Second Sight Keylogger

Description: Keylogger
Risk Level: Low
Date of First Occurence: Monday, April 21, 2008
Software Developer: (unknown)
Brief Info: Keyloggers invisibly monitor and record all of your computer activity. This information is then automatically emailed to an anonymous user.
Removal: This threat can be removed using "Spyware Terminator"

REMOVER SPYWARE »

Geographical Distribution of Threat "Second Sight Keylogger"

Threat Info

View All

Detected Items

  1. Detected Files: %SYSDIR%\ptrue2.DLL MD5: 179A9180E4516A845F7C8192B4E2356F Size:81920 MD5: CD9555E9D345A4A3195D1C4349719DA4 Size:73728 %SYSDIR%\ptrue.dll MD5: 4A27A933C0DD1DCF03CA5CBB1B676D4C Size:204800 %SYSDIR%\KTKbdHk3.DLL MD5: 8A669CB39A92ECB43D733E3022F4FF4E Size:12800 MD5: 28BFE18E402AA448D78497E23725F441 Size:19456
  2. Detected Files with variable Filenames:

Detecting items list:

  1. Files by Name %SYSDIR%\KTKbdHk3.DLL %SYSDIR%\mmemdrv.exe %SYSDIR%\ptrue.dll %SYSDIR%\ptrue2.DLL %SYSDIR%\complus32\DGuard2.ocx %SYSDIR%\complus32\iQCustomButton.ocx %SYSDIR%\complus32\KBDMONITOR.OCX %SYSDIR%\complus32\Psrl32.ocx %SYSDIR%\complus32\smtp.ocx %SYSDIR%\complus32\Trlpro.ocx %SYSDIR%\complus32\vsflex7l.ocx %SYSDIR%\complus32\XceedZip.dll %SYSDIR%\complus32\XIMGEDIT30.OCX %SYSDIR%\complus32\xpcheck.ocx %systemdiskroot%\System VolumeID\RP15\LibCache\MsiInterface.exe %systemdiskroot%\System VolumeID\RP15\LibCache\msunin.exe %systemdiskroot%\System VolumeID\RP15\LibCache\scvhost.exe %systemdiskroot%\System VolumeID\RP15\LibCache\svcView.exe %systemdiskroot%\System VolumeID\RP46\APIgdi32.dll %systemdiskroot%\System VolumeID\RP46\bnr16.dll %systemdiskroot%\System VolumeID\RP46\bnr32.dll %systemdiskroot%\System VolumeID\RP46\sysadmin1.dll %systemdiskroot%\System VolumeID\RP46\sysadmin2.dll %systemdiskroot%\System VolumeID\RP46\sysadmin3.dll %systemdiskroot%\System VolumeID\RP46\sysnav04.dll %systemdiskroot%\System VolumeID\RP46\sysnav3a.dll %systemdiskroot%\System VolumeID\RP46\sysnav3b.dll %systemdiskroot%\System VolumeID\RP46\wcp32.dll
  2. Registry Values HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Runf ValueName=mmemdrv

« Go to Software Database