Home Malware Programs Spyware WebMail Spy

WebMail Spy

Posted: March 28, 2006

WebMail Spy is a commercial malware product designed especially for e-mail monitoring. It records all the e-mail messages received or sent using Microsoft Outlook, Microsoft Outlook Express, Eudora or other mail applications. WebMail Spy also captures all the letters from online mail services such as MSN Hotmail, AOL Mail, Yahoo! Mail, ICQ Mail and others. The software allows to disable standard computer tools like Task Manager and prevent a PC from entering into Safe Mode. This can be done in order to complicate malware detection. WebMail Spy must be manually installed. It secretly runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 webmailspy.exe
    2 wmssys32.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystemDisableTaskMgr=0x1HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun1wincfg32HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonIgnoreShiftOveride=0x1
Loading...