Instant Message Grabber

Instant Message Grabber is a keylogger that can record AOL instant messages and AOL instant messenger conversations.0

General information:

Malware Name: Instant Message Grabber
Malware Type: Key Logger
Company Name: BitSplash Software, LLC
Company URL: http://www.bitsplash.com/
Threat Level: Moderate Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

BitSplash Software, LLC is a developer of Instant Message monitoring software, graphics tools and other consumer targeted software. Currently, each of our software products is available for a 14-day free trial. It provides us with the keylogger Instant Message Grabber those automatically record AOL Instant Messages and AOL Instant Messenger conversations. Conversations can be conveniently browsed by Screen Name and date. It also has the ability to record only specific Screen Names. Additionally, it is able to automatically close Instant Messages from specified users.

Spyware Description:

Instant Message Grabber is a keylogger that can record AOL instant messages and AOL instant messenger conversations.0

Characteristics/Symptoms:

    -> Monitor and capture data from computers -> Run in stealth mode -> Intercepts keystrokes from the keyboard and records them in a log -> Starts with the operating system0

Additional information might be found here:

google Search at Google for Instant Message Grabber
bing Search at Bing for Instant Message Grabber
yahoo Search at Yahoo for Instant Message Grabber

Processes Running:

IMViewer.exe

File information Created after Installation:

File Location Size (Bytes) Type
C:\Documents and Settings\priya\Desktop\Instant Message Viewer.lnk 721 Shortcut
C:\Program Files\Instant Message Grabber 2.x\IMViewer.exe 1558016 Application
C:\WINDOWS\i2u_close.dll 81920 Application Extension

Folder information Created after Installation:

Folder Location
C:\Program Files\Instant Message Grabber 2.x

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindowsCurrentVersionUninstallIMG2 URLInfoAbout
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindowsCurrentVersionUninstallIMG2 UninstallString
HKEY_LOCAL_MACHINE SYSTEMCurrentControlSetServicesMGS Type