1. Symantec-Broadcom-Horizontal/
  2. Security Response/
  3. Attack Signatures/
  4. System Infected: Spyware.007SPY Install Request

System Infected: Spyware.007SPY Install Request

Severity: High

This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.

Description

This signature detects installation activities of the spyware Apropos.

Additional Information

Spyware.007Spy is a commercial spyware program that logs keystrokes, Web sites visited, programs used, and files and folder activity. It also has the ability to capture screenshots, and can use FTP or email to send all the logs to a remote server or email address.

This spyware can be run automatically in a silent, undetectable mode, and it cannot be accessed until it is brought out of silent mode. This can be done with a hotkey combination (the default combination is Ctrl+Alt+7).

Spyware:
Programs that have the ability to scan systems or monitor activity, and relay information to other computers or locations in cyberspace. Among the information that may be actively or passively gathered and disseminated by spyware are passwords, log-in details, account numbers, personal information, individual files, or other personal documents. Spyware may also gather and distribute information related to the user's computer, applications running on the computer, Internet browser usage, or other computing habits.

Spyware frequently attempts to remain unnoticed, either by actively hiding or by simply not making its presence on a system known to the user. Spyware can be downloaded from Web sites (typically in shareware or freeware), email messages, and instant messengers. Additionally, a user may unknowingly receive and/or trigger spyware by accepting an End User License Agreement from a software program linked to the spyware, or from visiting a Web site that downloads the spyware with or without an End User License Agreement.

Affected

  • Windows

Response

For instructions on how to remove this installation from your network, reference Symantec Security Response. See the reference link below.
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube