AnalogX PacketMon
AnalogX PacketMon is a remote control that allows administrators to manage and control PCs or networks from a remote location. Can always watch what users are doing on the remote computer.
General information:
Malware Name: |
AnalogX PacketMon |
Malware Type: |
Remote Control |
Company Name: |
AnalogX |
Company URL: |
http://www.analogx.com/
|
Threat Level: |
Low Risk |
Operating System: |
WIN XP |
Installation Type: |
Installed through EXE |
Operation: |
Time of After Installation |
Company Description:
AnalogX provides you the software AnalogX PacketMon that is a packet capture utility used to capture and analyze IP traffic. It allows you to capture IP packets that pass through your network interface. Once the packet is received, you can use the
built in viewer to examine the IP header as well as the contents.
Spyware Description:
AnalogX PacketMon is a remote control that allows administrators to manage and control PCs or networks from a remote location. Can always watch what users are doing on the remote computer.
Characteristics/Symptoms:
-> It can be used to view the contents sent through network, by capturing IP packets passing through the network. -> It can be used to watch what users are doing on the remote computer. -> Slow down the performance of PC.
Additional information might be found here:
Processes Running:
pmon.exe
File information Created after Installation:
File Location |
Size (Bytes) |
Type |
C:\Documents and Settings\[USER]\Local Settings\Temp\Del28.exe |
118452 |
Application |
C:\Documents and Settings\[USER]\Start Menu\Programs\AnalogX\PacketMon\PacketMon.lnk |
1585 |
Shortcut |
C:\Program Files\AnalogX\PacketMon\AnalogX Website.URL |
97 |
Internet Shortcut |
Folder information Created after Installation:
Folder Location |
C:\Documents and Settings\[USER]\Start Menu\Programs\Analog |
C:\Documents and Settings\[USER]\Start Menu\Programs\AnalogX\PacketMo |
Registry information Created after Installation:
Main Registry Key |
Sub Registry Key |
Key Value Name |
HKEY_CURRENT_USER |
\Software\AnalogX\PacketMon |
|
HKEY_CURRENT_USER |
\Software\AnalogX\PacketMon |
Auto New |
HKEY_CURRENT_USER |
\Software\AnalogX\PacketMon |
Packet View |