Home Malware Programs Keyloggers System Spy

System Spy

Posted: March 28, 2006

System Spy is a discontinued commercial keylogging application designed to track user activity, monitor computer events, log keystrokes and mouse clicks, record passwords and addresses of visited web sites. System Spy must be manually installed. It secretly runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 analyzer.exe
    2 ss.exe
    3 sysmon.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINEsoftwareclassescryptxctl.cryptxclsidHKEY_LOCAL_MACHINEsoftwareclassesvblibrary.vblibclsidHKEY_LOCAL_MACHINEsoftwaregbytesoftwaresetupcurrentversionuninstallspecialistsystemspy@vv1.00(tbproducts)HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionuninstallsystemspyv1.00uninstallstringame
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}fbb3c009-6d14-11d2-9e37-813a750b363dfbb3c007-6d14-11d2-9e37-813a750b363dfbb3c006-6d14-11d2-9e37-813a750b363dfbb3c003-6d14-11d2-9e37-813a750b363dfbb3c001-6d14-11d2-9e37-813a750b363dfbb3c000-6d14-11d2-9e37-813a750b363d4b447067-9f42-11d2-90f1-4445535400004b447063-9f42-11d2-90f1-4445535400004b447062-9f42-11d2-90f1-44455354000045070aee-e66c-11d1-b0ac-444553540000104e51dd-c011-11d1-9c65-70a605c10e27104e51dc-c011-11d1-9c65-70a605c10e27104e51db-c011-11d1-9c65-70a605c10e27104e51da-c011-11d1-9c65-70a605c10e27

Related Posts

Loading...