1. Symantec/
  2. Security Response/
  3. Attack Signatures/
  4. System Infected: Spyware.NeoSpy Activity

System Infected: Spyware.NeoSpy Activity

Severity: High

This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.

Description

This signature detects attempt by Security Risk.NeoSpy communicating and requesting information from its controlling server.

Additional Information

Once installed, the security risk creates the following folders:

* %UserProfile%\Local Settings\Temp\RarSFX0\
* %UserProfile%\Start Menu\Programs\NeoSpy\
* %ProgramFiles%\NeoSpy\
* %ProgramFiles%\NeoSpy\0001\
* %ProgramFiles%\NeoSpy\0002\
* %ProgramFiles%\NeoSpy\0003\
* %ProgramFiles%\NeoSpy\0004\
* %ProgramFiles%\NeoSpy\0005\
* %ProgramFiles%\NeoSpy\0006\
* %ProgramFiles%\NeoSpy\0007\
* %ProgramFiles%\NeoSpy\BDE\
* %ProgramFiles%\NeoSpy\DB\
* %ProgramFiles%\NeoSpy\Hlp\
* %ProgramFiles%\NeoSpy\isr\
* %ProgramFiles%\NeoSpy\isr\39455\
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0001\
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0001\log\
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0001\_restore\
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0002\
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0003\
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0004\
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0005\
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0006\
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0007\
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0008\
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0009\
* %ProgramFiles%\NeoSpy\TEMP\



The security risk then drops the following files:

* %UserProfile%\Desktop\NeoSpy.lnk
* %UserProfile%\Local Settings\Temp\INMEM000.REM
* %UserProfile%\Start Menu\Programs\NeoSpy\ Help.lnk
* %UserProfile%\Start Menu\Programs\NeoSpy\ NeoSpy.lnk
* %UserProfile%\Start Menu\Programs\NeoSpy\How to buy NeoSpy.url
* %UserProfile%\Start Menu\Programs\NeoSpy\ReadMe.lnk
* %UserProfile%\Start Menu\Programs\NeoSpy\Uninstall.lnk
* %ProgramFiles%\NeoSpy\0001\shell.dos
* %ProgramFiles%\NeoSpy\0001\_datamain.dat
* %ProgramFiles%\NeoSpy\0002\_datamain.dat
* %ProgramFiles%\NeoSpy\0003\_datamain.dat
* %ProgramFiles%\NeoSpy\0004\_datamain.dat
* %ProgramFiles%\NeoSpy\0005\_datamain.dat
* %ProgramFiles%\NeoSpy\0006\_datamain.dat
* %ProgramFiles%\NeoSpy\0007\_datamain.dat
* %ProgramFiles%\NeoSpy\12500852.ssp
* %ProgramFiles%\NeoSpy\adv.ini
* %ProgramFiles%\NeoSpy\BDE\bantam.dll
* %ProgramFiles%\NeoSpy\BDE\blw32.dll
* %ProgramFiles%\NeoSpy\BDE\ceeurope.btl
* %ProgramFiles%\NeoSpy\BDE\charset.cvb
* %ProgramFiles%\NeoSpy\BDE\europe.btl
* %ProgramFiles%\NeoSpy\BDE\IDAPI32.CFG
* %ProgramFiles%\NeoSpy\BDE\idapi32.dll
* %ProgramFiles%\NeoSpy\BDE\idapinst.dll
* %ProgramFiles%\NeoSpy\BDE\idasci32.dll
* %ProgramFiles%\NeoSpy\BDE\iddbas32.dll
* %ProgramFiles%\NeoSpy\BDE\iddr32.dll
* %ProgramFiles%\NeoSpy\BDE\idr20009.dll
* %ProgramFiles%\NeoSpy\BDE\other.btl
* %ProgramFiles%\NeoSpy\BDE\usa.btl
* %ProgramFiles%\NeoSpy\DB\Administrator.ndb
* %ProgramFiles%\NeoSpy\genof.bak
* %ProgramFiles%\NeoSpy\genof.dat
* %ProgramFiles%\NeoSpy\Help.chm
* %ProgramFiles%\NeoSpy\Hide.lnk
* %ProgramFiles%\NeoSpy\hl.dll
* %ProgramFiles%\NeoSpy\How to buy NeoSpy.url
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0001\log\shell1n39455.6117190972.ico
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0001\log\shell2n39455.6117190972.ico
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0001\log\shell3n39455.6117190972.ico
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0001\log\shell4n39455.6117190972.ico
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0001\log\shell5n39455.6117190972.ico
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0001\log\shell6n39455.6117190972.ico
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0001\_datadrive.dat
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0001\_restore\shell2n39455.6117190972.jpg
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0001\_restore\shell3n39455.6117190972.jpg
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0001\_restore\shell4n39455.6117190972.jpg
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0001\_restore\shell5n39455.6117190972.jpg
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0001\_restore\shell6n39455.6117190972.jpg
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0001\_restore\shell7n39455.6117190972.jpg
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0003\FILE39455.6117187384.JPG
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0003\_datadrive.dat
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0004\tmp.dat
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0004\_datadrive.dat
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0007\39455.6117409838
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\0007\_datadrive.dat
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\gilst.cat
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\pilst.cat
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\_datamain.dat
* %ProgramFiles%\NeoSpy\isr\39455\0.611715486111111\_under.dat
* %ProgramFiles%\NeoSpy\main.exe
* %ProgramFiles%\NeoSpy\options.bak
* %ProgramFiles%\NeoSpy\options.dat
* %ProgramFiles%\NeoSpy\ReadMe.txt
* %ProgramFiles%\NeoSpy\rlib.dll
* %ProgramFiles%\NeoSpy\Shr.dll
* %ProgramFiles%\NeoSpy\SPlayer.ini
* %ProgramFiles%\NeoSpy\stop.lnk
* %ProgramFiles%\NeoSpy\uninstall.dat
* %ProgramFiles%\NeoSpy\Uninstall.lnk
* %ProgramFiles%\NeoSpy\userlist.cat
* %SystemDrive%\temp001.dat



It may also create temporary files.

The security risk creates the following registry subkeys:

* HKEY_ALL_USERS\Software\MCSP
* HKEY_CLASSES_ROOT\.zsp
* HKEY_CLASSES_ROOT\CLSID\{38EA2037-19A5-4DA3-8944-9C1EB0DB164F}
* HKEY_CLASSES_ROOT\zspfile
* HKEY_LOCAL_MACHINE\SOFTWARE\Borland
* HKEY_LOCAL_MACHINE\SOFTWARE\MCSP
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\neospy.exe
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NeoSpy
* HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winpcap



The risk then records URLs of visited Web sites, keystrokes typed, applications started and data from the clipboard.

Affected

  • Windows 98
  • Windows 95
  • Windows XP
  • Windows Me
  • Windows Vista
  • Windows NT
  • Windows Server 2003
  • Windows 2000

Response

The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.

1. Disable System Restore (Windows Me/XP).
2. Update the virus definitions.
3. Run a full system scan.
4. Delete any values added to the registry.


  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube