Home Malware Programs Keyloggers NS Keylogger

NS Keylogger

Posted: March 28, 2006

NS Keylogger is a commercial PC surveillance application that tracks user activity in the Internet, logs all keystrokes, takes screenshots, records passwords and captures chat conversations. Gathered data is saved to a hard disk. NS Keylogger must be manually installed. The risk runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 appdata.dll
    2 configs.ini
    3 gdiplus.dll
    4 keylogger.dll
    5 messenger.dll
    6 services.exe
    7 winlogon.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREClassesNiceRecorderDll.AboutBoxHKEY_LOCAL_MACHINESOFTWAREClassesNiceRecorderDll.AboutBox.1HKEY_LOCAL_MACHINESOFTWAREClassesNiceRecorderDll.ExplorerHKEY_LOCAL_MACHINESOFTWAREClassesNiceRecorderDll.Explorer.1HKEY_LOCAL_MACHINESOFTWAREClassesNiceRecorderDll.HotkeyControlHKEY_LOCAL_MACHINESOFTWAREClassesNiceRecorderDll.HotkeyControl.1HKEY_LOCAL_MACHINESOFTWAREClassesNiceRecorderDll.LoginBoxHKEY_LOCAL_MACHINESOFTWAREClassesNiceRecorderDll.LoginBox.1HKEY_LOCAL_MACHINESOFTWAREClassesNiceRecorderDll.MailSettingHKEY_LOCAL_MACHINESOFTWAREClassesNiceRecorderDll.MailSetting.1HKEY_LOCAL_MACHINESOFTWAREClassesNiceRecorderDll.MonitorControlHKEY_LOCAL_MACHINESOFTWAREClassesNiceRecorderDll.MonitorControl.1HKEY_LOCAL_MACHINESOFTWAREClassesNiceRecorderDll.PasswordControlHKEY_LOCAL_MACHINESOFTWAREClassesNiceRecorderDll.PasswordControl.1HKEY_LOCAL_MACHINESOFTWAREClassesNiceRecorderDll.RegisterBoxHKEY_LOCAL_MACHINESOFTWAREClassesNiceRecorderDll.RegisterBox.1HKEY_LOCAL_MACHINESOFTWAREClassesNiceRecorderDll.RegisterTipHKEY_LOCAL_MACHINESOFTWAREClassesNiceRecorderDll.RegisterTip.1HKEY_LOCAL_MACHINESOFTWAREClassesNiceRecorderDll.SetPasswordBoxHKEY_LOCAL_MACHINESOFTWAREClassesNiceRecorderDll.SetPasswordBox.1HKEY_LOCAL_MACHINESOFTWAREClassesNiceRecorderDll.SettingBoxHKEY_LOCAL_MACHINESOFTWAREClassesNiceRecorderDll.SettingBox.1HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunSysService=C:ProgramFilesNSkeyloggerservices.exe
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}6E9B9701-EDEF-4D00-804C-FD23644C0131F4C9FA0B-4E73-41B4-BBBB-B680AB4F9C9DBF9BCED1-67F2-43DE-8351-16DF6520B7BCBDAEB579-3B30-46BF-9BFD-D2F48862BB848B7971F3-4BD8-43A4-A432-5A80DB640BA983C02270-7BC9-444E-ADBF-E7AEBA849154761EA5D9-5171-432D-99A7-282109373EB86B8443A7-E6C9-432D-8AD2-43728F69616869B1417C-A1EB-4049-86B8-9CBE318E2B1D552D3DF3-F32A-459A-8C26-45AD5C1D987C3D1F63A7-CE32-46EC-8E45-53733227E71B252A0AFD-BA48-4CA3-98AD-022B58BD0185

Related Posts

Loading...