eSpyNow

eSpyNow is a spyware with high risk that logs keystrokes and captures screen shots. It records URLs but only when it will run under stealth mode and is hidden from the user.0

General information:

Malware Name: eSpyNow
Malware Type: Spyware
Company Name: eSunSoft Technologies
Company URL: http://www.espynow.com/
Threat Level: High Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

eSunSoft Technologies provides you the software eSpyNow that secretly record email, chat, instant messages and even password! It monitors internet activity, logs key strokes, and captures screenshots. It also can email logs to a predefined address. It works in extreme stealth mode and is completely hidden and moreover it’s easy to use.

Spyware Description:

eSpyNow is a spyware with high risk that logs keystrokes and captures screen shots. It records URLs but only when it will run under stealth mode and is hidden from the user.0

Characteristics/Symptoms:

    -> It logs keystrokes and captures screen shots. -> It records URLs but only when it will run under stealth mode. -> It is hidden from the user.0

Additional information might be found here:

google Search at Google for eSpyNow
bing Search at Bing for eSpyNow
yahoo Search at Yahoo for eSpyNow

Processes Running:

SVCH0ST.EXE

File information Created after Installation:

File Location Size (Bytes) Type
C:\WINDOWS\system32\VIS9286.TMP 1 TMP File
C:\WINDOWS\system32\vddrivers\BlockUserFilter.spy unknown SPY File
C:\WINDOWS\system32\vddrivers\ErrorLogFile.txt 61 Text Document

Folder information Created after Installation:

Folder Location
C:\Documents and Settings\All Users\Start Menu\Programs\eSpyNow v2.0
C:\WINDOWS\system32\vddrivers

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_CURRENT_USER \Software\Microsoft\Windows\CurrentVersion\Run reg2.00
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eSpyNow v2.0 DisplayName0
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eSpyNow v2.0 [NULL]0