SpyLanternKeylogger

Description: Spyware
Risk Level: High
Date of First Occurence: Tuesday, June 10, 2008
Software Developer: (unknown)
Brief Info: Spy Lantern Keylogger invisibly monitors and records all of your computer activity. This information is then automatically emailed to an anonymous user.
Removal: This threat can be removed using "Spyware Terminator"

SCAN & REMOVE NOW »

Geographical Distribution of Threat "SpyLanternKeylogger"

Threat Info

View All

Detected Items

  1. Detected Files: %SYSDIR%\hisykyl.exe MD5: 870BFEE37647B450C3A7F9A05C367F21 Size:139264 %PROGRAMFILES%\eChanblard\Incoming\spy-lantern-keylogger-pro\setup.exe MD5: 7BCCA3A60D4C06BBCD4DDBB695594DB5 Size:1770580 %SYSDIR%\fihylipcc.exe MD5: 822A37E78B8793BE4B59C821E5F19215 Size:331776
  2. Detected Files with variable Filenames: MD5: 6CF1B391B3FE1220A2BA18CD85125B38 Size: 102400 %SYSDIR%\vyvuhh.dll %SYSDIR%\fuqegoh.dll %SYSDIR%\fihyliph.dll %SYSDIR%\bujadh.dll MD5: 89674F36DF7EBBDB9AF33BF9445C486A Size: 163840 %SYSDIR%\vyvuha.dll %SYSDIR%\hisykya.dll %SYSDIR%\fuqegoa.dll %SYSDIR%\fihylipa.dll %SYSDIR%\bujada.dll MD5: 27B57398705432D0471F1B2191144377 Size: 491025 %SYSDIR%\fihylipv.exe %SYSDIR%\bujadv.exe

Detecting items list:

  1. Files by Name %sysdir%\dysilez.exe %sysdir%\dysileza.dll %sysdir%\dysilezcc.exe %sysdir%\dysilezh.dll %sysdir%\dysilezl.exe %sysdir%\dysilezv.exe %sysdir%\dysilez.cfg %sysdir%\dysilez.chm %sysdir%\dysilez.sys %sysdir%\zowox.exe %sysdir%\zowox.chm %sysdir%\zowoxl.exe %sysdir%\zowox.cfg %sysdir%\zowox.sys %sysdir%\zowoxa.dll
  2. Files by MD5 MD5: 7BCCA3A60D4C06BBCD4DDBB695594DB5 Size: 1770580 MD5: DEF0BFE16A03DAEB6F11FA3229465DE4 Size: 348160 MD5: 89674F36DF7EBBDB9AF33BF9445C486A Size: 163840 MD5: 822A37E78B8793BE4B59C821E5F19215 Size: 331776 MD5: 6CF1B391B3FE1220A2BA18CD85125B38 Size: 102400
  3. Files by Directories %START_PROGRAMSALL%\Spy Lantern Keylogger %windir%\zowox
  4. Registry Keys HKLM\software\Microsoft\Windows\CurrentVersion\Uninstall\Spy Lantern Keylogger HKLM\SYSTEM\CurrentControlSet\Services\DysilezDriver HKLM\SYSTEM\CurrentControlSet\Services\DysilezSrv

« Go to Software Database