XPCSpy Pro 3.0
|
Description:
|
Keylogger
|
|
Risk Level:
|
Low
|
|
Date of First Occurence:
|
Thursday, April 17, 2008
|
|
Software Developer:
|
(unknown)
|
|
Brief Info:
|
Keyloggers invisibly monitor and record all of your computer activity. This information is then automatically emailed to an anonymous user.
|
|
Removal:
|
This threat can be removed using "Spyware
Terminator"
|
SCAN & REMOVE NOW »
Geographical Distribution of Threat "XPCSpy Pro 3.0"
Threat Info
View All
Detected Items
- Detected Files:
%PROGRAMFILES%\XSoft\AXCAD\zlib1.dll
MD5: 87EDDCEB9D22C129E386E652C5CDA521 Size:53760
%PROGRAMFILES%\XSoft\AXCAD\zlib.dll
MD5: 4603063FC3B74650A5783F03D8E42A49 Size:65536
%PROGRAMFILES%\XSoft\AXCAD\XRMRes.dll
MD5: F6A6BC75678A77ED9545A8437AB1D3C4 Size:69632
%PROGRAMFILES%\XSoft\AXCAD\XRM.dll
MD5: F64D066FF6D88649C3E9D7A19A170E47 Size:57414
%PROGRAMFILES%\XSoft\AXCAD\whiptk.dll
MD5: 2B07EB14BD0F437141F6E7834D3A5BE0 Size:749568
%PROGRAMFILES%\XSoft\AXCAD\W3dTk.dll
MD5: 197D35F9550893D251764FE677B75ED7 Size:544768
%PROGRAMFILES%\XSoft\AXCAD\SpaBasen.dll
MD5: 21C261DA385EF8CB4ABEDD4F2C1C9113 Size:2240512
%PROGRAMFILES%\XSoft\AXCAD\SpaBase.dll
MD5: A819125A090C2E755F90216A1ACBB17A Size:2306114
%PROGRAMFILES%\XSoft\AXCAD\SpaAVisn.dll
MD5: 08CE8D508BF01E2F273469CDFEA254B0 Size:880640
%PROGRAMFILES%\XSoft\AXCAD\SpaAVis.dll
MD5: 2A96646D90D3D6CA3D8AED311C96A395 Size:864322
%PROGRAMFILES%\XSoft\AXCAD\SpaACISn.dll
MD5: 867CF9218F89D94D5383A9A625964813 Size:20234240
%PROGRAMFILES%\XSoft\AXCAD\SpaACIS.dll
MD5: FCA098D8F86BD9984B98FC1509D6751D Size:19988546
%PROGRAMFILES%\XSoft\AXCAD\render.dll
MD5: 72A053A7F3C817591DF12600CAC62318 Size:49152
%PROGRAMFILES%\XSoft\AXCAD\PStyleEdRes.dll
MD5: 27163C8B9E1EEE1ACCB0E39800B53423 Size:77824
%PROGRAMFILES%\XSoft\AXCAD\PStyleEd.dll
MD5: 1F039D6C9DDE44D6405AD33D490EE1E8 Size:118859
%PROGRAMFILES%\XSoft\AXCAD\ProfilesEditorRes.dll
MD5: B4CDF5CE87627FAD405148A0FCF1F1CF Size:86016
%PROGRAMFILES%\XSoft\AXCAD\PDFToolkit_2.03ITC_6.dll
MD5: D27CE1C3B9D5C68C78A3DE3E636604B8 Size:421888
%PROGRAMFILES%\XSoft\AXCAD\OdaDlgExt_2.03ITC_6.dll
MD5: D91F6FB8D89BEA2AC9C5C185CE733AA1 Size:28672
%PROGRAMFILES%\XSoft\AXCAD\msvcp60.dll
MD5: 1F57EB5B92B2AC7F9D71A77D184D8C13 Size:413696
%PROGRAMFILES%\XSoft\AXCAD\mfc42u.dll
MD5: 67D964F84D63B7ADB6E8F881645729C5 Size:1163776
%PROGRAMFILES%\XSoft\AXCAD\mfc42.dll
MD5: 4602907535FD682195DFFF9117365826 Size:1028096
%PROGRAMFILES%\XSoft\AXCAD\IcadUtils.dll
MD5: 9B4CCA677F1663D8021C36371BA481ED Size:176202
%PROGRAMFILES%\XSoft\AXCAD\IcadRes.dll
MD5: F1D449018C0822580B3E0C4E98F7E27A Size:2142208
%PROGRAMFILES%\XSoft\AXCAD\IcadCommon.dll
MD5: E1FB0A7D0F69D6CF6F1BBADB3A517CFA Size:192589
%PROGRAMFILES%\XSoft\AXCAD\IcadAuto.dll
MD5: 032E188EA914727ECD532199538AFE07 Size:1204297
%PROGRAMFILES%\XSoft\AXCAD\IcadAuth.dll
MD5: 9F93043B947A1DF385348F57045AA207 Size:720969
%PROGRAMFILES%\XSoft\AXCAD\gr.dll
MD5: 83C1BBCD38F334E5736E739CB0A2EF94 Size:626757
%PROGRAMFILES%\XSoft\AXCAD\geo.dll
MD5: 0CF1DB8EADBBBB1F50E11093E40B1C4A Size:458822
%PROGRAMFILES%\XSoft\AXCAD\gdiplus.dll
MD5: 3317698F2090DD811F0AA93190E13C82 Size:1706800
%PROGRAMFILES%\XSoft\AXCAD\emf2xmlDemo.exe
MD5: 1885FD7620382DFD3814C289E9B8C669 Size:36864
%PROGRAMFILES%\XSoft\AXCAD\emf2xml.dll
MD5: 3E404506F660DCFD80448F814DA0287C Size:163840
%PROGRAMFILES%\XSoft\AXCAD\DWGPreview.dll
MD5: 6B0CB56EBE56C149C073ECD1AA46DA28 Size:77824
%PROGRAMFILES%\XSoft\AXCAD\DwfToolkit.dll
MD5: F0926C2EB012CF9BF33E1AA862A2D2B9 Size:1622016
%PROGRAMFILES%\XSoft\AXCAD\DwfCore.dll
MD5: 42A40A24FC477EF4053A9EB8DCF2BD79 Size:286720
%PROGRAMFILES%\XSoft\AXCAD\DD_SpatialIndex_2.03ITC_6.dll
MD5: DA03BDFF04C36A634F1D5C7025102BEA Size:40960
%PROGRAMFILES%\XSoft\AXCAD\DD_Root_2.03ITC_6.dll
MD5: CEFBDF1C32FABF9BB3426CC80B711B46 Size:471040
%PROGRAMFILES%\XSoft\AXCAD\DD_PdfExport_2.03ITC_6.dll
MD5: 676A4011C2A4A4811187D0A669E3618A Size:253952
%PROGRAMFILES%\XSoft\AXCAD\DD_Gs_2.03ITC_6.dll
MD5: B8EB8FF898441AFD21415243418728A8 Size:229376
%PROGRAMFILES%\XSoft\AXCAD\DD_Gi_2.03ITC_6.dll
MD5: 074C71F5D74A86EF213534528F01462F Size:528384
%PROGRAMFILES%\XSoft\AXCAD\DD_Ge_2.03ITC_6.dll
MD5: 81B47513BF2494A91AEA438B7B13832D Size:643072
%PROGRAMFILES%\XSoft\AXCAD\DD_Dwf7Export_2.03ITC_6.dll
MD5: 64D96AAFCF6232640982F25AC0F38CFD Size:311296
%PROGRAMFILES%\XSoft\AXCAD\DD_Db_2.03ITC_6.dll
MD5: E2FB3412BFAC5E799D184B780FD096B3 Size:6348800
%PROGRAMFILES%\XSoft\AXCAD\DD_Br_2.03ITC_6.dll
MD5: 25E33CFCDE8DEFF02D3764A55C888934 Size:114688
%PROGRAMFILES%\XSoft\AXCAD\DD_BmpExport_2.03ITC_6.dll
MD5: 5786EA12C2BB33CB6473E98E561E7EB8 Size:24576
%PROGRAMFILES%\XSoft\AXCAD\DD_Alloc_2.03ITC_6.dll
MD5: 570B84489E99A305D888C3F7F8E12346 Size:24576
%PROGRAMFILES%\XSoft\AXCAD\DD_AcisRenderer_2.03ITC_6.dll
MD5: 0E3A81E3EFA54DFF3EF70A38C55DD70F Size:368640
%PROGRAMFILES%\XSoft\AXCAD\DD_AcisBuilder_2.03ITC_6.dll
MD5: E7C49164145358F63D72231CB699EAA1 Size:606208
%PROGRAMFILES%\XSoft\AXCAD\DCLRes.dll
MD5: 37C9786C1FDCC2792B12EE9658A8C7F7 Size:32768
%PROGRAMFILES%\XSoft\AXCAD\DCL.dll
MD5: F2ABA6EC6D211186F9B73FF0F57363C1 Size:581702
%PROGRAMFILES%\XSoft\AXCAD\dbghelp.dll
MD5: 28D3E1F32742CA36974120B49E2B9DC2 Size:640000
%PROGRAMFILES%\XSoft\AXCAD\db.dll
MD5: A5865F3C41AE72FBDA5D257A98B02A85 Size:2052165
%PROGRAMFILES%\XSoft\AXCAD\CrashRpt.dll
MD5: 8E1EC02C2E8BA9074B5C22BBCA242B2D Size:88635
%PROGRAMFILES%\XSoft\AXCAD\BlockManager.dll
MD5: 20E153CB5BA6E472B81D3D9CEA0816B9 Size:90112
%PROGRAMFILES%\XSoft\AXCAD\AXGUIEN.dll
MD5: 61667C318A5CF54142310C1828A4E1D1 Size:57344
%PROGRAMFILES%\XSoft\AXCAD\AXGUI.dll
MD5: 37F6B5A27AAE00F8832E3540432C5F2C Size:57344
%PROGRAMFILES%\XSoft\AXCAD\AdekoRaster.dll
MD5: 26472DAE9A0890B309A0D18BE30ABCFD Size:110592
%PROGRAMFILES%\XSoft\AXCAD\ACIS.dll
MD5: 6107B896C64704ABB88713B04FA8C8A4 Size:90112
%PROGRAMFILES%\xsoft\AXCAD\UserProfileManager.exe
MD5: E22CE9F8EB5E61EC62FF45F9314039A2 Size:98304
%PROGRAMFILES%\xsoft\AXCAD\PStyleApp.exe
MD5: 661BC5CE62F9EB1C4C50B350CFB5CF9D Size:57420
%PROGRAMFILES%\XSoft\xworking\sysrts.exe
MD5: DE022FCD7A7846AEA67EB93C83F7E433 Size:456192
MD5: 99B67CFCF687896BCE2CA28A1EE6FA3D Size:456192
%PROGRAMFILES%\XSoft\xworking\SMSS.exe
MD5: 21DFCB0502C68DBEBF8BA88B42DDF6C7 Size:3428352
MD5: 30556F56808D866D8C0D084959B9D046 Size:3428352
MD5: 4237473EC82D9D967B8AF63C5697EE6B Size:754688
%PROGRAMFILES%\XSoft\xworking\KeyMon.dll
MD5: 39FC2CF64A76EA37B698D79F956ABED2 Size:1250627
%PROGRAMFILES%\XSoft\xworking\IMon.dll
MD5: 3BA2CBDDCD4A0C2A41914591744002CE Size:444416
%PROGRAMFILES%\XSoft\xworking\AMon.dll
MD5: 45B2B1499F6FD92A21F592256B3D78EE Size:169984
%PROGRAMFILES%\XSoft\unins000.exe
MD5: 0A8AF06CF49DF26ECF616F999E3B27BB Size:685849
%SYSDIR%\winxtm.dll
MD5: A6800AC1CD478FF991759F8188AA17C9 Size:3400
MD5: 837AC8A0DD4B728CB3CF87AE57DAE3BD Size:3400
MD5: 848E3743D2335AB16C61325814C96B32 Size:3400
MD5: BA4B04568D5C5809DDCBF42FE5A4C6A3 Size:3400
%PROGRAMFILES%\XSoft\xworking\rsrsys.sys
MD5: 50E307CFF75DF220666DD2F369F11062 Size:6754
%PROGRAMFILES%\XSoft\FINAL FANTASY VIII\Chocobo.exe
MD5: 607667AB8C62788E387E198146013CA9 Size:1171456
%PROGRAMFILES%\XSoft\FINAL FANTASY VIII\binkw32.dll
MD5: BA94F448509D370845D621131D29D310 Size:180224
%PROGRAMFILES%\XSoft\FINAL FANTASY VIII\FF8Config.exe
MD5: C138E86A369EA90DC540A8EB581618FA Size:183296
%PROGRAMFILES%\XSoft\FINAL FANTASY VIII\FF8.exe
MD5: F805B4241801A4C4181642C887B2343F Size:21540864
- Detected Files with variable Filenames:
MD5: 6FD9660484EF4FC63EC16736C181213B Size: 6643781
%PROGRAMFILES%\XSoft\AXCAD\icad.exe
%PROGRAMFILES%\xsoft\AXCAD\axcad.exe
MD5: 1E2E2857F995867C321EB82330A4E7B4 Size: 40448
%PROGRAMFILES%\XSoft\xworking\xld.exe
%PROGRAMFILES%\XSoft\rx.exe
Detecting items list:
- Files by Name
%PROGRAMFILES%\XSoft\unins000.exe
%PROGRAMFILES%\XSoft\rx.exe
%PROGRAMFILES%\XSoft\xworking\AMon.dll
%PROGRAMFILES%\XSoft\xworking\IMon.dll
%PROGRAMFILES%\XSoft\xworking\KeyMon.dll
%PROGRAMFILES%\XSoft\xworking\RSR.exe
%PROGRAMFILES%\XSoft\xworking\rsrsys.sys
%PROGRAMFILES%\XSoft\xworking\sysrts.exe
%PROGRAMFILES%\XSoft\xworking\xld.exe
%SYSDIR%\winxtm.dll
- Files by Directories
%PROGRAMFILES%\XSoft
- Files by CLSID or Name
CLSID=3A9DB4A6-E29C-4AE8-9C44-B058941EB5D0
CLSID=67C4682D-5AED-48DB-83CB-2B53270E9BCB
CLSID=DC89FE62-D39E-4388-650D-2321078DF6F6
- Registry Keys
HKCR\AMon.TShellExecuteHook
HKCR\IMon.IESpy
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3A9DB4A6-E29C-4AE8-9C44-B058941EB5D0}
- Registry Values
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ValueName=winxld
«
Go to Software Database