Home Malware Programs Spyware TSPY_EYEBOT.A


Posted: February 12, 2010

TSPY_EYEBOT.A is a malicious spyware program that monitors and gathers user information for malicious purposes. TSPY_EYEBOT.A will run in the background and inadvertently con users to agree to installing the spyware program by accepting the End User License Agreement on certain free software. TSPY_EYEBOT.A uses invasive methods to gather personal data such as passwords and usernames. TSPY_EYEBOT.A may also cause a general degradation in both network connection and system performance. Use a reliable anti-spyware program to remove TSPY_EYEBOT.A immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System Root%\cleansweep.exe
    2 %System Root%\cleansweep.exe\cleansweep.exe - also detected as TSPY_EYEBOT.A
    3 %System Root%\cleansweep.exe\config.bin - non-malicious file

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunHKEY..\..\..\..{RegistryKeys}cleansweep.exe = "%System Root%\cleansweep.exe\cleansweep.exe"