Big Mother
Big Mother is a keylogger that logs URL visits, Email, chats, games, FTP, and data flows. It also takes webpage snapshots and records MSN messenger content.
General information:
Malware Name: |
Big Mother |
Malware Type: |
Keylogger |
Company Name: |
Tup Software Ltd |
Company URL: |
http://tupsoft.com/
|
Threat Level: |
Elevated Risk |
Operating System: |
WIN XP |
Installation Type: |
Installed through EXE |
Operation: |
Time of After Installation |
Company Description:
Tup Software Ltd provides you the software Big Mother that not only logs in real time URL visits, Email, chats, games, FTP, and data flows, but also takes webpage snapshots, duplicates Email and FTP copies, records MSN messenger content, and gives
statistical reports. It freely restricts online activities with time schedules and according to customized filtering Internet rules.
Spyware Description:
Big Mother is a keylogger that logs URL visits, Email, chats, games, FTP, and data flows. It also takes webpage snapshots and records MSN messenger content.
Characteristics/Symptoms:
-> It logs URL visits, Email, chats, games, FTP, and data flows. -> It also takes webpage snapshots and records MSN messenger content.
Additional information might be found here:
Processes Running:
BigMother.exe
File information Created after Installation:
File Location |
Size (Bytes) |
Type |
C:\Program Files\Tupsoft\BigMother\Engine\ArServerDaemon.exe |
126976 |
Application |
C:\Program Files\Tupsoft\BigMother\Engine\ArValidate.dll |
274432 |
Application Extension |
C:\Program Files\Tupsoft\BigMother\Engine\ArsFile.dll |
147456 |
Application Extension |
Folder information Created after Installation:
Folder Location |
C:\Program Files\Tupsoft\BigMothe |
C:\Program Files\Tupsoft\BigMother\Consol |
Registry information Created after Installation:
Main Registry Key |
Sub Registry Key |
Key Value Name |
HKEY_LOCAL_MACHINE |
\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{6B5B1F2E-73AA-4BEE-904F-F50B0777CBE8} |
SlowInfoCache |
HKEY_LOCAL_MACHINE |
\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\C:\AnyRouter |
|
HKEY_LOCAL_MACHINE |
\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\C:\AnyRouter\AnyRouterèõ°æ |
|