Spyware.STAR is distributed in WinZip file format, with the name star.zip, containing the following files
When setup.exe is executed, it does the following:
- Creates the following files:
- wsys.exe: This is the main spyware file. Detected as Spyware.STAR.
- wsys.dll: Detected as Spyware.STAR.
- LoggerConfigurator.exe: Detected as Spyware.STAR.
- RemoteUnInstaller.exe: Detected as Spyware.STAR.
- ReportManager.exe: Detected as Spyware.STAR.
- Allows the person installing it to configure the installation Path, and the Log Files Path.
- The default <installation path> is "%ProgramFiles%\STAR\"
- The default <log files path> is "%ProgramFiles%\STAR\"
Notes: %ProgramFiles% is a variable that refers to the path to the program files folder. By default, this is "C:\Program Files\."
- Adds the value:
"wsys" = "<installation path>\wsys.exe"
to the following registry key:
so that the spyware runs when you start Windows.