Home Malware Programs Trojans MonitoringTool:Win32/Powerspy

MonitoringTool:Win32/Powerspy

Posted: March 28, 2011

Threat Metric

Threat Level: 8/10
Infected PCs: 26
First Seen: March 28, 2011
OS(es) Affected: Windows

MonitoringTool:Win32/Powerspy aka Powerspy, is a keylogger that has the ability to record computer activity. MonitoringTool:Win32/Powerspy may record keystrokes on an infected PC where passwords and login information may be stolen and then accessed by a remote attacker. MonitoringTool:Win32/Powerspy has even been known to send recorded data to a pre-set server over a network or internet. It is essential that a keylogger such as MonitoringTool:Win32/Powerspy be detected and safely removed with a malware removal app before it causes irreversible destruction.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 adsnwm.exe
    2 wnaspid.exe

Aliases

Logger.JCN [AVG]Riskware/PowerSpy [Fortinet]Trojan-Spy.Win32.KeyLogger [Ikarus]Monitor/Win32.PowerSpy.gen [Antiy-AVL]SPR/PowerSpy.aed [AntiVir]not-a-virus:Monitor.Win32.PowerSpy.bwj [Kaspersky]Win32.SPRPowerSpy.Ae [eSafe]Win32:PowerSpy-S [PUP] [Avast]Spyware.AIMSniffer [Symantec]Suspicious file [Panda]Spy/PowerSpy [Fortinet]Gen:Trojan.Heur.bm0@X8Hm4Sdi [BitDefender]a variant of Win32/PowerSpy.AA [NOD32]Spyware-PowerSpy [McAfee]Trj/CI.A [Panda]
More aliases (39)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\System32\wnaspid.exe File name: wnaspid.exe
Size: 24.57 KB (24576 bytes)
MD5: cbb6b0683f3b83d068f1064bf8370140
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\System32
Group: Malware file
Last Updated: June 13, 2011
%WINDIR%\system32\winsvc.exe File name: winsvc.exe
Size: 20.48 KB (20480 bytes)
MD5: b35acfba8362e375684e0a3a70a7b9ef
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: March 28, 2011

More files

Related Posts

Loading...