PC James Bond 007
PC James Bond 007 records keystrokes, screenshots, websites visited, programs run, and chat conversations.It then sends the record to a pre-determined e-mail address. User can also view the record on the monitored computer.0
General information:
Malware Name: |
PC James Bond 007 |
Malware Type: |
Key Logger |
Company Name: |
eMatrixSoft, Inc. |
Company URL: |
http://www.ematrixsoft.com/
|
Threat Level: |
Elevated Risk |
Operating System: |
WIN XP |
Installation Type: |
Installed through EXE |
Operation: |
Time of After Installation |
Company Description:
eMatrixSoft, Inc. provides us the keylogger PC James Bond 007 log all keystrokes, including optional non-alphanumerical keys, typed with time, Windows username, application name and window caption. It also monitors and records all latest versions
Skype/MSN/ICQ/AIM/YAHOO! Messenger's both sides chatting conversations with time, chat users, and all coming/outgoing messages. It also logs the username and password used to login in a messenger.
Spyware Description:
PC James Bond 007 records keystrokes, screenshots, websites visited, programs run, and chat conversations.It then sends the record to a pre-determined e-mail address. User can also view the record on the monitored computer.0
Characteristics/Symptoms:
-> Monitor and capture data from computers -> Run in stealth mode -> Intercepts keystrokes from the keyboard and records them in a log -> Starts with the operating system0
Additional information might be found here:
Processes Running:
pscs.exe
File information Created after Installation:
File Location |
Size (Bytes) |
Type |
C:\Program Files\PSCS\data\emxfile.emx |
270336 |
EMX File |
C:\Program Files\PSCS\data\symserv.exe |
32768 |
Application |
C:\Program Files\PSCS\data\sysmon32.exe |
118784 |
Application |
Folder information Created after Installation:
Folder Location |
C:\Program Files\PSCS |
C:\Program Files\PSCS\data |
Registry information Created after Installation:
Main Registry Key |
Sub Registry Key |
Key Value Name |
HKEY_CLASSES_ROOT |
CLSID{DBAAEA4B-AD29-47BD-8776-C787D5BE28AA}InprocServer32 |
ThreadingModel |
HKEY_CLASSES_ROOT |
CLSID{E5FF9F62-0E7C-4372-8AD5-DA7D2418070C}InprocServer32 |
ThreadingModel |
HKEY_CLASSES_ROOT |
CLSID{F812B147-0E26-4222-8EE4-9F753CD2B39C}InprocServer32 |
ThreadingModel |