Home Malware Programs Keyloggers Anserin

Anserin

Posted: March 28, 2006

Anserin is a parasitic keylogger, which records all the keystrokes that the user enters on certain online banking web site. Gathered data may be sent to the remote attacker. Anserin uses a large list of banking and financial Internet resources. It automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 ibm[X].exe
    2 kl.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunShell=C:ProgramFilesCommonFilesMicrosoftSharedWebFoldersibm[X].exeHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonShell=explorer.exe[spacecharacters]C:ProgramFilesCommonFilesMicrosoftSharedWebFoldersibm[X].exe
Loading...