Home / malwarePDF  

Trojan-Spy:W32/KeyLogger.RM


First posted on 02 November 2007.
Source: SecurityHome

Aliases :

Trojan-Spy:W32/KeyLogger.RM is also known as Trojan-Spy.Win32.KeyLogger.rl, Trojan-Spy.Win32.KeyLogger.rm, Trojan-Spy.Win32.KeyLogger.rk.

Explanation :

This is a key-logging trojan that logs all the keystrokes of the user and sends them to a particular website.

This malware may arrive as an attachment labeled as a Microsoft Word RTF file.

Upon Execution, this malware displays the following fake error message:



It then drops the following files on Windows System folder:


Note: %systemdir% by default is C:Windowssystem32

It also creates the following registry key as part of its auto-start mechanism:


Initially, it will try to contact this URL to set the infected machine's status


Then this malware sends the user's keystrokes including its ip address to this URL:

Last update 02 November 2007

 

TOP

Malware :

Family: