Remove Espionage. Description and removal instructions

 
Title: Espionage

Type: Remote Administration Tools
Severity scale:Espionage severity is 70  (70 / 100)
 
Espionage is a very dangerous RAT virus, designed for remote
controlling of the infected PC and spying on user activity. The program
includes such dangerous functions as "Anti Virus killer" and "Firewall
killer". It can disable almost any AV and Firewall protection. This
virus can be used as HTTP server. It means that the intruder can use
his web browser to view and steal all the information, stored in
victim's computer. This RAT also has a "surveillance" function. It uses
victim's webcam and microphone to spy on user. It also logs keystrokes
and makes screenshots from the infected PC. The author of this pest is
a hacker called erebus. The program was created in Visual Basic and
compressed with ASPack. Several versions originated (Espionage 1.0
Espionage 1.1) during the period from January 2002 to February 2005.

From the publisher:

"Espionage is a trojan http server. it was created on an xp box with
visual basic. (it will run on all versions of windows) trojan runs on
port81 and is controlled through browser. To access the server after
infection simply bring up http://server's ip:81 in your browser.
what is so different about espionage? Espionage has the ability to
close antivirus's on windows 95/98/NT/2k/XP, including mcaffee and
norton. also, on NT/2k/XP, the system task manager is disabled.
Registry editor and msconfig are also disabled along with many other
anti virus and firewall applications. What else can espionage besides
serve files via browser/http? Espionage has the ability to view screen,
view pc camera, view pc info, erebus"


Espionage properties:
• Allows remote user connection
• Takes and sends out screenshots of user activity
• Sends out logs by FTP or email
• Logs keystrokes
• Hides from the user
• Stays resident in background

Automatic Espionage removal:

remover for Espionage

Espionage manual removal:

Kill processes:
[system root]\\system\\cap.exe
Delete registry values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\win svc host
Delete files:
[system root]\\system\\cap.exe

Other programs to remove Espionage:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 23/03/05
Information updated: 23/03/05

Additional resources related to Espionage:

Attention: If you know or you have a website or page about Espionage removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Espionage parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Related news:
Similar parasites: