1. Symantec/
  2. Security Response/
  3. Spyware.KeyLover

Spyware.KeyLover

Updated:
February 13, 2007 11:44:37 AM
Type:
Spyware
Version:
2.1
Publisher:
KernelTek Co.
Risk Impact:
High
File Names:
kl21setup.exe kl21.dll KeyLover21.exe kll.dll KeyLoverLite.exe kllsetup.exe
Systems Affected:
Windows

Depending on which version is installed, Adware.KeyLover performs the following actions:
    1. May create some of the following files:

      KeyLover Version 2.1

      • %UserProfile%\My Documents\[log_file_name].klg
      • %ProgramFiles%\KernelTek\KeyLover21\debug.txt
      • %ProgramFiles%\KernelTek\KeyLover21\Dll\kl21.dll
      • %ProgramFiles%\KernelTek\KeyLover21\ftptest.txt
      • %ProgramFiles%\KernelTek\KeyLover21\Help\KL2Help.chm
      • %ProgramFiles%\KernelTek\KeyLover21\install.log
      • %ProgramFiles%\KernelTek\KeyLover21\KeyLover21.exe
      • %ProgramFiles%\KernelTek\KeyLover21\kl.lic
      • %ProgramFiles%\KernelTek\KeyLover21\kl2.cfg
      • %ProgramFiles%\KernelTek\KeyLover21\KuninsT.exe
      • %ProgramFiles%\KernelTek\KeyLover21\License.txt
      • %ProgramFiles%\KernelTek\KeyLover21\mailtest.txt
      • %ProgramFiles%\KernelTek\KeyLover21\Readme.txt
      • %ProgramFiles%\KernelTek\KeyLover21\user.lic

        KeyLoverLite

      • %UserProfile%\foo\My Documents\[log_file_name].klg
      • %ProgramFiles%\KernelTek\KeyLoverLite\debug.txt
      • %ProgramFiles%\KernelTek\KeyLoverLite\Dll\kll.dll
      • %ProgramFiles%\KernelTek\KeyLoverLite\install.log
      • %ProgramFiles%\KernelTek\KeyLoverLite\KeyLoverLite.exe
      • %ProgramFiles%\KernelTek\KeyLoverLite\kl.lic
      • %ProgramFiles%\KernelTek\KeyLoverLite\kll.cfg
      • %ProgramFiles%\KernelTek\KeyLoverLite\KuninsT.exe
      • %ProgramFiles%\KernelTek\KeyLoverLite\License.txt
      • %ProgramFiles%\KernelTek\KeyLoverLite\mailtest.txt
      • %ProgramFiles%\KernelTek\KeyLoverLite\Readme.txt
      • %ProgramFiles%\KernelTek\KeyLoverLite\user.lic

        Notes:
      • %UserProfile% is a variable that refers to the current user's profile folder. By default, this is C:\Documents and Settings\[CURRENT USER] (Windows NT/2000/XP).
      • %ProgramFiles% is a variable that refers to the program files folder. By default, this is C:\Program Files.

    2. May create some of the following registry keys:

      HKEY_LOCAL_MACHINE\SOFTWARE\KernelTek\KeyLover
      HKEY_LOCAL_MACHINE\SOFTWARE\KernelTek\KeyLoverLite
      HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.klg


    3. Logs keystrokes.

    4. May email the gathered information to a predetermined email address.


    Summary| Technical Details| Removal

    Search Threats

    Search by name
    Example: W32.Beagle.AG@mm
    STAR Antimalware Protection Technologies
    2016 Internet Security Threat Report, Volume 21
    • Twitter
    • Facebook
    • LinkedIn
    • Google+
    • YouTube