Second Sight Keylogger
|
Description:
|
Keylogger
|
|
Risk Level:
|
Low
|
|
Date of First Occurence:
|
Monday, April 21, 2008
|
|
Software Developer:
|
(unknown)
|
|
Brief Info:
|
Keyloggers invisibly monitor and record all of your computer activity. This information is then automatically emailed to an anonymous user.
|
|
Removal:
|
This threat can be removed using "Spyware
Terminator"
|
ELIMINAR SPYWARE »
Geographical Distribution of Threat "Second Sight Keylogger"
Threat Info
View All
Detected Items
- Detected Files:
%SYSDIR%\ptrue2.DLL
MD5: 179A9180E4516A845F7C8192B4E2356F Size:81920
MD5: CD9555E9D345A4A3195D1C4349719DA4 Size:73728
%SYSDIR%\ptrue.dll
MD5: 4A27A933C0DD1DCF03CA5CBB1B676D4C Size:204800
%SYSDIR%\KTKbdHk3.DLL
MD5: 8A669CB39A92ECB43D733E3022F4FF4E Size:12800
MD5: 28BFE18E402AA448D78497E23725F441 Size:19456
- Detected Files with variable Filenames:
Detecting items list:
- Files by Name
%SYSDIR%\KTKbdHk3.DLL
%SYSDIR%\mmemdrv.exe
%SYSDIR%\ptrue.dll
%SYSDIR%\ptrue2.DLL
%SYSDIR%\complus32\DGuard2.ocx
%SYSDIR%\complus32\iQCustomButton.ocx
%SYSDIR%\complus32\KBDMONITOR.OCX
%SYSDIR%\complus32\Psrl32.ocx
%SYSDIR%\complus32\smtp.ocx
%SYSDIR%\complus32\Trlpro.ocx
%SYSDIR%\complus32\vsflex7l.ocx
%SYSDIR%\complus32\XceedZip.dll
%SYSDIR%\complus32\XIMGEDIT30.OCX
%SYSDIR%\complus32\xpcheck.ocx
%systemdiskroot%\System VolumeID\RP15\LibCache\MsiInterface.exe
%systemdiskroot%\System VolumeID\RP15\LibCache\msunin.exe
%systemdiskroot%\System VolumeID\RP15\LibCache\scvhost.exe
%systemdiskroot%\System VolumeID\RP15\LibCache\svcView.exe
%systemdiskroot%\System VolumeID\RP46\APIgdi32.dll
%systemdiskroot%\System VolumeID\RP46\bnr16.dll
%systemdiskroot%\System VolumeID\RP46\bnr32.dll
%systemdiskroot%\System VolumeID\RP46\sysadmin1.dll
%systemdiskroot%\System VolumeID\RP46\sysadmin2.dll
%systemdiskroot%\System VolumeID\RP46\sysadmin3.dll
%systemdiskroot%\System VolumeID\RP46\sysnav04.dll
%systemdiskroot%\System VolumeID\RP46\sysnav3a.dll
%systemdiskroot%\System VolumeID\RP46\sysnav3b.dll
%systemdiskroot%\System VolumeID\RP46\wcp32.dll
- Registry Values
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Runf ValueName=mmemdrv
«
Go to Software Database