Home Malware Programs Keyloggers Topfox

Topfox

Posted: March 28, 2006

Topfox is a malicious keylogger that monitors software windows for predefined keywords and records all the user's input entered into many fields in such windows. Topfox also monitors conversations in running instant messengers and may log user keystrokes. Gathered data is sent to a predetermined e-mail address. The keylogger terminates running processes of certain software, attempts to download and execute arbitrary files. It is able to inject malicious code into active tasks in order to hide itself from the user and log keystrokes. Topfox automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 ntkrnl.dll
    2 svch0st.exe
    3 wdata32.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunsvchostHKEY_USERS[CurrentUserID]SoftwareClasses(Default)=%System%svch0st.exeHKEY_USERS[CurrentUserID]_Classes(Default)=%System%svch0st.exe
Loading...