|
| How to remove Spyware.UltimateKeylog |
|
| Author:Spyware.UltimateKeylog Hits: UpdateTime:2008-8-1 12:14:48 |
|
|
For remove Spyware.UltimateKeylog virus,please clean/delete all Spyware.UltimateKeylog infected files and Delete/Modify any values Spyware.UltimateKeylog added to the registry as following:
This spyware program can be downloaded from www.ultimatekeylogger.com.
When the program is executed, it creates the following files:
- %UserProfile%\Local Settings\Temp\[RANDOM NAME].tmp
- C:\Documents and Settings\All Users\Application Data\ukl\encryptedlogs\Administrator\DecryptedReport\DecryptedReport.html
- C:\Documents and Settings\All Users\Application Data\ukl\encryptedlogs\Administrator\DecryptedReport\Screenshots\Screenshot_[USER NAME]_at_[COMPUTER NAME]_[DATE].jpg
- C:\Documents and Settings\All Users\Application Data\ukl\encryptedlogs\Administrator\encryptedscrns\Screenshot_[USER NAME]_at_[COMPUTER NAME]_[DATE]
- C:\Documents and Settings\All Users\Application Data\ukl\encryptedlogs\Administrator\encryptedscrns\Screenshot_[USER NAME]_at_[COMPUTER NAME]_[DATE]
- C:\Documents and Settings\All Users\Application Data\ukl\encryptedlogs\Administrator\log.ukl
- C:\Documents and Settings\All Users\Application Data\ukl\ukl.cfg
- C:\Documents and Settings\All Users\Application Data\uklpr\appface.dll
- C:\Documents and Settings\All Users\Application Data\uklpr\KLKlMon.dll
- C:\Documents and Settings\All Users\Application Data\uklpr\KLPP.dll
- C:\Documents and Settings\All Users\Application Data\uklpr\KRyLack_Software_Website.url
- C:\Documents and Settings\All Users\Application Data\uklpr\LICENSE.txt
- C:\Documents and Settings\All Users\Application Data\uklpr\ui.urf
- C:\Documents and Settings\All Users\Application Data\uklpr\Ultimate_Keylogger_Website.url
- C:\Documents and Settings\All Users\Application Data\uklpr\unukl.exe
- C:\Documents and Settings\All Users\Application Data\uklpr\wmpusrvc.chm
- C:\Documents and Settings\All Users\Application Data\uklpr\wmpusrvc.exe
- C:\Documents and Settings\All Users\Desktop\Ultimate Keylogger.lnk
- C:\Documents and Settings\All Users\Start Menu\Programs\Ultimate Keylogger\Ultimate Keylogger.lnk
Next, the program modifies the following registry entry so that it executes whenever Windows starts: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\"ukl" = "C:\documents and Settings\All Users\Application Data\uklpr\wmpusrvc.exe"
It then creates the following registry subkeys:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E4F2CA1F-7ED0-25CB-5EEF-F26D9921AC33}
- HKEY_CURRENT_USER\Software\ukl
- HKEY_CLASSES_ROOT\CLSID\{E4F2CA1F-7ED0-25CB-5EEF-F26D9921AC33}
This spyware program can perform the following functions:
- Record keystrokes
- Take screen-shots after a prescribed amount of time
- Monitor Web activity
- Send logs and reports to a destination specified by the user
For successful remove Spyware.UltimateKeylog virus,you may also need do as following:
1. Temporarily Disable System Restore .
2. Update the virus definitions. Reboot computer in SafeMode;
3. Delete the IE temp files,some Spyware.UltimateKeylog temp file exisit there.
4.If you failed to remove Spyware.UltimateKeylog,please go to our remove help forum:http://help.antiviruses123.com
|
| End Of The Article How to remove Spyware.UltimateKeylog remove process |
|
Suspicious.MLApp Suspicious.IRCBot W32.Spyrat Kollah YW removal ins… Keygen for Acronis Pro… SpywareRemover2009 re… AV Antispyware remova… Suspicious.S.MH2 Suspicious.Graybird W32.Woospi!inf Suspicious.Tidserv Suspicious.Vundo.2 Suspicious.Skintrim Suspicious.Lop Brospy IF removal ins… Suspicious.Swizzor Suspicious.Farfli.2 AntiSpyware Pro 2009 … Kaspersky Key Finder … Suspicious.Harakit Suspicious.Vundo W32.Spamuzle.E!inf AntispywareProtector Suspicious.MH690.A ASC AntiSpyware remov… Internet Speed Monitor… Panopticum LensPro III… Spyware Protect 2009 … Spyware.KeyProwler Spyware.MLog360 SpywareProtect2009 Xsoftspy Keygen Spyware.NetScreenWatch Suspicious.MH690 Antispy knight Agent ajpy removal in… SillyDl FYW removal i… AntiSpywareGuard Suspicious.Farfli Spyware.CompuSpy
|