Home Malware Programs Keyloggers OverSpy

OverSpy

Posted: March 28, 2006

OverSpy is a commercial PC surveillance application that monitors softwares used, tracks user Internet activity, logs keystrokes, takes screenshots, captures online chat conversations, records incoming and outgoing e-mail messages. Gathered data can be sent to a configurable e-mail address. OverSpy must be manually installed. The application runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 doublehook.dll
    2 hook.dll
    3 ntqsi.dll
    4 overspy.exe
    5 uninshs.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareVirtuozaOverSpyHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunscvhostHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallOverSpy_is1
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}AE40EBA0-2D49-48C9-BA8D-E9F046240F5FA9D098F3-3FD5-3675-A210-58704085A191

Related Posts

Loading...