Home Malware Programs Remote Administration Tools IE Watcher

IE Watcher

Posted: March 28, 2006

IE Watcher is a commercial Internet surveillance application that tracks user online activity and records addresses of visited web sites. Gathered data is transferred to the attacker. IE Watcher is a client/server software. It can also be used to terminate running web browser processes and send messages to the monitored user. The application must be manually installed. IE Watcher runs every time the monitored user logs on the Internet.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 iewatch20.exe
    2 sn_client.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionInstallerUpgradeCodesEAB51286E37F57342B8CFF6E6B117052HKEY_USERSSoftwareMicrosoftInstallerFeatures52B930E8E8DEB3345A1CFD7959AF9B63HKEY_USERSSoftwareMicrosoftInstallerProducts52B930E8E8DEB3345A1CFD7959AF9B63HKEY_USERSSoftwareMicrosoftInstallerUpgradeCodesEAB51286E37F57342B8CFF6E6B1170
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}8E039B25-ED8E-433B-A5C1-DF9795FAB936
Loading...