Home Malware Programs Keyloggers WinWhatWhere

WinWhatWhere

Posted: March 28, 2006

WinWhatWhere is a commercial PC surveillance product that tracks user activity, monitors computer events, logs all keystrokes, takes screenshots, captures online chat conversations and e-mail messages, records passwords and web sites visited. It regularly sends gathered data to a configurable e-mail address. WinWhatWhere must be manually installed. It may automatically run on Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 _isreg32.dll
    2 express.exe
    3 il40.exe
    4 msdfcng.exe
    5 msegcng.exe
    6 updsem.exe
    7 winsdoc16.sys
    8 winsdoc32.sys
    9 winsdoc8.sys
    10 winsutl.exe
    11 xpress.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionAppPathsmsdfcng.exeHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWinWhatWhere
Loading...