_CURRENT_USERSoftwareAudiertHKEY_CURRENT_USERSoftwareClassesApplicationswatcher.exeHKEY_CURRENT_USERSoftwareDigi-WatcherC:HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunLoadWatcherHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallDigi-Watcher.com
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}E2CFC215-A5AD-11D6-8E1A-000086427BAFE2CFC217-A5AD-11D6-8E1A-000086427BAFE2CFC216-A5AD-11D6-8E1A-000086427BAFE2CFC218-A5AD-11D6-8E1A-000086427BAFA4545E47-89CA-11D6-AF8D-000347889858
Loading...