Spyware.ActivityKey

Printer Friendly Page

Updated: February 13, 2007 11:42:55 AM
Type: Spyware
Version: 1.60
Publisher: softcows.com
Risk Impact: High
File Names: actik.exe hidden.dll chatlogs.dll akeylogger.exe
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP


When Spyware.ActivityKey is installed, the following actions are performed:

  1. Creates the following files:

    • %Userprofile%\Desktop\Activity Keylogger.lnk
    • %Userprofile%\Start Menu\Programs\Activity Keylogger\Activity Keylogger Help.lnk
    • %Userprofile%\Start Menu\Programs\Activity Keylogger\Activity Keylogger.lnk
    • %Userprofile%\Start Menu\Programs\Activity Keylogger\Uninstall Activity Keylogger.lnk
    • %ProgramFiles%\Activity Keylogger\actik.exe
    • %ProgramFiles%\Activity Keylogger\black.lis
    • %ProgramFiles%\Activity Keylogger\help.chm
    • %ProgramFiles%\Activity Keylogger\hidden.dll
    • %ProgramFiles%\Activity Keylogger\License.txt
    • %ProgramFiles%\Activity Keylogger\Log\icons\unknownicon.bmp
    • %ProgramFiles%\Activity Keylogger\Log\null.htm
    • %ProgramFiles%\Activity Keylogger\readme.txt
    • %ProgramFiles%\Activity Keylogger\systemlog.txt
    • %ProgramFiles%\Activity Keylogger\unins000.dat
    • %ProgramFiles%\Activity Keylogger\unins000.exe
    • %ProgramFiles%\Activity Keylogger\warning.txt
    • %ProgramFiles%\Activity Keylogger\white.lis
    • %Windir%\aksettings.ini
    • %Windir%\chatlogs.dll


      Notes:
    • %ProgramFiles% is a variable that refers to the program files folder. By default, this is C:\Program Files.
    • %UserProfile% is a variable that refers to the current user's profile folder. By default, this is C:\Documents and Settings\<Current User> (Windows NT/2000/XP).
    • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.

  2. Creates the registry subkey:

    HKEY_LOCAL_MACHINE\SOFTWARE\Activity Keylogger

  3. Adds the value:

    "Activity" = "%ProgramFiles%\Activity Keylogger\actik.exe"

    to the registry key:

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

    so that the Spyware runs when you start Windows.

  4. Spyware.ActivityKey monitors user activity, logs keystrokes, takes screenshots, and can be configured to send gathered information to a specified email address.


Search by name
Example: W32.Beagle.AG@mm
Windows 7
Windows Vista Security