Home Malware Programs Keyloggers Edepol

Edepol

Posted: March 28, 2006

Edepol is a parasitic keylogger that records all user keystrokes and transfers gathered data to a predefined remote host. The threat injects malicious code into running legitimate processes in order to hide its activity and presence in the computer. Edepol automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 hipprrver.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareWset
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}9F81D88C-C298-9935-C5D1-40AA4DB91155
Loading...