Remote Install Mate Watcher Key Logger
Remote Install Mate Watcher Key Logger is a program that logs keystrokes and monitors the user without his/her knowledge. It runs in the background completely undetectable and monitors all computer activity. It can be accessed from a remote location.0
General information:
Malware Name: |
Remote Install Mate Watcher Key Logger |
Malware Type: |
Key Logger |
Company Name: |
Userfriendlyproducts Inc |
Company URL: |
http://www.matewatcher.com/
|
Threat Level: |
Elevated Risk |
Operating System: |
WIN XP |
Installation Type: |
Installed through EXE |
Operation: |
Time of After Installation |
Company Description:
Spyware Description:
Remote Install Mate Watcher Key Logger is a program that logs keystrokes and monitors the user without his/her knowledge. It runs in the background completely undetectable and monitors all computer activity. It can be accessed from a remote location.0
Characteristics/Symptoms:
-> It captures and logs keystrokes on the computer without the user's knowledge and consent. -> It is usually hidden from the user. -> The logged data may be encrypted and is typically sent to a remote attacker. -> It
can even steal the passwords.0
Additional information might be found here:
Processes Running:
csrss.exe
File information Created after Installation:
File Location |
Size (Bytes) |
Type |
C:\Documents and Settings\[USER]\Start Menu\Programs\Control Panel Software\Control Panel Help File.lnk |
644 |
Shortcut |
C:\WORKSSETUP\ControlPanel\csrss.exe |
11603968 |
Application |
C:\WORKSSETUP\ControlPanel\settings.ini |
39 |
Configuration Settings |
Folder information Created after Installation:
Folder Location |
C:\WORKSSETUP |
C:\WORKSSETUP\ControlPanel |
Registry information Created after Installation:
Main Registry Key |
Sub Registry Key |
Key Value Name |
HKEY_LOCAL_MACHINE |
SOFTWAREMicrosoftWindowsCurrentVersionUninstallControl Panel Software |
NoModify |
HKEY_LOCAL_MACHINE |
SOFTWAREMicrosoftWindowsCurrentVersionUninstallControl Panel Software |
Publisher |
HKEY_LOCAL_MACHINE |
SOFTWAREMicrosoftWindowsCurrentVersionUninstallControl Panel Software |
UninstallString |