Home Malware Programs Keyloggers KeyCaptor

KeyCaptor

Posted: March 28, 2006

KeyCaptor is a commercial keylogger that tracks user activity, logs all keystrokes, takes screenshots, captures online chat conversations, records passwords and transfers gathered data to a predetermined remote host. KeyCaptor is able to hide its running processes. The threat must be manually installed. It automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 keycaptor.exe
    2 nostealth.exe
    3 ntinvisible.dll
    4 systemsa32.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunsrv32winHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallKeyCaptor
Loading...