PaqKeylog
|
Description:
|
Spyware
|
|
Risk Level:
|
None
|
|
Date of First Occurence:
|
Wednesday, April 23, 2008
|
|
Software Developer:
|
(unknown)
|
|
Brief Info:
|
Keyloggers invisibly monitor and record all of your computer activity. This information is then automatically emailed to an anonymous user.
|
|
Removal:
|
This threat can be removed using "Spyware
Terminator"
|
ENTFERNEN SPYWARE »
Geographical Distribution of Threat "PaqKeylog"
Threat Info
View All
Detected Items
- Detected Files:
%SYSDIR%\golyy5dd1.dll
MD5: 799084428E7CAEDBB6561F9F52526F6E Size:1731
MD5: 4F9E7A1648D2F5952E43C0DF0EB1CE37 Size:1731
MD5: 9CCA0F3C5320B16300695749154F3DB8 Size:1731
MD5: A8194F7E1FA6077EA6F282D5D90828DA Size:1731
MD5: 12AB55F22944C84DB4BAB1B9C473A3A3 Size:1731
MD5: E2A6F8AA98CA2213693730A77F487C08 Size:1731
MD5: 8766A27860AAB787C31BA40167633965 Size:1731
MD5: EC8F4BFBA7717901D54B3C9F4D76657F Size:1731
MD5: 62802AD7CFA47F47C8CA8D57FA49B2DF Size:1731
MD5: 55F85F0CF834EDA46A9B11F1D2FE00C9 Size:1731
MD5: 734A4223D9F2E905B9ACC26749290267 Size:1731
MD5: A2752C0A9028C67B960CFBFB641A7B52 Size:1731
and more....
%PROGRAMFILES%\PaqTool\amac\unins000.exe
MD5: C67114B6BED0149290ACA5DDCE032EBE Size:82253
MD5: 47BC7A7B7AA8DB094DA94A04F35817A6 Size:678682
MD5: BF15CE70E055955FAFD81A18EC1C0771 Size:77257
MD5: EAA5797F1AA563DBDE384F776D2A26B9 Size:856538
%PROGRAMFILES%\PaqTool\amac\amac.exe
MD5: B42852E87A177A18E6A3686996F4DF09 Size:49152
MD5: 0D461C6341CE9B3EEB2A695A99EABC3E Size:299008
MD5: DE607AA5054911072390E87986465F7E Size:286720
MD5: DA623B10BAC37B315CEEB443C703F300 Size:299008
MD5: B34A9DC7B430DD5C0194106002A7E97A Size:476638
MD5: B198AA52E08D8C26560FF42E02409B48 Size:290816
MD5: 6B0B2F3D953DA59A241D09C46ECF4F5D Size:299008
MD5: 6F2C125E75AD21F0B49944B3C8A7A8DF Size:278528
MD5: 312738123A9EC418BD0C2FFC2F581D31 Size:286720
MD5: D90E34CD692D8CE3C64CA1E3D3ACD039 Size:290816
MD5: 5F900CDDCE90995A244F92490229AAA5 Size:299008
MD5: 1A63321D65B22B62BAF11224837BCAAE Size:286720
and more....
%PROGRAMFILES%\PaqTool\amac\wakeup.exe
MD5: 19D88FD8EFD17C76AACF27AE9C8D5264 Size:16384
MD5: 32A0A6931FB47CE43360F5F5B577F96C Size:28672
%PROGRAMFILES%\PaqTool\amac\pamq.dll
MD5: 8FBCEA3E41EB9D900E1CE4B00C741A53 Size:98304
MD5: 9E77FB90B82CB58CC86BC14BDB421E32 Size:20480
%PROGRAMFILES%\PaqTool\amac\MfcAxCtl.ocx
MD5: E7530D64A479E58EE0A20E6B00438393 Size:311296
MD5: A40F6DF4337AB80779BAEBFCE42E30FD Size:311296
MD5: 07811A0A4E5055D57B2A9D475925E617 Size:311296
%PROGRAMFILES%\PaqTool\amac\MACAddressChanger.exe
MD5: 5CFFA193754FB14B180F78D7E0B7EE02 Size:323584
MD5: 3A1FD1EA1BE1F1AD2FE461FD4DB0FE65 Size:501210
MD5: AE4589694622113D4E7253A86952BF75 Size:323584
%PROGRAMFILES%\PaqTool\amac\winping.exe
MD5: 7B3A8B1C3A1E12E83462C7A67A7A7FCD Size:237568
MD5: CF75CA74AFE23AA82D5E73DB6D00AD1C Size:282624
%PROGRAMFILES%\PaqTool\amac\PaqBonus.exe
MD5: 5C3E10DE293107728878E3AC500F70DF Size:397379
MD5: 4D91F3E2A2403433962A6FFDB930F4ED Size:442435
MD5: 8EF2ED7A8CFDA8557FA566BE6C16084D Size:397379
%PROGRAMFILES%\PaqTool\amac\digerati.dll
MD5: 1AFF244CA134956C54474F4E2433E4CE Size:616960
%PROGRAMFILES%\PaqTool\amac\(dods )Patch a-Mac Address Change.EXE
MD5: B7F2692B6DCE95D6B3103452DCECE07B Size:61959
%PROGRAMFILES%\PaqTool\amac\amac.exe
MD5: 8AD2EE55BC0D1C94D64EFC4EFC9FEC3E Size:49152
MD5: BFEA4DE403F8E074A75136C679E4714B Size:299008
%PROGRAMFILES%\PaqTool\Ecare\Mousehook.dll
MD5: 250DF8B54E397A84568AC6102341693D Size:28672
%PROGRAMFILES%\PaqTool\Ecare\LaunchDLL.dll
MD5: 08B8FBB5444D1A83203BFAFD76540D01 Size:102400
%PROGRAMFILES%\PaqTool\Ecare\eyescare.exe
MD5: AEAAC2385F8D85F614214854F8135715 Size:131072
%SYSDIR%\golyy5dd1.dll
MD5: 1E57281D47D26CE7EDC1AD4AF01B7E03 Size:1731
MD5: 718448CDCF2D04CA675BA8D79DB08E35 Size:1731
MD5: BB9801FCB7EFB7C658898BBCD417813C Size:1731
MD5: BE4BCDF9A30EBEE11FCD752A522985E3 Size:1731
%PROGRAMFILES%\PaqTool\Hokel\uninstall.exe
MD5: 5207896DDFD29A5C212518603D682A88 Size:33728
%PROGRAMFILES%\PaqTool\deskdetect\spyclient\DDConfig.sys
MD5: ADFE26184AD45FC5AF1BEF30915A5F6F Size:2787
%PROGRAMFILES%\PaqTool\deskdetect\spyclient\DDClient.exe
MD5: CF32A41D5E547EA46394752936A1FB2F Size:496128
%PROGRAMFILES%\PaqTool\deskdetect\spyclient\DDClient.dll
MD5: 9F2FFF1CC189581AAAD6781F285027FA Size:18432
%PROGRAMFILES%\PaqTool\deskdetect\DDController.exe
MD5: B425499F9AA41EE10588FDCB9322E556 Size:1065472
%PROGRAMFILES%\PaqTool\dd2000pe.exe
MD5: 5E23D5843E35FB2464DBB7A0773166BD Size:1349111
%PROGRAMFILES%\PaqTool\Hokel\KeyLogger.dll
MD5: 27836052B370297EC4397E91061DA949 Size:5632
- Detected Files with variable Filenames:
MD5: BF15CE70E055955FAFD81A18EC1C0771 Size: 77257
%PROGRAMFILES%\PaqTool\amac\unins000.exe
%PROGRAMFILES%\PaqTool\amac\is-8IRD1.tmp
Detecting items list:
- Files by Name
%START_PROGRAMS%\PaqTool\Paq Keylog.lnk
%START_PROGRAMS%\PaqTool\Uninstall Paq keylog.lnk
%DESKTOP%\Paq Keylog.lnk
%ProgramFiles%\PaqTool\keylog\KeyLog.exe
%ProgramFiles%\PaqTool\keylog\launchDll.dll
%ProgramFiles%\PaqTool\keylog\logo.avi
%ProgramFiles%\PaqTool\keylog\paqlog.cfg
%ProgramFiles%\PaqTool\keylog\unins000.dat
%ProgramFiles%\PaqTool\keylog\unins000.exe
%sysdir%\golyy5dd1.dll
- Files by Directories
%START_PROGRAMS%\PaqTool
%ProgramFiles%\PaqTool
- Registry Keys
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Paq KeyLog_is1
HKLM\SOFTWARE\golbup
- Registry Values
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ValueName=VC_Log Value=%ProgramFiles%\PaqTool\keylog\KeyLog.exe
«
Go to Software Database