Home Malware Programs Keyloggers Intelliflag Content Monitor

Intelliflag Content Monitor

Posted: March 28, 2006

Intelliflag Content Monitor is a commercial PC surveillance application that logs all user keystrokes, records online chat conversations and web sites visited, captures sent and received e-mail messages. The application sends gathered data to a configurable e-mail address. Intelliflag Content Monitor must be manually installed. It runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 [X].sys
    2 cm_al.exe
    3 cm_ms.exe
    4 cm_yc.exe
    5 cryptkci.dll
    6 em_oe.exe
    7 em_ou.exe
    8 intelliflag.exe
    9 intelliflag_be.exe
    10 km.exe
    11 sm_ie.exe
    12 sm_ns.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunintelliflag_be.exeHKEY_LOCAL_MACHINESOFTWAREClassesSEN10L2.RegistrationHKEY_LOCAL_MACHINESOFTWAREIntelliflagHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionAppPathsintelliflag.exeHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionSharedDLLs\%System%sen10l2.dllHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallIntelliflagContentMonitor_is1
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}E3324155-5645-4D6A-B0F2-89266B291C4F05F35AA2-D3CC-4041-890C-046E9910D6BFBE51DE2E-2FA0-4451-9241-8CFE5A2F9869
Loading...