Home Malware Programs Spyware SpyGatorPro

SpyGatorPro

Posted: March 28, 2006

SpyGatorPro is a malware application that monitors user activity in the Internet, records keystrokes and takes screenshots. SpyGatorPro doesn't distribute itself and must be manually installed. You are highly adviced to get rid of this privacy risk as quickly as possible.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 sgp.exe
    2 spygatorpro.msi

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftInstallerFeatures7C741C4B12D640A43A5FCEB9BBB9650EHKEY_CURRENT_USERSoftwareMicrosoftInstallerProducts7C741C4B12D640A43A5FCEB9BBB9650EHKEY_CURRENT_USERSoftwareMicrosoftInstallerUpgradeCodesBFB2FAA0D27B30648814077FE5D071CBHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorerMenuOrderStartMenu2ProgramsHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionInstallerFoldersC:ProgramFilesSGPHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-21-1645522239-1085031214-839522115-1004Components1F1D4633D18348E4E9C8DA10ACC725ADHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-21-1645522239-1085031214-839522115-1004Products7C741C4B12D640A43A5FCEB9BBB9650EHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunMSRegScan=C:ProgramFilesSGPsgp.exeHKEY_LOCAL_MACHINESOFTWAREThunderTechnologiesInc.SpyGatorProThunderTechnologiesInc.SoftwareSpyGatorPro
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}B4C147C7-6D21-4A04-A3F5-EC9BBB9B56E0
Loading...