KSLogger
KSLogger will capture all keystrokes and mouse clicks and immediately write them to a log file. Unlike some other keyloggers, Keyboard Guardian can operate in a stealth mode, being invisible to most users. And it has an automatic emailing feature
that can securely send all log files to the specified address. It also reveals hidden passwords, URLs, usernames, etc.0
General information:
Malware Name: |
KSLogger |
Malware Type: |
Key Logger |
Company Name: |
Kelly Software |
Company URL: |
http://www.kellysoftware.com/
|
Threat Level: |
Elevated Risk |
Operating System: |
WIN XP |
Installation Type: |
Installed through EXE |
Operation: |
Time of After Installation |
Company Description:
Kelly Software provides various software. One of its software is KSLogger. KSLogger monitors all keystrokes made on the computer and sends them to a log (text) file. We define the location and name of the log file. The application is hidden from the
tray, so we don't know its running. The process is named sys007s, so it looks like a system program when it's running in the background/hidden. We also have the option to capture the captions of all visible windows, so it's easy to monitor
what programs are running. To run automatically, run it with a parameters.
Spyware Description:
KSLogger will capture all keystrokes and mouse clicks and immediately write them to a log file. Unlike some other keyloggers, Keyboard Guardian can operate in a stealth mode, being invisible to most users. And it has an automatic emailing feature
that can securely send all log files to the specified address. It also reveals hidden passwords, URLs, usernames, etc.0
Characteristics/Symptoms:
-> Monitor and capture data from computers -> Run in stealth mode -> Intercepts keystrokes from the keyboard and records them in a log -> Starts with the operating system0
Additional information might be found here:
Processes Running:
File information Created after Installation:
File Location |
Size (Bytes) |
Type |
Folder information Created after Installation:
Registry information Created after Installation:
Main Registry Key |
Sub Registry Key |
Key Value Name |
HKEY_CURRENT_USER |
SoftwareSys007sSetting |
winfile |
HKEY_CURRENT_USER |
SoftwareSys007sSettings |
getwins |