Yahoo Logger
|
Description:
|
Keylogger
|
|
Risk Level:
|
Low
|
|
Date of First Occurence:
|
Tuesday, April 29, 2008
|
|
Software Developer:
|
(unknown)
|
|
Brief Info:
|
Keyloggers invisibly monitor and record all of your computer activity. This information is then automatically emailed to an anonymous user.
|
|
Removal:
|
This threat can be removed using "Spyware
Terminator"
|
REMOVER SPYWARE »
Geographical Distribution of Threat "Yahoo Logger"
Threat Info
View All
Detected Items
- Detected Files:
%SYSDIR%\admparsey.dll
MD5: 1055A1CB81EFDF30525CEC10BC4FB090 Size:1024
MD5: 7E2DDF6537762AB4926B4FE37EDF6296 Size:1024
MD5: 90CDFB5E8DCD0A4CA93B40901CA47BB2 Size:1024
MD5: 7BB8C2CBA847066A33FA633A433C2445 Size:1024
%SYSDIR%\csvdey\csvdey.exe
MD5: 8F4F27F5C88474C40B1F2FAAEA639E40 Size:1134080
%SYSDIR%\csvdey\csvdey.dll
MD5: 943CC8B9B17234565CF805DB3640B167 Size:92160
%SYSDIR%\csvdey\csvde.dll
MD5: EF842210675520E617DD470811F34FB6 Size:52736
%SYSDIR%\csvdey\Uninstall.exe
MD5: B5ECFE31A0FF5708CA32DD01D4FC7E19 Size:49461
%SYSDIR%\csvdey\rvy.exe
MD5: 02E60F56EC9A5E0BA93CF10D4FD3FB8E Size:681472
- Detected Files with variable Filenames:
Detecting items list:
- Files by Name
%SYSDIR%\csvdey\csvde.dll
%SYSDIR%\csvdey\csvdey.dll
%SYSDIR%\csvdey\csvdey.exe
%SYSDIR%\csvdey\file_id.diz
%SYSDIR%\csvdey\license.txt
%SYSDIR%\csvdey\rvy.dat
%SYSDIR%\csvdey\rvy.exe
%SYSDIR%\csvdey\Uninstall.exe
%SYSDIR%\csvdey\Links\Download lastest version.url
%SYSDIR%\csvdey\Links\Mail to support.url
%SYSDIR%\csvdey\Links\Program's home page.url
%SYSDIR%\csvdey\Links\Registration.url
%START_PROGRAMS%\SpyArsenal Yahoo Logger\SpyArsenal Yahoo Logger.lnk
%START_PROGRAMS%\SpyArsenal Yahoo Logger\Links\Download lastest version.lnk
%START_PROGRAMS%\SpyArsenal Yahoo Logger\Links\Mail to support.lnk
%START_PROGRAMS%\SpyArsenal Yahoo Logger\Links\Program's home page.lnk
%DESKTOP%\SpyArsenal Yahoo Logger.lnk
%SYSDIR%\admparsey.dll
- Files by Directories
%SYSDIR%\csvdey
%START_PROGRAMS%\SpyArsenal Yahoo Logger
- Registry Keys
HKLM\SOFTWARE\KMiNT21\SpyArsenal-Yahoo-Logger
HKLM\SOFTWARE\KMiNT21\Yahoo Logger
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpyArsenal-Yahoo-Logger
- Registry Values
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ValueName=csvdey
«
Go to Software Database