Home Malware Programs Spyware Spyware.PowerSpy

Spyware.PowerSpy

Posted: February 1, 2011

Spyware.PowerSpy is a spyware program that monitors internet activity and users browsing habits. The infection is dangerous spyware which hackers use to create malicious parasites enabling them to setup a botnet network or password stealing Trojans. Spyware.PowerSpy is sometimes sold to cybercrooks and once in the hands of hackers, Spyware.PowerSpy can be used to create Trojans that are specifically designed to steal login credentials to online banking accounts.

Spyware.PowerSpy is usually found on cybercrime forums where the hackers share the toolkit amongst others. Do not hesitate to remove Spyware.PowerSpy, your hard-earned money will soon be lost if you do not terminate this malware immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ProgramFiles%\SKPCS\COMCTL32.OCX
    2 %ProgramFiles%\SKPCS\data\emxfile.emx
    3 %ProgramFiles%\SKPCS\data\eventsys.exe
    4 %ProgramFiles%\SKPCS\data\ps_demo_report.html
    5 %ProgramFiles%\SKPCS\data\psini.ini

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{48E59290-9880-11CF-9754-00AA00C00908}\1.0\HELPDIR][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6B7E6392-850A-101B-AFC0-4210102A8DA7}\1.3\0\win32][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{86CF1D34-0C5F-11D2-A9FC-0000F8754DA1}\2.0\0\win32][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{86CF1D34-0C5F-11D2-A9FC-0000F8754DA1}\2.0\HELPDIR][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{86CF1D34-0C5F-11D2-A9FC-0000F8754DA1}\2.0][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
Loading...