Home Malware Programs Keyloggers Hazif.b

Hazif.b

Posted: March 28, 2006

Hazif.b is a parasitic keylogger, which records user keystrokes in attempt to steal Yahoo! Messenger passwords and account details. The threat can also gather other user sensitive information. Hazif.b periodically sends collected data to a predetermined contact using an instant messenger. The keylogger automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 spoolsv32.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunspoolsv32=%System%spoolsv32.exe
Loading...