Home Malware Programs Keyloggers Power Spy

Power Spy

Posted: March 28, 2006

PowerSpy is a spyware program that offers you keylogging, screen captures, and other standard spyware functionality, with the justification that these features can be used to monitor computer-based activities. However, despite a seemingly benign purpose, PowerSpy will actually attack your control over your own computer. Common symptoms of a PowerSpy infection include a disabled Task Manager, random system shutdowns, general performance degradation and unusual usage of system resources. Even though PowerSpy may do everything that PowerSpy claims to do and more, the additional 'features' make PowerSpy a hazard to any PC, and you should remove PowerSpy with great haste and a good anti-virus program whenever possible.

Don't Start Thinking That PowerSpy is a 'Good' Spy

PowerSpy is also marketed with the name PowerSpy, and in all cases pretends to be a helpful monitoring tool that lets parents watch over their children. Some websites affiliated with PowerSpy include ematrixsoft.com and topsecretsoftware.com. These sites go into great detail about the various computer-monitoring and information-recording features that topsecretsoftware.com has, which are identical to the functions of any typical keylogger.

These websites even let hapless visitors try out PowerSpy for free, but there's a catch – PowerSpy is a spy on you, as well! As soon as PowerSpy is installed, you'll be subjected to a variety of attacks on your security and general system performance. Unfortunately, all of this is also backed up by PowerSpy's painfully honest marketing:

"Complete [sic] INVISIBLE to computer users – No trace in Add/Remove Programs, Start menu, Applications and Windows Task Manager. No trace on Desktop Taskbar, System Tray, and Windows Explorer."

What PowerSpy's marketing doesn't tell you is that these drawbacks apply to you, as well, and make PowerSpy just as difficult for you to remove as it would be for anyone else.

Your safest course of action in this situation is to switch to Safe Mode with Networking, which can be accessed with F8 during a reboot. This will launch Windows with only a bare minimum of processes, and let you find the appropriate anti-malware program to detect and get rid of PowerSpy.

PowerSpy's Bad Spy Tricks

Along with all of PowerSpy's spyware-related functions, PowerSpy will also use other attacks to limit your ability to combat PowerSpy. Your ability to access Task Manager with Ctrl+Alt+Delete may be disabled, and other Windows programs like MSConfig and Regedit may also be blocked.

PowerSpy may also force your PC to shutdown at random intervals, or to prevent you from using security-related software.

PowerSpy will also register .dll files, send email messages with an internal SMTP client engine, and may even download files without your permission. Despite being installed voluntarily in most cases, PowerSpy is clearly no less threatening than any Trojan or virus; manually uninstalling PowerSpy is, therefore, highly discouraged.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 pcjb.exe
    2 psuser.ini
    3 regsvcdll.exe
    4 windll32.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunegsvcdll

Related Posts

2 Comments

  • waterwolt says:

    I have installed Power Spy Portable with crack. After installation it appears on the monitor and shows a link to disappear it. When i click he link, it opens its website and ask me to uy the softwate to disappear from the monitoru.
    It neither appear in spy wear monitor scanning nor task manager. How can i delete it from my system.

  • nini says:

    I want to uninstall it

Loading...