ChatChecker

ChatChecker is a keylogger with elevated risk that monitors and captures data from computers including screenshots, keystrokes, web cam and microphone data, instant messaging chat sessions, email, visited websites and captures all inbound and outbound messenger Chat.0

General information:

Malware Name: ChatChecker
Malware Type: Key Logger
Company Name: IMbrella Software Inc
Company URL: http://chatchecker.com/
Threat Level: Elevated Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

IMbrella Software Inc provides you the software ChatChecker that is a surveillance tool. It captures and records instant message conversations of both sides.

Spyware Description:

ChatChecker is a keylogger with elevated risk that monitors and captures data from computers including screenshots, keystrokes, web cam and microphone data, instant messaging chat sessions, email, visited websites and captures all inbound and outbound messenger Chat.0

Characteristics/Symptoms:

    -> Starts with the operating system -> Monitor and capture data from computers -> Run in stealth mode -> Intercepts keystrokes from the keyboard and records them in a log0

Additional information might be found here:

google Search at Google for ChatChecker
bing Search at Bing for ChatChecker
yahoo Search at Yahoo for ChatChecker

Processes Running:

lite.exe

File information Created after Installation:

File Location Size (Bytes) Type
C:\WINDOWS\system32\Event Agent\Bin\ipconfigbat.bat 19 MS-DOS Batch File
C:\WINDOWS\system32\Event Agent\INSTALL.LOG 7173 Text Document
C:\WINDOWS\system32\Event Agent\ea.exe 45056 Application

Folder information Created after Installation:

Folder Location
C:\WINDOWS\system32\Event Agent
C:\WINDOWS\system32\Event Agent\Bin

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_LOCAL_MACHINE \SOFTWARE\p2plog\p2pLog\1.0\control NoIcon0
HKEY_LOCAL_MACHINE \SOFTWARE\p2plog\p2pLog\1.0\control NoWeb0
HKEY_LOCAL_MACHINE \SOFTWARE\p2plog\p2pLog\1.0\control OnlyMyPC0