SpySoft.PowerSpy

Description: Spyware
Risk Level: High
Date of First Occurence: Friday, May 09, 2008
Software Developer: (unknown)
Brief Info: Power Spy invisibly monitors and records all of your computer activity. This information is then automatically emailed to an anonymous user.
Removal: This threat can be removed using "Spyware Terminator"

ELIMINAR SPYWARE »

Geographical Distribution of Threat "SpySoft.PowerSpy"

Threat Info

View All

Detected Items

  1. Detected Files: %PROGRAMFILES%\PSCS\data\symserv.exe MD5: 4755B64E85D72C6F3077433096F4040A Size:49152 MD5: 307BDABD4D316921C156A2AE7B5274FE Size:102912 %PROGRAMFILES%\PSCS\data\navaqsvc.exe MD5: D651EB7C9F533C585CE128914D3394A9 Size:131072 %SYSDIR%\bdmreg.exe MD5: AA323A29207FAB4F4564A6E84F7F896D Size:24576 MD5: A0DF191F279AA3370C488AFAEE75D296 Size:24576 MD5: C65FD2AF43DFD1DA3C6941A4422FAFD7 Size:24576 MD5: DB67BE6FB4C8DB668DAC0516E4C62FE5 Size:544768 MD5: CA6A97983ACC98FA615D1F5791380921 Size:24576 MD5: 17BDFB3F924140537C3CCF6CC79C2880 Size:24576 MD5: F4421EA6D01B6531FEC331E185EBC1B4 Size:24576 MD5: 4AC68A86A39CBC130B98328895F2DFC2 Size:24576 MD5: 97B4975066650B232052E98FF63BC4A5 Size:24576 MD5: F108754A1DE8145BFC4D6EA99C37A6F7 Size:24576 MD5: D4D91B30D069D1747513515512C681A0 Size:24576 MD5: 085F15CFE469297377684A0AD3641B34 Size:24576 and more.... g:\!Admin\SYSTEM\SPY-CRACK-HACK\Activity Monitoring\Power Spy\Power Spy 2007 6.5.4.exe MD5: 98B59053AB96AFE88E4D48423EED2248 Size:4670389 %PROGRAMFILES%\PSCS\pssrv.exe MD5: 28F48C9645EBCFECBD9D56802AC69B30 Size:302592 %PROGRAMFILES%\PSCS\data\eventwin.exe MD5: CAB528925CCD995C07DBDA9794079857 Size:647168 MD5: 4473A6DCFB87DED5897B41B1BC9521EE Size:131072 %SYSDIR%\bdmreg.exe MD5: 76F79B110BB3D05099EB4D9C69DB780B Size:24576
  2. Detected Files with variable Filenames:

Detecting items list:

  1. Files by Name %programfiles%\PSCS\pssrv.exe %sysdir%\bdmreg.exe
  2. Files by MD5 MD5: 98B59053AB96AFE88E4D48423EED2248 Size: 4670389 MD5: AB14D13F613C14F2216843625D021D5F Size: 933888
  3. Files by Directories %programfiles%\PSCS
  4. Registry Values HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ValueName=bdmreg Value=%sysdir%\bdmreg.exe

« Go to Software Database