Home Malware Programs Keyloggers Golden Eye

Golden Eye

Posted: March 28, 2006

Golden Eye is a commercial keylogger that records keystrokes, tracks user activity and takes screenshots. Although Golden Eye is not an actual malicious application, it can be used to violate user privacy. The keylogger must be manually installed. It runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 agseyapp.exe
    2 bmptojpg.dll
    3 gehp.dll
    4 kbhook.dll
    5 oleaut32.dll
    6 picclp32.ocx
    7 unins000.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionSharedDLLsC:ProgramFilesAGSeyAppgehp.dll=0x1HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionSharedDLLsC:ProgramFilesAGSeyAppoleaut32.dll=0x1HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionSharedDLLsC:ProgramFilesAGSeyApppicclp32.ocx=0x1HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunAGSeyApp
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}C74190B6-8589-11D1-B16A-00C0F0283628BDD1F04B-858B-11D1-B16A-00C0F028362866833FE6-8583-11D1-B16A-00C0F02836282C247F23-8591-11D1-B16A-00C0F02836281EFB6596-857C-11D1-B16A-00C0F0283628

Related Posts

Loading...