Big Mother

Big Mother is a keylogger that logs URL visits, Email, chats, games, FTP, and data flows. It also takes webpage snapshots and records MSN messenger content.

General information:

Malware Name: Big Mother
Malware Type: Keylogger
Company Name: Tup Software Ltd
Company URL: http://tupsoft.com/
Threat Level: Elevated Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

Tup Software Ltd provides you the software Big Mother that not only logs in real time URL visits, Email, chats, games, FTP, and data flows, but also takes webpage snapshots, duplicates Email and FTP copies, records MSN messenger content, and gives statistical reports. It freely restricts online activities with time schedules and according to customized filtering Internet rules.

Spyware Description:

Big Mother is a keylogger that logs URL visits, Email, chats, games, FTP, and data flows. It also takes webpage snapshots and records MSN messenger content.

Characteristics/Symptoms:

    -> It logs URL visits, Email, chats, games, FTP, and data flows. -> It also takes webpage snapshots and records MSN messenger content.

Additional information might be found here:

google Search at Google for Big Mother
bing Search at Bing for Big Mother
yahoo Search at Yahoo for Big Mother

Processes Running:

BigMother.exe

File information Created after Installation:

File Location Size (Bytes) Type
C:\Program Files\Tupsoft\BigMother\Engine\ArServerDaemon.exe 126976 Application
C:\Program Files\Tupsoft\BigMother\Engine\ArValidate.dll 274432 Application Extension
C:\Program Files\Tupsoft\BigMother\Engine\ArsFile.dll 147456 Application Extension

Folder information Created after Installation:

Folder Location
C:\Program Files\Tupsoft\BigMothe
C:\Program Files\Tupsoft\BigMother\Consol

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{6B5B1F2E-73AA-4BEE-904F-F50B0777CBE8} SlowInfoCache
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\C:\AnyRouter
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\C:\AnyRouter\AnyRouterרҵ°æ