Home Malware Programs Keyloggers Gorgs

Gorgs

Posted: March 28, 2006

Gorgs is a parasitical keylogger that records all user keystrokes and silently sends gathered data to a predefined e-mail address. Gorgs may also contact a predetermined web server, download from there and execute arbitrary malicious code. The threat automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 gorsys32.dll
    2 svcroot.dll
    3 svcroot.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsNTCurrentVersionWindowsload=%System%svcroot.exeHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunsvcroot=%Windows%svcroot.exe
Loading...