ChatChecker
ChatChecker is a keylogger with elevated risk that monitors and captures data from computers including screenshots, keystrokes, web cam and microphone data, instant messaging chat sessions, email, visited websites and captures all inbound and outbound
messenger Chat.0
General information:
Malware Name: |
ChatChecker |
Malware Type: |
Key Logger |
Company Name: |
IMbrella Software Inc |
Company URL: |
http://chatchecker.com/
|
Threat Level: |
Elevated Risk |
Operating System: |
WIN XP |
Installation Type: |
Installed through EXE |
Operation: |
Time of After Installation |
Company Description:
IMbrella Software Inc provides you the software ChatChecker that is a surveillance tool. It captures and records instant message conversations of both sides.
Spyware Description:
ChatChecker is a keylogger with elevated risk that monitors and captures data from computers including screenshots, keystrokes, web cam and microphone data, instant messaging chat sessions, email, visited websites and captures all inbound and outbound
messenger Chat.0
Characteristics/Symptoms:
-> Starts with the operating system -> Monitor and capture data from computers -> Run in stealth mode -> Intercepts keystrokes from the keyboard and records them in a log0
Additional information might be found here:
Processes Running:
lite.exe
File information Created after Installation:
File Location |
Size (Bytes) |
Type |
C:\WINDOWS\system32\Event Agent\Bin\ipconfigbat.bat |
19 |
MS-DOS Batch File |
C:\WINDOWS\system32\Event Agent\INSTALL.LOG |
7173 |
Text Document |
C:\WINDOWS\system32\Event Agent\ea.exe |
45056 |
Application |
Folder information Created after Installation:
Folder Location |
C:\WINDOWS\system32\Event Agent |
C:\WINDOWS\system32\Event Agent\Bin |
Registry information Created after Installation:
Main Registry Key |
Sub Registry Key |
Key Value Name |
HKEY_LOCAL_MACHINE |
\SOFTWARE\p2plog\p2pLog\1.0\control |
NoIcon0 |
HKEY_LOCAL_MACHINE |
\SOFTWARE\p2plog\p2pLog\1.0\control |
NoWeb0 |
HKEY_LOCAL_MACHINE |
\SOFTWARE\p2plog\p2pLog\1.0\control |
OnlyMyPC0 |