Home Malware Programs Keyloggers SpymodePCSpy

SpymodePCSpy

Posted: March 28, 2006

SpymodePCSpy appears to be a legitimate software published by SpyMode company. However, it can be successfully used by the attacker to violate your privacy. SpymodePCSpy is a keylogger that secretly works in background and records all your keystrokes, tracks your activity in the Internet, steals passwords and other sensitive information.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 main.exe
    2 memaker2.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOTMSWinsock.WinsockHKEY_CLASSES_ROOTMSWinsock.Winsock.1HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunpst=C:WindowsSystemmemaker2.exeHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionwrn=unr
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}248DD890-BB45-11CF-9ABC-0080C7E7B78D248DD893-BB45-11CF-9ABC-0080C7E7B78D248DD892-BB45-11CF-9ABC-0080C7E7B78D248DD897-BB45-11CF-9ABC-0080C7E7B78D248DD896-BB45-11CF-9ABC-0080C7E7B78D
Loading...