Spyware.BrowserSpy

Printer Friendly Page

Updated: February 7, 2007 7:21:21 PM
Type: Spyware
Name: BrowserSpy
Version: 1.0.0.1
Publisher: ChronexSoftware
Risk Impact: Medium
Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows NT, Windows 2000

Once the security risk is installed, it creates the following files:
  • %ProgramFiles%\ChironexSoftware\BrowserSpy\ATL71.dll
  • %ProgramFiles%\ChironexSoftware\BrowserSpy\BrowserSpy.dll
  • %ProgramFiles%\ChironexSoftware\BrowserSpy\install.lnk
  • %ProgramFiles%\ChironexSoftware\BrowserSpy\install.log
  • %ProgramFiles%\ChironexSoftware\BrowserSpy\installation.html
  • %ProgramFiles%\ChironexSoftware\BrowserSpy\readme.txt
  • %ProgramFiles%\ChironexSoftware\BrowserSpy\SciLexer.dll
  • %ProgramFiles%\ChironexSoftware\BrowserSpy\Uninstall.exe
  • %ProgramFiles%\ChironexSoftware\BrowserSpy\web\browserspy.url

It then creates the following registry subkeys:
HKEY_CLASSES_ROOT\BrowserSpy.BrowserSpyInspectBar.1
HKEY_CLASSES_ROOT\BrowserSpy.BrowserSpyInspectBar
HKEY_CLASSES_ROOT\BrowserSpy.BrowserSpySourceBar.1
HKEY_CLASSES_ROOT\BrowserSpy.BrowserSpySourceBar
HKEY_CLASSES_ROOT\CLSID\{3FE18ADB-116B-4327-8FB8-F125B4CC2F51}
HKEY_CLASSES_ROOT\CLSID\{F3494B2D-DCD1-4CC5-A688-D8D49CAB3180}
HKEY_CLASSES_ROOT\TypeLib\{B193CA7C-F25F-47E9-BAE1-787A8995AD1F}\1.0
HKEY_CLASSES_ROOT\Interface\{C0C9F698-8D42-4208-A301-D1E9EA0656B7}
HKEY_CLASSES_ROOT\Interface\{547DB85E-E010-489B-9F4C-9CB76CC6D9FF}
HKEY_CLASSES_ROOT\TypeLib\{44EC0535-400F-11D0-9DCD-00A0C90391D3}\1.0
HKEY_CLASSES_ROOT\Interface\{B2D0778B-AC99-4C58-A5C8-E7724E5316B5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{F3494B2D-DCD1-4CC5-A688-D8D49CAB3180}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{3FE18ADB-116B-4327-8FB8-F125B4CC2F51}

The security risk creates the following registry entries:
HKEY_LOCAL_MACHINE\Software\ChironexSoftware\BrowserSpy\"Version"="1.0.0.0"
HKEY_LOCAL_MACHINE\Software\ChironexSoftware\BrowserSpy\"SciLexer"="%ProgramFiles%\ChironexSoftware\BrowserSpy\SciLexer.dll"
HKEY_LOCAL_MACHINE\Software\ChironexSoftware\BrowserSpy\"ini"="%ProgramFiles%\ChironexSoftware\BrowserSpy\bspy.ini"
HKEY_LOCAL_MACHINE\Software\ChironexSoftware\BrowserSpy\"sdhash"=""
HKEY_LOCAL_MACHINE\Software\ChironexSoftware\BrowserSpy\"postinstall"="%ProgramFiles%\ChironexSoftware\BrowserSpy\installation.html"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BrowserSpy\"DisplayName"=""
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BrowserSpy\"UninstallString"=""
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BrowserSpy\"InstallLocation"=""
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BrowserSpy\"(Default)"=""
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BrowserSpy\"DisplayName"="BrowserSpy"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BrowserSpy\"UninstallString"=""%ProgramFiles%\ChironexSoftware\BrowserSpy\Uninstall.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BrowserSpy\%ProgramFiles%\ChironexSoftware\BrowserSpy\install.log""
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BrowserSpy\"InstallLocation"="%ProgramFiles%\ChironexSoftware\BrowserSpy"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BrowserSpy\"InstallSource"="%SystemDrive%"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BrowserSpy\"InstallSourceFile"="%SystemDrive%\bs1-0setup.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BrowserSpy\"InstallDate"="[Date this software is installed]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BrowserSpy\"Publisher"="ChironexSoftware"

The security risk monitors Internet Explorer and computer usage.
Search by name
Example: W32.Beagle.AG@mm
Limited Time Offers! Save up to 50%
Windows Vista Security