Home Malware Programs Spyware TwoSeven

TwoSeven

Posted: March 28, 2006

TwoSeven is a malware spyware that records keywords the user enters into popular Internet search engines. It sends gathered data to a predetermined web server. TwoSeven may secretly download and install third-party software. The threat doesn't spread and must be manually installed. It runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 mswinindex.exe
    2 winfnd-b.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunmmxrun=C:ProgramFiles000000mswinindex.exeHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionmmxrunflag
Loading...