Home Malware Programs Remote Administration Tools e-Surveiller

e-Surveiller

Posted: March 28, 2006

e-Surveiller is a comprehensive remote administration tool with a rich set of functions. e-Surveiller is a legitimate and quite popular product. Although it is classified as a RAT, it doesn't give the person controlling it a remote control of an affected computer. Instead it monitors and records keystrokes, mouse clicks, instant message conversations, Internet activity and applications used. It also captures online chat conversations, records user passwords and addresses of visited web sites. Gathered data can be sent to a configurable e-mail address or uploaded to a defined FTP server.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 asycfilt.bin
    2 bbjpeg.dll
    3 comcat.bin
    4 deactive.bin
    5 e-surveillerhelp.lnk
    6 e-surveillerlogviewer.lnk
    7 e-surveillerstation.lnk
    8 eshelp.chm
    9 esicons.fon
    10 esread.exe
    11 estation.exe
    12 esupdate.exe
    13 esviewer.chm
    14 install.bin
    15 jpeg32.dll
    16 makensis.exe
    17 mon.bin
    18 msvbvm50.bin
    19 mswinsck.bin
    20 oleaut32.bin
    21 olepro32.bin
    22 readme.lnk
    23 stdole2.bin
    24 uninstall.exe
    25 uninstalle-surveiller.lnk
    26 zlib.dll
    27 zlib.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT.zlgHKEY_CLASSES_ROOTSoftwareMicrosoftWindowsCurrentVersionRunOncee-SurveillerStationHKEY_CLASSES_ROOTSoftwareMicrosoftWindowsCurrentVersionRune-SurveillerStationHKEY_CLASSES_ROOTSoftwareSurveilleTeche-SurveillerHKEY_CLASSES_ROOTe-Surveiller.LogfileHKEY_LOCAL_MACHINESOFTWARESurveilleTeche-SurveillerHKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionUninstalle-Surveiller
Loading...