Behavior
Spyware.HiddenRecorder periodically takes screenshots of the computer.
Symptoms
Files are detected as Spyware.HiddenRecorder.
Transmission
Spyware.HiddenRecorder must be manually installed.
technical details
File names:
HR.exe
hr_setup.exe
When Spyware.HiddenRecorder is installed, it does the following:
1. Creates the following files:
* %UserProfile%\Desktop\hr_setup.exe
* %ProgramFiles%\Oleansoft\HR\Archive\Readme.txt
* %ProgramFiles%\Oleansoft\HR\HR.EXE
* %ProgramFiles%\Oleansoft\HR\HRHELP.CHM
* %ProgramFiles%\Oleansoft\HR\License.txt
* %ProgramFiles%\Oleansoft\HR\Uninstal.exe
* %Windir%\system\Winhr15.dll
* %Windir%\hrdir.ini
Note:
* %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
* %UserProfile% is a variable that refers to the current user's profile folder. By default, this is C:\Documents and Settings\[Current User] (Windows NT/2000/XP).
* %ProgramFiles% is a variable that refers to the program files folder. By default, this is C:\Program Files.
2. Creates the following registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hidden Recorder
3. Adds the value:
"HR" = "C:\Program Files\Oleansoft\HR\Hr.exe"
to the registry subkey:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
to ensure the programs runs on windows startup.
REMOVAL INSTRUCTIONSSee:
http://securityresponse.symantec.com/avcenter/venc/data/spyware.hiddenrecorder.htmlTo delete the value from the registry 1. Click Start > Run.
2. Type regedit
Then click OK.
Note: If the registry editor fails to open the risk may have modified the registry to prevent access to the registry editor. Security Response has developed a tool to resolve this problem. Download and run this tool, and then continue with the removal.
3. Navigate to and delete the following subkey:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hidden Recorder
4. Navigate to the subkey:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
5. In the right pane, delete the value:
"HR" = "C:\Program Files\Oleansoft\HR\Hr.exe"
6. Exit the Registry Editor.