| System Spy removal| Spyware System Spy Information |
|---|
Name: System Spy Category: Keylogger Date: 2001-09-28 Author: Stephen M. Younts Coded in: Visual Basic 5.0 Dangerous: Yes | System Spy belongs to Keylogger spyware category. It's presense means that your computer is infected with malicious software and is insecure.
System Spy description by Stephen M. Younts: Vendor: ´System Spy will ´hide´ on a user´s computer & ´record´ the actions of another person via application title capturing. * Captures active window title, time window was opened, time window was closed, & total time window was active. * Invisible to person while running, including Task List (Ctrl+Alt+Delete). * Option to ´Hide´ & ´Record´ at system start-up. * Captured information is stored encrypted, in dated any file (ex. ´01.20.99.DAT´) & made to be deleted via System Spy interface. * System Spy interface can only be displayed when a specified text file is opened. Specified text file made to be stored off of computer.´ >> Delete System Spy automatically - Download Spyware Doctor
| System Spy Removal Instructions |
|---|
Kill the following processes setup.exe, ss.exe | Unregister the following DLLs and reboot setuplng.dll in Program Files\ss\setup\
| Delete these registry entries HKEY_CLASSES_ROOT\clsid\{104e51da-c011-11d1-9c65-70a605c10e27} HKEY_CLASSES_ROOT\clsid\{104e51db-c011-11d1-9c65-70a605c10e27} HKEY_CLASSES_ROOT\clsid\{104e51dc-c011-11d1-9c65-70a605c10e27} HKEY_CLASSES_ROOT\clsid\{104e51dd-c011-11d1-9c65-70a605c10e27} HKEY_CLASSES_ROOT\clsid\{45070aee-e66c-11d1-b0ac-444553540000} HKEY_CLASSES_ROOT\clsid\{4b447062-9f42-11d2-90f1-444553540000} HKEY_CLASSES_ROOT\clsid\{4b447063-9f42-11d2-90f1-444553540000} HKEY_CLASSES_ROOT\clsid\{4b447067-9f42-11d2-90f1-444553540000} HKEY_CLASSES_ROOT\clsid\{fbb3c000-6d14-11d2-9e37-813a750b363d} HKEY_CLASSES_ROOT\clsid\{fbb3c001-6d14-11d2-9e37-813a750b363d} HKEY_CLASSES_ROOT\clsid\{fbb3c003-6d14-11d2-9e37-813a750b363d} HKEY_CLASSES_ROOT\clsid\{fbb3c006-6d14-11d2-9e37-813a750b363d} HKEY_CLASSES_ROOT\clsid\{fbb3c007-6d14-11d2-9e37-813a750b363d} HKEY_CLASSES_ROOT\clsid\{fbb3c009-6d14-11d2-9e37-813a750b363d} HKEY_LOCAL_MACHINE\software\classes\clsid\{104e51db-c011-11d1-9c65-70a605c10e27} HKEY_LOCAL_MACHINE\software\classes\clsid\{4b447063-9f42-11d2-90f1-444553540000} HKEY_LOCAL_MACHINE\software\classes\clsid\{fbb3c001-6d14-11d2-9e37-813a750b363d} HKEY_LOCAL_MACHINE\software\classes\clsid\{fbb3c007-6d14-11d2-9e37-813a750b363d} HKEY_LOCAL_MACHINE\software\classes\cryptxctl.cryptx\clsid HKEY_LOCAL_MACHINE\software\classes\interface\{104e51da-c011-11d1-9c65-70a605c10e27} HKEY_LOCAL_MACHINE\software\classes\interface\{104e51dc-c011-11d1-9c65-70a605c10e27} HKEY_LOCAL_MACHINE\software\classes\interface\{4b447062-9f42-11d2-90f1-444553540000} HKEY_LOCAL_MACHINE\software\classes\interface\{4b447067-9f42-11d2-90f1-444553540000} HKEY_LOCAL_MACHINE\software\classes\interface\{fbb3c000-6d14-11d2-9e37-813a750b363d} HKEY_LOCAL_MACHINE\software\classes\interface\{fbb3c003-6d14-11d2-9e37-813a750b363d} HKEY_LOCAL_MACHINE\software\classes\interface\{fbb3c006-6d14-11d2-9e37-813a750b363d} HKEY_LOCAL_MACHINE\software\classes\typelib\{104e51dd-c011-11d1-9c65-70a605c10e27} HKEY_LOCAL_MACHINE\software\classes\typelib\{45070aee-e66c-11d1-b0ac-444553540000} HKEY_LOCAL_MACHINE\software\classes\typelib\{fbb3c009-6d14-11d2-9e37-813a750b363d} HKEY_LOCAL_MACHINE\software\classes\vblibrary.vblib\clsid HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\system spy v1.00\uninstallstring HKEY_LOCAL_MACHINE\software\tbproducts\system spy\v1.00\name HKEY_LOCAL_MACHINE\software\tg byte software\setup\currentversion\uninstall specialist\system spy@vv1.00 (tbproducts)
| Remove the following files register.txt, setup.pkg. ss.exe, ss.ini in Program Files\ss\ setup.exe, setup.inf, setuplng.dll in Program Files\ss\setup\ vblib.ocx in Windows\system32\
| Remove the following directories Program Files\ss
|
Bookmark System Spy page
|