NetMama
|
Description:
|
Keylogger
|
|
Risk Level:
|
Critical
|
|
Date of First Occurence:
|
Tuesday, July 10, 2007
|
|
Software Developer:
|
(unknown)
|
|
Brief Info:
|
Keyloggers invisibly monitor and record all of your computer activity. This information is then automatically emailed to an anonymous user.
|
|
Removal:
|
This threat can be removed using "Spyware
Terminator"
|
REMOVER SPYWARE »
Geographical Distribution of Threat "NetMama"
Threat Info
View All
Detecting items list:
- Files by Name
%ProgramFiles%\Provisqz\dAPIs.dll
%ProgramFiles%\Provisqz\gongli.dll
%ProgramFiles%\Provisqz\jet32.dll
%ProgramFiles%\Provisqz\mama.dll
%ProgramFiles%\Provisqz\nbc.exe
%ProgramFiles%\Provisqz\nmmhelper.dll
%ProgramFiles%\Provisqz\nmst.exe
%ProgramFiles%\Provisqz\pch.dll
%COMMONFILES%\mmtsb\ebc_net.dll
%COMMONFILES%\mmtsb\logi0321.dll
%COMMONFILES%\mmtsb\net_m_m.exe
%COMMONFILES%\mmtsb\netm0_d.dll
%COMMONFILES%\mmtsb\NMimeF.dll
%COMMONFILES%\mmtsb\odbc.dll
%COMMONFILES%\mmtsb\pptq.dat
%sysdir%\net_3201.dll
- Files by Directories
%ProgramFiles%\Provisqz
%COMMONFILES%\mmtsb
- Files by CLSID or Name
CLSID=184AF5F9-FB5C-4D70-95C8-3613B5DC0E23
CLSID=7D9ED5A8-EDBB-4B42-B549-DD4184E25592
- Registry Keys
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{184AF5F9-FB5C-4D70-95C8-3613B5DC0E23}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{184AF5F9-FB5C-4D70-95C8-3613B5DC0E23}
«
Go to Software Database