When Spyware.AdvancedKey is installed, the following actions are performed:
- Displays the End-User License Agreement.
- Prompts for the installation folder. The default installation folder is %Windir%\IDDE.
Notes: %Windir% is a variable. By default, this is C:\Windows or C:\Winnt.
- Creates following files and folders:
- %Windir%\IDDE\kmonitor.exe: Main application for logging viewing and configuring. Detected as Spyware.AdvancedKey.
- %Windir%\IDDE\License.txt: License information.
- %Windir%\IDDE\manual.chm: Help file.
- %Windir%\IDDE\readme.txt: Documentation.
- %Windir%\IDDE\register.bat: Used for registering the Spyware.
- %Windir%\IDDE\Setup.exe: Used to place the files in the proper location and set up registries. Detected as Spyware.AdvancedKey.
- %Windir%\IDDE\setup.log: Log of the installation process.
- %Windir%\IDDE\trace.exe: Used to trace screenshots. Detected as Spyware.AdvancedKey.
- %Windir%\IDDE\uninstall.bat: Used for uninstallation.
- %Windir%\IDDE\Uninstall.exe: Generic uninstaller.
- %Windir%\IDDE\wrk.log: Log of the installation process.
- %Windir%\system\svchost.exe: Main logger. Detected as Spyware.AdvancedKey.
- %System%\TMLib.dll: Used for saving logs and setting up the environment for logging. Detected as Spyware.AdvancedKey.
- %System%\TMUtils.dll: Used for saving screenshots and tracing the screeshots. Detected as Spyware.AdvancedKey.
- %Windir%\IDDE\CLPBR\: Directory that contains screenshots.
- %Windir%\ddemal32.bin: Log file.
- %Windir%\system\setup.log
- %Windir%\system\MSIDLLSI.DAT
Note: %System% is a variable. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
- Creates the following registry subkeys:
HKEY_LOCAL_MACHINE\Software\Microsoft\IDDE
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DEE6806C-FB33-D04C-E1C6-8DA9B2204850}
HKEY_LOCAL_MACHINE\SOFTWARE\Licenses
- Creates a service with the following attributes:
Service name: svchost
Display name: MS Software Generic Host Process for Win32 Services
Path to executable: %Windir%\system\svchost.exe
Startup type: Automatic
- Performs the following actions:
- Logs keystrokes
- Monitors the clipboard
- Captures screenshots
- Monitors Internet activity
- Emails log files
- Hides and unhides its Taskbar icon using the Ctrl+Alt+Del+R key combination