Troj/SCKeyLog-L is a Trojan for the Windows platform.
When Troj/SCKeyLog-L is installed the following files are created:
<System>\cvsloops.dat
<System>\cvsloops.le
<System>\spoolsvc.dll
<System>\spoolsvc.exe
The files cvsloops.dat and cvsloops.le are clean and can simply be deleted.
The file spoolsvc.dll is detected as Troj/SCKeyLo-AL.
The following registry entry is created to run spoolsvc.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
spoolsvc
<System>\spoolsvc.exe
The following registry entries are created to run code exported by spoolsvc.dll on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\spoolsvc
DllName
spoolsvc.dll
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\spoolsvc
Impersonate
0
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\spoolsvc
Startup
WLEvtStartup