ICQ Password Recovery

ICQ Password Recovery is a password recovery tool that may be used to gain unauthorized access to a computer and to a user s data. It is harmful if installed without the knowledge of the user.

General information:

Malware Name: ICQ Password Recovery
Malware Type: Password Recovery Tool
Company Name: Alpine Snow
Company URL: http://www.alpinesnow.com/
Threat Level: Low Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

Alpine Snow provides you the software ICQ Password Recovery that can recover passwords to any version of ICQ. Just select the .dat file of the ICQ user and the username and password will instantly be decrypted. Tested on all ICQ versions. Press Open DAT File to open the ICQ DAT file that you want to recover the password to. This file is usually located in one of the sub folders of the ICQ directory.

Spyware Description:

ICQ Password Recovery is a password recovery tool that may be used to gain unauthorized access to a computer and to a user s data. It is harmful if installed without the knowledge of the user.

Characteristics/Symptoms:

    -> It is harmful if installed without the knowledge of the user. -> It may be used to gain unauthorized access to a computer and to a user s data.

Additional information might be found here:

google Search at Google for ICQ Password Recovery
bing Search at Bing for ICQ Password Recovery
yahoo Search at Yahoo for ICQ Password Recovery

Processes Running:

ICQRecovery.exe

File information Created after Installation:

File Location Size (Bytes) Type
C:\Program Files\ICQ Password Recovery 2005\IBuildLib1.dll 57344 Application Extension
C:\Program Files\ICQ Password Recovery 2005\ICQRecovery.exe 28160 Application
C:\Program Files\ICQ Password Recovery 2005\INSTALL.LOG 1647 Text Document

Folder information Created after Installation:

Folder Location
C:\Documents and Settings\[USER]\Start Menu\Programs\ICQ Password Recovery 200

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ICQ Password Recovery 2005 Changed
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ICQ Password Recovery 2005
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ICQ Password Recovery 2005 UninstallString