Home Malware Programs Trojans Kwoo

Kwoo

Posted: March 28, 2006

Kwoo is a trojan that records user keystrokes and sends gathered data to a predetermined remote web server. It also silently downloads from this server, installs and runs unsolicited software without asking for user permission. Kwoo may change the Internet Explorer default home page and Windows wallpaper. The spyware automatically runs as a service on every computer startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 msuls.exe
    2 msusc.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainStartPage=[websiteaddress]HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesWindowsNetworkingAgent
Loading...