Threat Explorer

The Threat Explorer is a comprehensive resource consumers can turn to for daily, accurate, up-to-date information on the latest threats, risks and vulnerabilities.



13 February 2007
Spytech Software
Risk Impact:
File Names:
Setup.exe,Shadow.exe,and ShadowModule.exe
Systems Affected:


Spyware.Spytech.B is spyware that monitors user activity and takes periodic screenshots.


The files are detected as Spyware.Spytech.B.


Spyware.Spytech.B must be manually installed.

Antivirus Protection Dates

  • Initial Rapid Release version 02 October 2014 revision 022
  • Latest Rapid Release version 02 October 2014 revision 022
  • Initial Daily Certified version 02 July 2004
  • Latest Daily Certified version 28 September 2010 revision 036
  • Initial Weekly Certified release date 07 July 2004
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Spyware.Spytech.B can:
    • Take periodic screenshots to monitor user activity.
    • Monitor Web activity by looking at the Web browser cache.

When Spyware.Spytech.B is installed it does the following:
  1. Displays the license agreement.

  2. Allows the person installing it to select the installation folder. The default installation folder is %ProgramFiles%\Spytech Software\Spytech Shadow.

    %ProgramFiles% is a variable that refers to the path to the program files folder. By default, this is C:\Program Files.

  3. Allows the individual who is installing it to select one of two installation types:
    • Normal: Installs program files, documentation files, and program shortcuts.
    • Stealth: Installs only program files.

  4. Gives the option to install an uninstaller.

  5. Creates the following files and folders:
    • %ProgramFiles%\Spytech Software\Spytech Shadow\Shadow.exe: A log viewer and configurations manager, detected as Spyware.Spytech.B.
    • %ProgramFiles%\Spytech Software\Spytech Shadow\ShadowModule.exe: The logging module, detected as Spyware.Spytech.B.
    • %System%\libimg.dll: Win32 image I/O and manipulation library with GDI extensions.
    • %ProgramFiles%\Spytech Software\Spytech Shadow\license.txt: License information.
    • %ProgramFiles%\Spytech Software\Spytech Shadow\Order Spytech Software Online!!.url. A link to an ordering Web site.
    • %ProgramFiles%\Spytech Software\Spytech Shadow\help.cnt: A Help file.
    • %ProgramFiles%\Spytech Software\Spytech Shadow\help.GID: A Help file.
    • %ProgramFiles%\Spytech Software\Spytech Shadow\HELP.HLP: A Help file.
    • %ProgramFiles%\Spytech Software\Spytech Shadow\readme!.txt: Documentation.
    • %Windir%\unvise32.exe: A generic uninstaller.
    • %ProgramFiles%\Spytech Software\Spytech Shadow\uninstall.log: A log that an uninstaller uses.
    • %Windir%\shadopts.dat: Configurations.
    • %Windir%\SHAgentSS\: Screenshot directory.
    • C:\Documents and Settings\All Users\Start Menu\Programs\Spytech Shadow\SpyTech Shadow.lnk: Start menu link.
    • C:\Documents and Settings\All Users\Start Menu\Programs\Spytech Shadow\User License.lnk: Start menu link.
    • C:\Documents and Settings\All Users\Start Menu\Programs\Spytech Shadow\Order Spytech Software Online!!.lnk: Start menu link.
    • C:\Documents and Settings\All Users\Start Menu\Programs\Spytech Shadow\Shadow Help.lnk: Start menu link.
    • C:\Documents and Settings\All Users\Start Menu\Programs\Spytech Shadow\Shadow Readme.lnk: Start menu link.
    • C:\Documents and Settings\All Users\Start Menu\Programs\Spytech Shadow\Remove Spytech Shadow.lnk: Start menu link.

      • %System% is a variable. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
      • %Windir% is a variable. By default, this is C:\Windows or C:\Winnt.
      • Depending on the options selected during installation, certain files may not be present.

  6. Adds the subkey:

    Spytech Shadow

    to the registry key:


    and then adds these values to that subkey:

    "DisplayName" = "Spytech Shadow"
    "UninstallString" = "%Windir%\unvise32.exe %ProgramFiles%\Spytech Software\Spytech Shadow\uninstal.log"

  7. Adds the value:

    "%Windir%\unvise32.exe" = "0x1"

    to the registry key:


The following instructions pertain to all Symantec antivirus products that support Security Risk detection.

Before you begin
This is a general removal procedure. This application may include an uninstallation tool named "unins000.exe" located in the installation folder. We suggest that, before you attempt to remove this spyware using the following instructions, try to uninstall it using the provided uninstaller.
  1. Update the definitions.
  2. Restart the computer in Safe mode.
  3. Run a full system scan and delete all the files detected as Spyware.Spytech.B.
  4. Delete the values that were added to the registry.
For specific details on each of these steps, read the following instructions.

1. To update the definitions
To obtain the most recent definitions, start your Symantec program and run LiveUpdate.

2. To restart the computer in Safe mode
Shut down the computer and turn off the power. Wait for at least 30 seconds, and then restart the computer in Safe mode or VGA mode. For instructions, read the document, "How to start the computer in Safe Mode ."

3. To scan for and delete the files
  1. Start Norton AntiVirus and make sure that it is configured to scan all the files. For more information, read the document, "How to configure Norton AntiVirus to scan all files."
  2. Run a full system scan.
  3. If any files are detected as Spyware.Spytech.B, click Delete.

    If your Symantec antivirus product reports that it cannot delete a detected file, write down the path and file names. Then use Windows Explorer to locate and delete the file.
4. To delete the value from the registry

Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry ," for instructions.

Note: This is done to make sure that all the keys are removed. They may not be there if the uninstaller removed them.
  1. Click Start > Run.
  2. Type regedit

    Then click OK.

  3. Navigate to the key:


  4. In the left plane, delete the subkey:

    Spytech Shadow

  5. Navigate to the key:


  6. In the left plane, delete the value:

    "%Windir%\unvise32.exe" = "0x1"

  7. Exit the Registry Editor.