Home Malware Programs Trojans Usblog

Usblog

Posted: March 28, 2006

Usblog is a trojan designed to record all user keystrokes and send gathered data to the attacker. It also secretly downloads from the Internet and runs arbitrary files. Usblog may also attempt to steal e-mail account details stored in Microsoft Outlook. The trojan works as an Internet Explorer add-on and therefore runs every time the user launches the web browser.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 rpc32.dll

Registry Modifications

  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}6166DA6E-9EE3-4A5B-8A84-F543CC942CBE
Loading...