Home Malware Programs Spyware SearchPounder

SearchPounder

Posted: March 28, 2006

SearchPounder is a malware spyware that monitors user activity in the Internet and records keywords that the user enters into popular Internet search engines and many web sites. SearchPounder sends gathered data to its home server. The spyware can be installed by some advertising applications.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 pounder.exe
    2 sysmonnt.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREClassesInetCtls.InetHKEY_LOCAL_MACHINESOFTWAREClassesInetCtls.Inet.1HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunsysmonnt=%System%sysmonnt.exe
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}48E59290-9880-11CF-9754-00AA00C0090848E59292-9880-11CF-9754-00AA00C0090848E59291-9880-11CF-9754-00AA00C0090848E59295-9880-11CF-9754-00AA00C0090848E59294-9880-11CF-9754-00AA00C0090848E59293-9880-11CF-9754-00AA00C00908
Loading...