BehaviorSpyware.KeyboardLogger logs keystrokes and records the windows in which they were entered.
SymptomsFiles are detected as Spyware.KeyboardLogger
TransmissionSpyware.KeyboardLogger must be manually installed.
technical detailsFile names: keyspy.exe
When Spyware.KeyboardLogger is installed it does the following:
1. Creates the following files:
* %SystemDrive%\Documents and Settings\All Users\Application Data\KLog\ins.dat
* %UserProfile%\Start Menu\Programs\Keyboard Logger Pro\Help.lnk
* %UserProfile%\Start Menu\Programs\Keyboard Logger Pro\Keyboard Logger.lnk
* %UserProfile%\Start Menu\Programs\Keyboard Logger Pro\Order on-line.lnk
* %UserProfile%\Start Menu\Programs\Keyboard Logger Pro\Uninstall.lnk
* %ProgramFiles%\Keyboard Logger\KeySpy.exe (Spyware.Keyboardlogger)
* %ProgramFiles%\Keyboard Logger\kh.dll
* %ProgramFiles%\Keyboard Logger\kl.chm
* %ProgramFiles%\Keyboard Logger\license.txt
* %ProgramFiles%\Keyboard Logger\Order.url
* %ProgramFiles%\Keyboard Logger\Readme.txt
* %ProgramFiles%\Keyboard Logger\Uninstall.exe
Note:
* %UserProfile% is a variable that refers to the current user's profile folder. By default, this is C:\Documents and Settings\[Current User] (Windows NT/2000/XP).
* %ProgramFiles% is a variable that refers to the program files folder. By default, this is C:\Program Files.
* %SystemDrive% is a variable that refers to the drive on which Windows is installed. By default, this is drive C.
2. Adds the following value:
"pskl" = "%ProgramFiles%\Keyboard Logger Pro\keyspy.exe"
to the registry subkey:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
so that the risk runs every time Windows starts.
3. Creates the following registry subkeys:
HKEY_CURRENT_USER\Software\Keyboard Logger Pro
HKEY_CLASSES_ROOT\{RandomCLSID}
REMOVAL INSTRUCTIONSSee:
http://securityresponse.symantec.com/avcenter/venc/data/spyware.keyboardlogger.htmlTo delete the values from the registry 1. Click Start > Run.
2. Type regedit
Then click OK.
Note: If the registry editor fails to open the risk may have modified the registry to prevent access to the registry editor. Security Response has developed a tool to resolve this problem. Download and run this tool, and then continue with the removal.
3. Navigate to and delete the following subkey:
HKEY_CURRENT_USER\Software\Keyboard Logger Pro
4. Navigate to the subkey:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
5. In the right pane, delete the value:
"pskl" = "%ProgramFiles%\Keyboard Logger Pro\Keyspy.exe"
6. Exit the Registry Editor.