Home Malware Programs Keyloggers Stranget

Stranget

Posted: March 28, 2006

Stranget is a dangerous parasitical keylogger that records user keystrokes and steals many passwords. It also collects information about the infected computer and its network configuration, terminates running processes of most more or less popular antivirus applications, firewalls and other security-related software. Stranget sends gathered data to a predefined e-mail address or uploads it to a predetermined FTP server. The threat can download and execute arbitrary potentially harmful files. It is also able to regularly update itself via the Internet. Stranget runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 mn32.dll
    2 nm32.exe
    3 ~url.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInstallDateHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInstallPathHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunujmHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionUpdate2
Loading...