ICQ Sniffer

ICQ Sniffer is a spyware that captures and log ICQ chats from computers. It also export captured ICQ conversations as HTML files.

General information:

Malware Name: ICQ Sniffer
Malware Type: Spyware
Company Name: EffeTech
Company URL: http://effetech.com/
Threat Level: Moderate Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

EffeTech provides you the software ICQ Sniffer that for ICQ monitoring (also known as EtherBoss Monitor) is a handy network utility to capture and log ICQ chats from computers within the same LAN. It supports messaging through ICQ server with format of plain text, RTF, or HTML. All intercepted messages are well organized by ICQ user with buddies and shown instantly on the main window. It provides rich-features report system to export captured ICQ conversations as HTML files for later analyzing and reference.

Spyware Description:

ICQ Sniffer is a spyware that captures and log ICQ chats from computers. It also export captured ICQ conversations as HTML files.

Characteristics/Symptoms:

    -> It captures and log ICQ chats from computers. -> It also export captured ICQ conversations as HTML files.

Additional information might be found here:

google Search at Google for ICQ Sniffer
bing Search at Bing for ICQ Sniffer
yahoo Search at Yahoo for ICQ Sniffer

Processes Running:

IcqSniffer.exe

File information Created after Installation:

File Location Size (Bytes) Type
C:\Program Files\IcqSniffer\bottombk.jpg 286 ViewerInDepth JPG image
C:\Program Files\IcqSniffer\eula.txt 1798 Text Document
C:\Program Files\IcqSniffer\help.htm 14246 Firefox Document

Folder information Created after Installation:

Folder Location
C:\Documents and Settings\All Users\Start Menu\Programs\ICQ Sniffe
C:\Documents and Settings\[USER]\Start Menu\Programs\ICQ Sniffe

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_CURRENT_USER \Software\EffeTech\ICQ Sniffer 15-day Evaluation Version\General
HKEY_CURRENT_USER \Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\ICQ Sniffer
HKEY_CURRENT_USER \Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\ICQ Sniffer Order