AlphaOne Technology Support Forums
Welcome, Guest. Please login or register.
January 08, 2009, 03:15:11 AM

Login with username, password and session length
Search:     Advanced search
1733 Posts in 827 Topics by 5342 Members
Latest Member: hikslyypro
* Home Help Search Login Register
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Security Announcements  |  Windows-based Security Issues  |  Topic: Hacktool.Spytector 0 Members and 0 Guests are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: Hacktool.Spytector  (Read 832 times)
Brad
SysAdmin
Tech Team
Hero Member
********
Offline Offline

Posts: 391



View Profile
Hacktool.Spytector
« on: June 13, 2005, 12:51:08 AM »

Behavior
Hacktool.Spytector is a hack tool used to generate customizable spyware that has the ability to log keystrokes.

Symptoms
One or more files are detected as Hacktool.Spytector.

Transmission
The file must be manually executed to install this program.

technical details
File names: Spytector.exe

When Hacktool.Spytector is executed, it performs the following actions:

   1. Creates the folder %ProgramFiles%\Spytector

      Note: %ProgramFiles% is a variable that refers to the program files folder. By default, this is C:\Program Files.

   2. Creates the following files in the folder %ProgramFile%\Spytector:

          * Spytector.exe
          * Help.chm
          * ReadMe.txt
          * License.html
          * Spytector Purchase

   3. Creates the following registry subkeys:

      HKEY_CURRENT_USER\Software\Spytector\1.2.5
      HKEY_LOCAL_MACHINE\Windows\CurrentVersion\Uninstall\Spytector\1.2.5

   4. Displays a dialog box that is used to create customizable spyware. Customizable features of the spyware include:

          * Server name (Filename)
          * Logfile name
          * Startup key (GUID)
          * Log delivery method (Email, FTP, or Browser.)
          * Adding password
          * Automatic uninstallation
          * Keylogger filter
          * Icon

REMOVAL INSTRUCTIONS
See: http://securityresponse.symantec.com/avcenter/venc/data/hacktool.spytector.html

To delete the value from the registry
   1. Click Start > Run.
   2. Type regedit

      Then click OK.

      Note: If the registry editor fails to open the risk may have modified the registry to prevent access to the registry editor. Security Response has developed a tool to resolve this problem. Download and run this tool, and then continue with the removal.

   3. Navigate to and delete the following subkeys:

      HKEY_CURRENT_USER\Software\Spytector\1.2.5
      HKEY_LOCAL_MACHINE\Windows\CurrentVersion\Uninstall\Spytector\1.2.5

   4. Exit the Registry Editor.
Logged

Pages: [1] Go Up Print 
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Security Announcements  |  Windows-based Security Issues  |  Topic: Hacktool.Spytector « previous next »
Jump to:  

Powered by MySQL Powered by PHP AlphaOne Technology Support Forums | Powered by SMF 1.0.7.
© 2001-2005, Lewis Media. All Rights Reserved.
Valid XHTML 1.0! Valid CSS!