Threat Database Spyware Spyware.PowerSpy

Spyware.PowerSpy

By Sumo3000 in Spyware

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 244
First Seen: July 24, 2009
Last Seen: February 8, 2021
OS(es) Affected: Windows

Spyware.PowerSpy is a privacy threat that can secretly infiltrate a system and monitor a user's activities. Spyware.PowerSpy is related to Power Spy which is a monitoring software from eMatrixSoft, Inc. In the wrong hands, Spyware.PowerSpy can be maliciously used to steal a victim's private information by monitoring applications used, websites visited, electronic messages sent or received and capturing keystrokes. Spyware.PowerSpy is also able to take screen shots of a system. Spyware.PowerSpy will store the stolen information in log files and then send the files to a predefined e-mail address. It's advisable to remove Spyware.PowerSpy from your PC if it was not intentionally installed.

Aliases

7 security vendors flagged this file as malicious.

Anti-Virus Software Detection
Sophos Mal/VB-G
McAfee-GW-Edition Heuristic.LooksLike.Riskware.PowerSpy.P
Ikarus not-a-virus:Monitor.Win32.PowerSpy
BitDefender Gen:Trojan.Heur.bm0@XmGa3Tki
a-squared Riskware.Monitor.Win32.PowerSpy!IK
Prevx1 Malware.Gen
Kaspersky not-a-virus:Monitor.Win32.PowerSpy.401

SpyHunter Detects & Remove Spyware.PowerSpy

File System Details

Spyware.PowerSpy may create the following file(s):
# File Name MD5 Detections
1. f0904192_system.exe a9c1c3c9c5e621d7b573aa5d17aec2ef 132
2. system.exe c8e9f6e7e5547e9a09349b2554996f46 84
3. system.exe 68188de4788b856c18a4f274d3fad490 7
4. system.exe df31de3b6e3781bb8bfbfb279ab69f3e 6
5. system.exe 6f5cd9d6fdb89738a5ac334b13f2c233 5
6. system.exe f88d504de94d375671ee854f5819fe33 1
7. system.exe 315493fd9183aaea78ce21966bd8f6e5 1
8. pykeylogger-0.8.2a_dist.exe 25405886c76f8c869620eef93f39e966 1
9. %ProgramFiles%\SKPCS\data\eventsys.exe
10. %ProgramFiles%\SKPCS\COMCTL32.OCX
11. %ProgramFiles%\SKPCS\data\ps_demo_report.html
12. %ProgramFiles%\SKPCS\data\psini.ini
13. %ProgramFiles%\SKPCS\data\emxfile.emx
14. adsnwm.exe cd8876f46fe06e625b437539cd9f75b9 0

Registry Details

Spyware.PowerSpy may create the following registry entry or registry entries:
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{86CF1D34-0C5F-11D2-A9FC-0000F8754DA1}\2.0]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6B7E6392-850A-101B-AFC0-4210102A8DA7}\1.3\0\win32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{86CF1D34-0C5F-11D2-A9FC-0000F8754DA1}\2.0\HELPDIR]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{48E59290-9880-11CF-9754-00AA00C00908}\1.0\HELPDIR]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{86CF1D34-0C5F-11D2-A9FC-0000F8754DA1}\2.0\0\win32]

Trending

Most Viewed

Loading...