Home Malware Programs Spyware SrchSpy

SrchSpy

Posted: March 28, 2006

SrchSpy is a malware spyware that monitor user Internet activity and tracks his browsing habits. It also may record user web search queries. SrchSpy transfers gathered data to a predefined remote host. The spyware automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 iefilter.dll
    2 msiehelper.dll
    3 service.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoadiefilterHKEY_LOCAL_MACHINESOFTWAREMicrosoftfilterHKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesservice
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}B9D06F5B-5BF3-4BC5-A58F-D1CD948478CE
Loading...