Home Malware Programs Keyloggers Kbroy

Kbroy

Posted: March 28, 2006

Kbroy, also known as Maha, is a parasitic keylogger that records all user keystrokes in attempt to steal important passwords and login names. Gathered data might be transferred to the remote attacker. Kbroy also changes some Internet Explorer settings and disables the Windows Firewall. The keylogger automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 sqlserver.dll
    2 winupgrm.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainFormSuggestPWAsk=noHKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainFormSuggestPasswords=noHKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainUseFormSuggest=noHKEY_LOCAL_MACHINESOFTWAREMicrosoftActiveSetupInstalledComponentswinctrlHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunwinctrlHKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesRasManParametersDisableSavePassword=1HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileDisableNotifications=1HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileEnableFirewall=0

Related Posts

Loading...