Home Malware Programs Keyloggers not-a-virus:RemoteAdmin.Win32.eSurveiller.120

not-a-virus:RemoteAdmin.Win32.eSurveiller.120

Posted: November 26, 2009

not-a-virus:RemoteAdmin.Win32.eSurveiller.120 is a malicious spyware keylogging program that is designed to monitor and record computer actions including online activity. not-a-virus:RemoteAdmin.Win32.eSurveiller.120 is used for corrupt purposes and steals personal information such as login usernames and passwords from an unsuspecting computer user. Hackers created not-a-virus:RemoteAdmin.Win32.eSurveiller.120 to compromise financial accounts over the Internet. Once detected not-a-virus:RemoteAdmin.Win32.eSurveiller.120 should immediately be removed.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\smsystem.exe
    2 %System%\smsystem.ini
    3 %System%\smsystem.tmp
    4 %System%\zlib.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Classes\CLSID\{0000002F-0000-0000-C000-000000000046}\InprocServer32][HKEY_CURRENT_USER\Software\Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32][HKEY_CURRENT_USER\Software\Classes\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32][HKEY_CURRENT_USER\Software\Classes\CLSID\{00020422-0000-0000-C000-000000000046}\InprocServer32][HKEY_CURRENT_USER\Software\Classes\CLSID\{00020423-0000-0000-C000-000000000046}\InprocServer32][HKEY_CURRENT_USER\Software\Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32][HKEY_CURRENT_USER\Software\Classes\CLSID\{00020425-0000-0000-C000-000000000046}\InprocServer32][HKEY_CURRENT_USER\Software\Classes\CLSID\{0BE35203-8F91-11CE-9DE3-00AA004BB851}\InprocServer32][HKEY_CURRENT_USER\Software\Classes\CLSID\{0BE35204-8F91-11CE-9DE3-00AA004BB851}\InprocServer32][HKEY_CURRENT_USER\Software\Classes\CLSID\{46763EE0-CAB2-11CE-8C20-00AA0051E5D4}\InprocServer32][HKEY_CURRENT_USER\Software\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32]
Loading...