Home Malware Programs Keyloggers SystemSleuth

SystemSleuth

Posted: March 28, 2006

SystemSleuth is a commercial PC surveillance application that monitors user activity, logs keystrokes, takes screenshots, records online chat conversations, captures incoming and outgoing e-mail messages, records web sites visited. SystemSleuth stores gathered data in encrypted log files. These files can be sent to a configurable e-mail address. The application must be manually installed. It runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 ddss.exe
    2 ddssdemo.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftInstallerFeaturesEA50A778F651BE748AF9CBF6C24D2981HKEY_CURRENT_USERSoftwareMicrosoftInstallerProductsEA50A778F651BE748AF9CBF6C24D2981HKEY_CURRENT_USERSoftwareMicrosoftInstallerUpgradeCodes6B7C89967F8073B489687CEA2A1D9744HKEY_LOCAL_MACHINESOFTWAREDivineDownloadsSystemSleuthHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionInstallerFoldersC:ProgramFilesDDSSHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionInstallerFoldersC:ProgramFilesDDSSDemoHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionInstallerUpgradeCodes6B7C89967F8073B489687CEA2A1D9744HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunmsregscan
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}877A05AE-156F-47EB-A89F-BC6F2CD49218
Loading...