ChatChecker

ChatChecker is a keylogger with elevated risk that monitors and captures data from computers including screenshots, keystrokes, web cam and microphone data, instant messaging chat sessions, email, visited websites and captures all inbound and outbound messenger Chat.0

General information:

Malware Name:ChatChecker
Malware Type:Key Logger
Company Name:IMbrella Software Inc
Company URL:http://chatchecker.com/
Threat Level:Elevated Risk
Operating System:WIN XP
Installation Type:Installed through EXE
Operation:Time of After Installation

Company Description:

IMbrella Software Inc provides you the software ChatChecker that is a surveillance tool. It captures and records instant message conversations of both sides.

Spyware Description:

ChatChecker is a keylogger with elevated risk that monitors and captures data from computers including screenshots, keystrokes, web cam and microphone data, instant messaging chat sessions, email, visited websites and captures all inbound and outbound messenger Chat.0

Characteristics/Symptoms:

    -> Starts with the operating system -> Monitor and capture data from computers -> Run in stealth mode -> Intercepts keystrokes from the keyboard and records them in a log0

Additional information might be found here:

googleSearch at Google for ChatChecker
bingSearch at Bing for ChatChecker
yahooSearch at Yahoo for ChatChecker

Processes Running:

lite.exe

File information Created after Installation:

File LocationSize (Bytes)Type
C:\WINDOWS\system32\Event Agent\Bin\ipconfigbat.bat19MS-DOS Batch File
C:\WINDOWS\system32\Event Agent\INSTALL.LOG7173Text Document
C:\WINDOWS\system32\Event Agent\ea.exe45056Application

Folder information Created after Installation:

Folder Location
C:\WINDOWS\system32\Event Agent
C:\WINDOWS\system32\Event Agent\Bin

Registry information Created after Installation:

Main Registry KeySub Registry KeyKey Value Name
HKEY_LOCAL_MACHINE\SOFTWARE\p2plog\p2pLog\1.0\controlNoIcon0
HKEY_LOCAL_MACHINE\SOFTWARE\p2plog\p2pLog\1.0\controlNoWeb0
HKEY_LOCAL_MACHINE\SOFTWARE\p2plog\p2pLog\1.0\controlOnlyMyPC0