ISpy

Description: Keylogger
Risk Level: High
Date of First Occurence: Tuesday, April 15, 2008
Software Developer: (unknown)
Brief Info: Keyloggers invisibly monitor and record all of your computer activity. This information is then automatically emailed to an anonymous user.
Removal: This threat can be removed using "Spyware Terminator"

SCAN & REMOVE NOW »

Geographical Distribution of Threat "ISpy"

Threat Info

View All

Detected Items

  1. Detected Files: %PROGRAMFILES%\Helper\findsiteonline.dll MD5: 36C81DFA646364217FCF1530E9529513 Size:15872 %PROGRAMFILES%\Helper\prosearchsite.dll MD5: 4AAA70B2D8990FF8C003D02C3450DF58 Size:13824 %PROGRAMFILES%\Helper\supersearcheng.dll MD5: 6B73BBBF533FA4EE118428AF23BDDFF9 Size:15872 %PROGRAMFILES%\Helper\1204044177.dll MD5: 1EC7F7108034DE64D566A18F03FEF1AB Size:12800 %PROGRAMFILES%\Helper\superfindout.dll MD5: 1ADA2FC3C848B2041C9792B2EF9D1F07 Size:15872 %PROGRAMFILES%\Helper\1205689347.dll MD5: 7F5775B9DDE4E71D2A81CB5D367CB700 Size:13312 %PROGRAMFILES%\Helper\route.exe MD5: 67D442F0DBEE60CFB43F821B554F44F6 Size:19968 %PROGRAMFILES%\Helper\ping.exe MD5: E46336F1DB355C03B6C07D3FA3DD8CBA Size:16384 %PROGRAMFILES%\Helper\info.exe MD5: A79674B6E34D3247CFDFE3BD00EA1B34 Size:741421 %PROGRAMFILES%\Helper\getmac.exe MD5: 802E4BB4945D8E923481E90B8CF8D62C Size:55296 %PROGRAMFILES%\Helper\yourprosearch.dll MD5: 2CDB6DFF382F84FC9BF4163A13ED5B5D Size:13824 %PROGRAMFILES%\Helper\UNWISE.EXE MD5: 973567B98CDFC147DF4E60471D9DF072 Size:153088 MD5: 79979253DF215587F29028D8E70F3132 Size:165376 %PROGRAMFILES%\Helper\HWebUpdate.exe MD5: F38304D14298945A1A30A72DED9F2B7A Size:3018240 MD5: 1C79FFA06A8C4DA8A0525EBF4CB9758C Size:3541504 %PROGRAMFILES%\Helper\HRenamer.exe MD5: A53F3FC8441EA4EF58B56CFA55CE3A33 Size:338944 MD5: 7927D6EB5754E0C8A1BC5999F9596064 Size:528384 %PROGRAMFILES%\Helper\HRegViewer.exe MD5: 459DC1C122A9DD4B91B54602C6D8F151 Size:634368 %PROGRAMFILES%\Helper\HAccess.dll MD5: 6A950DFA49E936A26D45C962E1146B95 Size:3462144 %PROGRAMFILES%\Helper\Helper.exe MD5: BC31EF8FF4AAD010F08F358E2C2A3472 Size:13027840 %PROGRAMFILES%\Helper\HDataSetup.exe MD5: 87338F825F3DA17AF891A253C4E0920A Size:657920 %PROGRAMFILES%\Helper\Hcheck.exe MD5: 871D4561566061A6B6A233F223A4204C Size:1650176 MD5: E71099D2475053A347F3DCDB56ED73EF Size:776704 %PROGRAMFILES%\Helper\backup.exe MD5: F517E87D551A61831D455392194760DB Size:2192384 MD5: 46399165144DD45156C48E7BCE4C7799 Size:837120 %PROGRAMFILES%\Helper\esearcheng.dll MD5: DBEE19F5007E1FEB2D214AA4A9FCFDEE Size:15872 %PROGRAMFILES%\Helper\uninst.exe MD5: 764F27A09D5B05AEAB3F5330BE9E82AB Size:52284 %PROGRAMFILES%\Helper\Setup_B.exe MD5: 773781543C13B0344621E35DC3BB961B Size:109592 %PROGRAMFILES%\Helper\SetupF_freang.exe MD5: 0C9FAC16A8FA3016E3A595C12E013ADF Size:1688240 %PROGRAMFILES%\Helper\ang.exe MD5: D9C193336D49158A8076677A76A020DC Size:86016 %PROGRAMFILES%\Helper\1205405509.dll MD5: C2B50F2300608C1E5E04446324C6AD6B Size:12800 %PROGRAMFILES%\Helper\1207210986.dll MD5: 7E46FA7936EEB42DFF26A70F36C5D55E Size:13312 %PROGRAMFILES%\Helper\InfoChannel\icftm.exe MD5: 086416815CA6DFF6852E7CD179B70E7D Size:401408 %PROGRAMFILES%\Helper\HServerAdmin.exe MD5: BFB43139CDBFD628F0C3C508B063A9B0 Size:3439616 %PROGRAMFILES%\Helper\HelperHL7Srvr.exe MD5: F1580A7E631A14C03FA8DD5AB3EC05D1 Size:1678848 %PROGRAMFILES%\Helper\HelperDbSrvr.exe MD5: 65E65079EFD0DBD44AA8FEDB34F78C77 Size:1548288 %PROGRAMFILES%\Helper\Helper9.dll MD5: 057F41834F8BD05C5C85FCB02724AD70 Size:19456 %PROGRAMFILES%\Helper\1202693024.dll MD5: AED42A31EE11D78A6F0ADB7FD50C52D4 Size:12800
  2. Detected Files with variable Filenames: MD5: 819E599CE465AA509C344EF4EB841269 Size: 13312 %PROGRAMFILES%\Helper\1204918350.dll %PROGRAMFILES%\Helper\1205071722.dll %PROGRAMFILES%\Helper\1204767872.dll MD5: 6C234CA9F443D5816350C2A3E5BD673B Size: 12800 %PROGRAMFILES%\Helper\1201995907.dll %PROGRAMFILES%\Helper\1201995905.dll %PROGRAMFILES%\Helper\1201995863.dll %PROGRAMFILES%\Helper\1201995837.dll %PROGRAMFILES%\Helper\1201995803.dll %PROGRAMFILES%\Helper\1201995792.dll %PROGRAMFILES%\Helper\1201995759.dll %PROGRAMFILES%\Helper\1201995734.dll %PROGRAMFILES%\Helper\1201995703.dll %PROGRAMFILES%\Helper\1201995674.dll %PROGRAMFILES%\Helper\1201995642.dll and next 0 variations. MD5: 14C373DF44958E1D305190122482AA72 Size: 13312 %PROGRAMFILES%\Helper\1208003874.dll %PROGRAMFILES%\Helper\1208003869.dll %PROGRAMFILES%\Helper\1208003864.dll %PROGRAMFILES%\Helper\1208003858.dll %PROGRAMFILES%\Helper\1208003853.dll %PROGRAMFILES%\Helper\1208003849.dll %PROGRAMFILES%\Helper\1208003843.dll %PROGRAMFILES%\Helper\1208003836.dll %PROGRAMFILES%\Helper\1208003831.dll %PROGRAMFILES%\Helper\1208003815.dll %PROGRAMFILES%\Helper\1205709629.dll and next 15 variations. MD5: 0309CFA4DA3DD8729F539CA41160D5DC Size: 12800 %PROGRAMFILES%\Helper\1202497175.dll %PROGRAMFILES%\Helper\1202497172.dll %PROGRAMFILES%\Helper\1202497168.dll %PROGRAMFILES%\Helper\1202497163.dll %PROGRAMFILES%\Helper\1202497159.dll %PROGRAMFILES%\Helper\1202497156.dll %PROGRAMFILES%\Helper\1202497151.dll %PROGRAMFILES%\Helper\1202497144.dll %PROGRAMFILES%\Helper\1202497139.dll %PROGRAMFILES%\Helper\1202497133.dll %PROGRAMFILES%\Helper\1202497126.dll and next 1 variations.

Detecting items list:

  1. Files by Name %START_PROGRAMS%\Help\I-Spy on the Web.lnk %START_PROGRAMS%\Help\I-Spy.lnk %START_PROGRAMS%\Help\Read Me First.lnk %START_PROGRAMS%\Help\Uninstall I-Spy.lnk %DESKTOP%\I-Spy.lnk %ProgramFiles%\Helper\Help.exe %ProgramFiles%\Helper\I-Spy.url %ProgramFiles%\Helper\min.dat %ProgramFiles%\Helper\readme.txt %ProgramFiles%\Helper\unins000.dat %ProgramFiles%\Helper\unins000.exe %sysdir%\cat.dll %Windir%\ispy.dll
  2. Files by Directories %ProgramFiles%\Helper
  3. Registry Keys HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\I-Spy
  4. Registry Values HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ValueName=ISHelp

« Go to Software Database