Home Malware Programs Spyware HSLAB Logger

HSLAB Logger

Posted: March 28, 2006

HSLAB Logger is a commercial PC monitoring tool that tracks user activity and records user actions in the Internet. It sends gathered information to a predefined e-mail address. The person controlling HSLAB Logger can use it to restrict access to installed software, computer tools or removable media. He can also terminate a specified software, eject a disk, restart or shutdown a PC. HSLAB Logger must be manually installed. It runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 closeproduct.dll
    2 hscc.exe
    3 hslab-logger.exe
    4 killdll.dll
    5 kpr.exe
    6 la.exe
    7 logger.exe
    8 uncl.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareHSLABHSLABLoggerHKEY_CURRENT_USERSoftwareHSLABSoftwareImagesPathsla.exeHKEY_CURRENT_USERSoftwareHSLABSoftwareImagesPathslogger.exeHKEY_CURRENT_USERSoftwareHSLABSoftwarePRODUCTSHSLABCustomerCareCenterHKEY_CURRENT_USERSoftwareHSLABSoftwarePRODUCTSHSLABLoggerHKEY_CURRENT_USERSoftwareHSLABSoftwarePRODUCTSPIDla.exeHKEY_CURRENT_USERSoftwareHSLABSoftwarePRODUCTSPIDlogger.exeHKEY_LOCAL_MACHINESOFTWAREHSLABHSLABLoggerHKEY_LOCAL_MACHINESOFTWAREHSLABSoftwarePRODUCTSHSLABCustomerCareCenterHKEY_LOCAL_MACHINESOFTWAREHSLABSoftwarePRODUCTSHSLABLoggerHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunHSLABLoggerHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallHSLABLogger
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}EFE1AD22-9A07-47FF-AFC5-E5042F1DA5C4FBFF3C64-19E5-7555-4CCF-D68F45A4AA43E9E85E5B-A066-4A7C-DA9B-07BF9D0291DD44D0E7B9-1615-48BF-99B9-EF50ADAC8943
Loading...