Home Malware Programs Keyloggers CompuSpy

CompuSpy

Posted: November 26, 2008

CompuSpy is a commercial key logger and intelligence gathering application. CompuSpy records all your keystrokes and mouse clicks. CompuSpy will also monitor and track the websites you visit, your emails, chats and converstions that you have through instant messengers. CompuSpy is designed primarily for logging your keystrokes, stealing passwords, and sensitive personal information. CompuSpy may be installed for legitimate reasons such as monitoring children and employee's internet activity.

Unfortunately, it can be used by someone with malevolent intentions to steal sensitive private information such as credit card and online banking information causing possible identity theft and significant financial loss. CompuSpy changes Windows registry and enables autorun on boot. CompuSpy configures ports, IP addresses, router IP and other important security function features. CompuSpy often goes unnoticed as it functions in the background and conceals its nefarious activities.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ProgramFiles%\CompuSpy\CompuSpy.exe
    2 %ProgramFiles%\CompuSpy\CompuSpy.ini
    3 %ProgramFiles%\CompuSpy\etCrypto.dll
    4 %ProgramFiles%\CompuSpy\license.txt
    5 %ProgramFiles%\CompuSpy\log\CompuSpy.log
    6 %ProgramFiles%\CompuSpy\log\CompuSpy_12PM.log
    7 %ProgramFiles%\CompuSpy\readme.txt
    8 %ProgramFiles%\CompuSpy\un_CompuSpySetup_19849.exe
    9 %ProgramFiles%\CompuSpy\un_CompuSpySetup_19849.txt

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"CompuSpy KeyLogger" = "C:\Program Files\CompuSpy\cswin2008.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\CompuSpy KeyLoggerHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\cswin2008.exeHKEY_LOCAL_MACHINE\SOFTWARE\Upsilon DynamicsHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"CompuSpy" = "C:\Program Files\CompuSpy\CompuSpy.exe"HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}CompuSpy KeyLogger
Loading...