1. Symantec-Broadcom-Horizontal/
  2. Security Response/
  3. Attack Signatures/
  4. HTTP Spyware Ultimatekeylog Activity

HTTP Spyware Ultimatekeylog Activity

Severity: High

This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.

Description

This signature detects activities of Spyware.UltimateKeylog communicating and requesting information.

Additional Information

Spyware.UltimateKeylog is a spyware program that records keystrokes and takes screenshots of the computer.

This spyware program can be downloaded from www.ultimatekeylogger.com.

When the program is executed, it creates the following files:

* %UserProfile%\Local Settings\Temp\[RANDOM NAME].tmp
* C:\Documents and Settings\All Users\Application Data\ukl\encryptedlogs\Administrator\DecryptedReport\DecryptedReport.html
* C:\Documents and Settings\All Users\Application Data\ukl\encryptedlogs\Administrator\DecryptedReport\Screenshots\Screenshot_[USER NAME]_at_[COMPUTER NAME]_[DATE].jpg
* C:\Documents and Settings\All Users\Application Data\ukl\encryptedlogs\Administrator\encryptedscrns\Screenshot_[USER NAME]_at_[COMPUTER NAME]_[DATE]
* C:\Documents and Settings\All Users\Application Data\ukl\encryptedlogs\Administrator\encryptedscrns\Screenshot_[USER NAME]_at_[COMPUTER NAME]_[DATE]
* C:\Documents and Settings\All Users\Application Data\ukl\encryptedlogs\Administrator\log.ukl
* C:\Documents and Settings\All Users\Application Data\ukl\ukl.cfg
* C:\Documents and Settings\All Users\Application Data\uklpr\appface.dll
* C:\Documents and Settings\All Users\Application Data\uklpr\KLKlMon.dll
* C:\Documents and Settings\All Users\Application Data\uklpr\KLPP.dll
* C:\Documents and Settings\All Users\Application Data\uklpr\KRyLack_Software_Website.url
* C:\Documents and Settings\All Users\Application Data\uklpr\LICENSE.txt
* C:\Documents and Settings\All Users\Application Data\uklpr\ui.urf
* C:\Documents and Settings\All Users\Application Data\uklpr\Ultimate_Keylogger_Website.url
* C:\Documents and Settings\All Users\Application Data\uklpr\unukl.exe
* C:\Documents and Settings\All Users\Application Data\uklpr\wmpusrvc.chm
* C:\Documents and Settings\All Users\Application Data\uklpr\wmpusrvc.exe
* C:\Documents and Settings\All Users\Desktop\Ultimate Keylogger.lnk
* C:\Documents and Settings\All Users\Start Menu\Programs\Ultimate Keylogger\Ultimate Keylogger.lnk



Next, the program modifies the following registry entry so that it executes whenever Windows starts:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\"ukl" = "C:\documents and Settings\All Users\Application Data\uklpr\wmpusrvc.exe"

It then creates the following registry subkeys:

* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E4F2CA1F-7ED0-25CB-5EEF-F26D9921AC33}
* HKEY_CURRENT_USER\Software\ukl
* HKEY_CLASSES_ROOT\CLSID\{E4F2CA1F-7ED0-25CB-5EEF-F26D9921AC33}



This spyware program can perform the following functions:

* Record keystrokes
* Take screen-shots after a prescribed amount of time
* Monitor Web activity
* Send logs and reports to a destination specified by the user

Affected

  • Windows 98
  • Windows 95
  • Windows XP
  • Windows Me
  • Windows Vista
  • Windows NT
  • Windows Server 2003
  • Windows 2000

Response

The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.

1. Disable System Restore (Windows Me/XP).
2. Update the virus definitions.
3. Run a full system scan.
4. Delete any values added to the registry.
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube