Mom Knows Best

Mom Knows Best is a keylogger that logs keystrokes of the user's PC covertly. Mom Knows Best is a keylogger that logs keystrokes of the user's PC covertly. Its features are as follows: Record keystrokes, record all websites visited by the user, file logging, and work under hidden mode.0

General information:

Malware Name: Mom Knows Best
Malware Type: Key Logger
Company Name: Ion-I
Company URL: http://ion-i.com/
Threat Level: Elevated Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

Ion-I is a small solutions development firm. It is dedicated to developing high end software for personal and corporate use. It also strives to create a vast community for families and educators. Its main goal is to create a safe monitor able computing experience for use with personal or business computers. To select clients we also perform custom software products and services.

Spyware Description:

Mom Knows Best is a keylogger that logs keystrokes of the user's PC covertly. Mom Knows Best is a keylogger that logs keystrokes of the user's PC covertly. Its features are as follows: Record keystrokes, record all websites visited by the user, file logging, and work under hidden mode.0

Characteristics/Symptoms:

    -> Monitor and capture data from computers -> Run in stealth mode -> Intercepts keystrokes from the keyboard and records them in a log -> Starts with the operating system0

Additional information might be found here:

google Search at Google for Mom Knows Best
bing Search at Bing for Mom Knows Best
yahoo Search at Yahoo for Mom Knows Best

Processes Running:

iSrv.exe

File information Created after Installation:

File Location Size (Bytes) Type
C:\WINDOWS\system32\mData\iClnt.exe 53248 Application
C:\WINDOWS\system32\mData\iFL.dat 1354 DAT File
C:\WINDOWS\system32\mData\iNL.dat 3603 DAT File

Folder information Created after Installation:

Folder Location

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindowsCurrentVersionUninstall{24E9D290-2D27-4E1C-A9B5-32C03A4893C8} VersionMajor
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindowsCurrentVersionUninstall{24E9D290-2D27-4E1C-A9B5-32C03A4893C8} VersionMinor
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindowsCurrentVersionUninstall{24E9D290-2D27-4E1C-A9B5-32C03A4893C8} WindowsInstaller