Home Malware Programs Backdoors Spymon

Spymon

Posted: March 28, 2006

Spymon is a backdoor, which provides the attacker with unauthorized remote access to a compromised PC. It allows the intruder to control the entire computer and steal user sensitive information. Spymon automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 cds.exe
    2 ds.exe
    3 ds.prefs
    4 hook.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersioncdsHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRuncdsHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunds

Related Posts

Loading...