PaqKeylog

Description: Spyware
Risk Level: None
Date of First Occurence: Wednesday, April 23, 2008
Software Developer: (unknown)
Brief Info: Keyloggers invisibly monitor and record all of your computer activity. This information is then automatically emailed to an anonymous user.
Removal: This threat can be removed using "Spyware Terminator"

ENTFERNEN SPYWARE »

Geographical Distribution of Threat "PaqKeylog"

Threat Info

View All

Detected Items

  1. Detected Files: %SYSDIR%\golyy5dd1.dll MD5: 799084428E7CAEDBB6561F9F52526F6E Size:1731 MD5: 4F9E7A1648D2F5952E43C0DF0EB1CE37 Size:1731 MD5: 9CCA0F3C5320B16300695749154F3DB8 Size:1731 MD5: A8194F7E1FA6077EA6F282D5D90828DA Size:1731 MD5: 12AB55F22944C84DB4BAB1B9C473A3A3 Size:1731 MD5: E2A6F8AA98CA2213693730A77F487C08 Size:1731 MD5: 8766A27860AAB787C31BA40167633965 Size:1731 MD5: EC8F4BFBA7717901D54B3C9F4D76657F Size:1731 MD5: 62802AD7CFA47F47C8CA8D57FA49B2DF Size:1731 MD5: 55F85F0CF834EDA46A9B11F1D2FE00C9 Size:1731 MD5: 734A4223D9F2E905B9ACC26749290267 Size:1731 MD5: A2752C0A9028C67B960CFBFB641A7B52 Size:1731 and more.... %PROGRAMFILES%\PaqTool\amac\unins000.exe MD5: C67114B6BED0149290ACA5DDCE032EBE Size:82253 MD5: 47BC7A7B7AA8DB094DA94A04F35817A6 Size:678682 MD5: BF15CE70E055955FAFD81A18EC1C0771 Size:77257 MD5: EAA5797F1AA563DBDE384F776D2A26B9 Size:856538 %PROGRAMFILES%\PaqTool\amac\amac.exe MD5: B42852E87A177A18E6A3686996F4DF09 Size:49152 MD5: 0D461C6341CE9B3EEB2A695A99EABC3E Size:299008 MD5: DE607AA5054911072390E87986465F7E Size:286720 MD5: DA623B10BAC37B315CEEB443C703F300 Size:299008 MD5: B34A9DC7B430DD5C0194106002A7E97A Size:476638 MD5: B198AA52E08D8C26560FF42E02409B48 Size:290816 MD5: 6B0B2F3D953DA59A241D09C46ECF4F5D Size:299008 MD5: 6F2C125E75AD21F0B49944B3C8A7A8DF Size:278528 MD5: 312738123A9EC418BD0C2FFC2F581D31 Size:286720 MD5: D90E34CD692D8CE3C64CA1E3D3ACD039 Size:290816 MD5: 5F900CDDCE90995A244F92490229AAA5 Size:299008 MD5: 1A63321D65B22B62BAF11224837BCAAE Size:286720 and more.... %PROGRAMFILES%\PaqTool\amac\wakeup.exe MD5: 19D88FD8EFD17C76AACF27AE9C8D5264 Size:16384 MD5: 32A0A6931FB47CE43360F5F5B577F96C Size:28672 %PROGRAMFILES%\PaqTool\amac\pamq.dll MD5: 8FBCEA3E41EB9D900E1CE4B00C741A53 Size:98304 MD5: 9E77FB90B82CB58CC86BC14BDB421E32 Size:20480 %PROGRAMFILES%\PaqTool\amac\MfcAxCtl.ocx MD5: E7530D64A479E58EE0A20E6B00438393 Size:311296 MD5: A40F6DF4337AB80779BAEBFCE42E30FD Size:311296 MD5: 07811A0A4E5055D57B2A9D475925E617 Size:311296 %PROGRAMFILES%\PaqTool\amac\MACAddressChanger.exe MD5: 5CFFA193754FB14B180F78D7E0B7EE02 Size:323584 MD5: 3A1FD1EA1BE1F1AD2FE461FD4DB0FE65 Size:501210 MD5: AE4589694622113D4E7253A86952BF75 Size:323584 %PROGRAMFILES%\PaqTool\amac\winping.exe MD5: 7B3A8B1C3A1E12E83462C7A67A7A7FCD Size:237568 MD5: CF75CA74AFE23AA82D5E73DB6D00AD1C Size:282624 %PROGRAMFILES%\PaqTool\amac\PaqBonus.exe MD5: 5C3E10DE293107728878E3AC500F70DF Size:397379 MD5: 4D91F3E2A2403433962A6FFDB930F4ED Size:442435 MD5: 8EF2ED7A8CFDA8557FA566BE6C16084D Size:397379 %PROGRAMFILES%\PaqTool\amac\digerati.dll MD5: 1AFF244CA134956C54474F4E2433E4CE Size:616960 %PROGRAMFILES%\PaqTool\amac\(dods )Patch a-Mac Address Change.EXE MD5: B7F2692B6DCE95D6B3103452DCECE07B Size:61959 %PROGRAMFILES%\PaqTool\amac\amac.exe MD5: 8AD2EE55BC0D1C94D64EFC4EFC9FEC3E Size:49152 MD5: BFEA4DE403F8E074A75136C679E4714B Size:299008 %PROGRAMFILES%\PaqTool\Ecare\Mousehook.dll MD5: 250DF8B54E397A84568AC6102341693D Size:28672 %PROGRAMFILES%\PaqTool\Ecare\LaunchDLL.dll MD5: 08B8FBB5444D1A83203BFAFD76540D01 Size:102400 %PROGRAMFILES%\PaqTool\Ecare\eyescare.exe MD5: AEAAC2385F8D85F614214854F8135715 Size:131072 %SYSDIR%\golyy5dd1.dll MD5: 1E57281D47D26CE7EDC1AD4AF01B7E03 Size:1731 MD5: 718448CDCF2D04CA675BA8D79DB08E35 Size:1731 MD5: BB9801FCB7EFB7C658898BBCD417813C Size:1731 MD5: BE4BCDF9A30EBEE11FCD752A522985E3 Size:1731 %PROGRAMFILES%\PaqTool\Hokel\uninstall.exe MD5: 5207896DDFD29A5C212518603D682A88 Size:33728 %PROGRAMFILES%\PaqTool\deskdetect\spyclient\DDConfig.sys MD5: ADFE26184AD45FC5AF1BEF30915A5F6F Size:2787 %PROGRAMFILES%\PaqTool\deskdetect\spyclient\DDClient.exe MD5: CF32A41D5E547EA46394752936A1FB2F Size:496128 %PROGRAMFILES%\PaqTool\deskdetect\spyclient\DDClient.dll MD5: 9F2FFF1CC189581AAAD6781F285027FA Size:18432 %PROGRAMFILES%\PaqTool\deskdetect\DDController.exe MD5: B425499F9AA41EE10588FDCB9322E556 Size:1065472 %PROGRAMFILES%\PaqTool\dd2000pe.exe MD5: 5E23D5843E35FB2464DBB7A0773166BD Size:1349111 %PROGRAMFILES%\PaqTool\Hokel\KeyLogger.dll MD5: 27836052B370297EC4397E91061DA949 Size:5632
  2. Detected Files with variable Filenames: MD5: BF15CE70E055955FAFD81A18EC1C0771 Size: 77257 %PROGRAMFILES%\PaqTool\amac\unins000.exe %PROGRAMFILES%\PaqTool\amac\is-8IRD1.tmp

Detecting items list:

  1. Files by Name %START_PROGRAMS%\PaqTool\Paq Keylog.lnk %START_PROGRAMS%\PaqTool\Uninstall Paq keylog.lnk %DESKTOP%\Paq Keylog.lnk %ProgramFiles%\PaqTool\keylog\KeyLog.exe %ProgramFiles%\PaqTool\keylog\launchDll.dll %ProgramFiles%\PaqTool\keylog\logo.avi %ProgramFiles%\PaqTool\keylog\paqlog.cfg %ProgramFiles%\PaqTool\keylog\unins000.dat %ProgramFiles%\PaqTool\keylog\unins000.exe %sysdir%\golyy5dd1.dll
  2. Files by Directories %START_PROGRAMS%\PaqTool %ProgramFiles%\PaqTool
  3. Registry Keys HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Paq KeyLog_is1 HKLM\SOFTWARE\golbup
  4. Registry Values HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ValueName=VC_Log Value=%ProgramFiles%\PaqTool\keylog\KeyLog.exe

« Go to Software Database