Home Malware Programs Keyloggers Handy Keylogger

Handy Keylogger

Posted: March 28, 2006

Handy Keylogger is a commercial PC surveillance tool that tracks user activity, logs all keystrokes, takes screenshots, captures online chat conversations and outgoing e-mail messages, records passwords and addresses of visited web sites. Logs can be sent to a configurable e-mail address or saved to a hard disk. Handy Keylogger must be manually installed. The application runs on every Windows startup and hides its processes.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 hlib32.dll
    2 hutils.dll
    3 qutils.dll
    4 register.bat
    5 setup.exe
    6 shadow32.exe
    7 svchost.exe
    8 trace.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftRFC1156AgentHKEY_LOCAL_MACHINESOFTWAREMicrosoftWABCOMHKEY_LOCAL_MACHINESYSTEMControlSet001ServicessvchostHKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicessvchost
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}D8F6A9AF-4F03-88BB-298B-F16260E36C29

Related Posts

Loading...