MI7

MI7 is a computer surveillance program. It allows you to see what have been typed on other computers including e-mails, passwords, etc.0

General information:

Malware Name: MI7
Malware Type: Key Logger
Company Name: RedPill
Company URL: http://redpill.co.za/
Threat Level: Elevated Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

RedPill is a software house with an agile approach to software development. Delivering exciting solutions on time is our passion. It allows us to monitor other computers instead of our own computer. It monitors several targets over a long period. We can view the history of each target, add notes and mark ‘smoking gun ‘sections. It’s even possible to monitor a computer where no physical access is possible.

Spyware Description:

MI7 is a computer surveillance program. It allows you to see what have been typed on other computers including e-mails, passwords, etc.0

Characteristics/Symptoms:

    -> Monitor and capture data from computers -> Run in stealth mode -> Intercepts keystrokes from the keyboard and records them in a log -> Starts with the operating system0

Additional information might be found here:

google Search at Google for MI7
bing Search at Bing for MI7
yahoo Search at Yahoo for MI7

Processes Running:

MI7Handler.exe

File information Created after Installation:

File Location Size (Bytes) Type
C:\Documents and Settings\[USER]\Start Menu\Programs\MI7\MI7.lnk 1944 Shortcut
C:\Program Files\MI7\NoImage.bmp 623094 Bitmap Image
C:\Program Files\MI7\redPillHackerManual.pdf 108766 PDF File

Folder information Created after Installation:

Folder Location
C:\Program Files\MI7

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindowsCurrentVersionUninstall{D8188199-FEF2-42E1-8D78-54176DEFC2C2} VersionMajor
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindowsCurrentVersionUninstall{D8188199-FEF2-42E1-8D78-54176DEFC2C2} VersionMinor
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindowsCurrentVersionUninstall{D8188199-FEF2-42E1-8D78-54176DEFC2C2} WindowsInstaller