PC James Bond 007

PC James Bond 007 records keystrokes, screenshots, websites visited, programs run, and chat conversations.It then sends the record to a pre-determined e-mail address. User can also view the record on the monitored computer.0

General information:

Malware Name: PC James Bond 007
Malware Type: Key Logger
Company Name: eMatrixSoft, Inc.
Company URL: http://www.ematrixsoft.com/
Threat Level: Elevated Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

eMatrixSoft, Inc. provides us the keylogger PC James Bond 007 log all keystrokes, including optional non-alphanumerical keys, typed with time, Windows username, application name and window caption. It also monitors and records all latest versions Skype/MSN/ICQ/AIM/YAHOO! Messenger's both sides chatting conversations with time, chat users, and all coming/outgoing messages. It also logs the username and password used to login in a messenger.

Spyware Description:

PC James Bond 007 records keystrokes, screenshots, websites visited, programs run, and chat conversations.It then sends the record to a pre-determined e-mail address. User can also view the record on the monitored computer.0

Characteristics/Symptoms:

    -> Monitor and capture data from computers -> Run in stealth mode -> Intercepts keystrokes from the keyboard and records them in a log -> Starts with the operating system0

Additional information might be found here:

google Search at Google for PC James Bond 007
bing Search at Bing for PC James Bond 007
yahoo Search at Yahoo for PC James Bond 007

Processes Running:

pscs.exe

File information Created after Installation:

File Location Size (Bytes) Type
C:\Program Files\PSCS\data\emxfile.emx 270336 EMX File
C:\Program Files\PSCS\data\symserv.exe 32768 Application
C:\Program Files\PSCS\data\sysmon32.exe 118784 Application

Folder information Created after Installation:

Folder Location
C:\Program Files\PSCS
C:\Program Files\PSCS\data

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_CLASSES_ROOT CLSID{DBAAEA4B-AD29-47BD-8776-C787D5BE28AA}InprocServer32 ThreadingModel
HKEY_CLASSES_ROOT CLSID{E5FF9F62-0E7C-4372-8AD5-DA7D2418070C}InprocServer32 ThreadingModel
HKEY_CLASSES_ROOT CLSID{F812B147-0E26-4222-8EE4-9F753CD2B39C}InprocServer32 ThreadingModel