Virus Encyclopedia

Welcome to the Virus Encyclopedia of Panda Security.

KeyLogger.FT

 
Threat LevelLow threat
DamageHigh
DistributionNot widespread

At a glance

Common name:KeyLogger.FT
Technical name:Constructor/KeyLogger.FT
Threat level:Medium
Alias:Trojan-Spy.Win32.KeyLogger.e,
Type:Security Risk
Subtype: Virus Constructor
Effects:  

It is a malicious tool which allows to create Trojans designed to log the keystrokes typed by the user. Then, the information it obtains is sent via email to the indicated email address.

Affected platforms:

Windows 2003/XP/2000/NT/ME/98/95

First detected on:Sept. 22, 2009
Detection updated on:Sept. 23, 2009
StatisticsNo

Brief Description 

    

KeyLogger.FT is a virus constructor type malware. To be more precise, KeyLogger.FT allows to create keylogger type Trojans, that is, designed to log the keystrokes typed by the user.

This application allows to configure the following options, among others:

  • Email address to which the obtained information is sent.
  • SMTP server to send the data.
  • Activation and lifetime of the Trojan.
  • Disable the Task manager.
  • Possibility to add the Trojan to other executable.

KeyLogger.FT does not spread automatically using its own means. It needs an attacking user's intervention in order to reach the affected computer.

Visible Symptoms 

    

KeyLogger.FT is easy to recognize, as it displays the following symptoms:

  • The program to create Trojans has the following icon:

  • When the file is run, the following message is displayed:

  • Then, the program is opened, which has the following interface:

>

Tech details

KeyLogger.FT

 
Threat LevelLow threat
DamageHigh
DistributionNot widespread

Effects

KeyLogger.FT is a program that allows to create keylogger type Trojans, which are designed to log the keystrokes typed by the user. This way, it could obtain any type of information, like passwords or any other confidential information.

KeyLogger.FT has the following characteristics:

  • The program to create Trojans has the following icon:

  • When the file is run, the following message is displayed:

  • Then, the program is opened, which has the following interface:

  • It has the following configuration options:
    - Email address to which send the information obtained.
    - Name of the file to be created.
    - SMTP server to send the data.
    - Activation of the Trojan: direct or after 4 reboots.
    - Lifetime of the Trojan: always in execution or uninstallation after a certain date.
    - Type of connection: via modem or LAN.
  • Additionally, it has these other options:
    - New'n Updates: Access to news and updates of the program.
    - Special: Extra options, such as disable the Task manager.
    - Create Spion: this option allows to generate the malicious file, which will hace the name that has been selected and the following icon, which is the old symbol of the Windows operating systems:

    - ExeJoiner: option that allows to add the Trojan to other executable, which could be legitimate (in order to pass itself off as an inoffensive file) or even a malicious file (in order to be run with other malware simultaneously).

    - About: Information about the author and the tool.

 

Regarding the Trojan that is generated, it creates in the infected computer the following files and Windows Registry entries:

  • In the Windows system directory it creates:
    - a copy of itself with the name that has been previously selected
    - EXKTKSP.DLL and EXKTKSP32.DLL. In these files the information it gathers is stored.
  • HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows\ CurrentVersion\ Run
    %name of the Trojan% = %sysdir%\%name of the Trojan%
    where %sysdir% is the Windows system directory.

Means of transmission 

KeyLogger.FT does not spread automatically using its own means. It needs an attacking user's intervention in order to reach the affected computer. The means of transmission used include, among others, floppy disks, CD-ROMs, email messages with attached files, Internet downloads, FTP, IRC channels, peer-to-peer (P2P) file sharing networks, etc.

Further Details  

KeyLogger.FT is written in the programming language Visual Basic v5. This program is 920,576 bytes in size.

Solution

See solution