Samsung R525, Samsung R540 Laptops Infested with Keylogger

A graduate of the Master of Science in Information Assurance (MSIA) program at Norwich University, discovered an application called "StarLogger" keystroke-recording program had been installed on his brand new Samsung laptop. He discovered the software was located in the C:\Windows\SL\ folder, and after some investigation, Hassan found it was recording every keystroke, including emails, documents, […]

A graduate of the Master of Science in Information Assurance (MSIA) program at Norwich University, discovered an application called "StarLogger" keystroke-recording program had been installed on his brand new Samsung laptop. He discovered the software was located in the C:\Windows\SL\ folder, and after some investigation, Hassan found it was recording every keystroke, including emails, documents, usernames and passwords.

Note that the researcher only reported StarLogger on two models, a Samsung R525 and a Samsung R540.

StarLogger in Samsung laptop

The easiest way to find StarLogger is to look for its Registry key:

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\winsl

You can also look for the following files on your hard drive. If you've StarLogger, its files will be located in your Windows root directory, in a subdirectory labeled "SL". A list of files you can expect to see is below:

  • iv.ini
  • WinSL.dat
  • WinSL.exe
  • WinSLH.dll
  • ImgView.exe
  • SL-Test.txt
  • unins000.dat
  • unins000.exe
  • StarLogger.url
  • WinSLManager.exe
  • StarLogger.url
  • Uninstall StarLogger.lnk
  • StarLogger.lnk
  • StarLogger on the Web.lnk
  • WinSLManager.exe
  • WinSLH.dll
  • WinSL

You can also check your Task Manager for WinSLManager.exe.

To remove it, first, update your antivirus program, give a full system run, chances are it'll detect & remove it.

Manual method:

  1. Stop the StarLogger process by going to the Processes tab in the Task Manager, right-clicking WinSLManager.exe, and clicking on End Process. If that doesn't work, you'll have to end the process by booting into Safe Mode, tracking down the precise location of WinSLManager.exe, and deleting it there.
  2. Next, unregister StarLogger DLL file. Open a command prompt and navigate to the folder containing WinSLH.dll. Then type "regsvr32 /u WinSLH.dll" without the quotes, and you should see a pop-up window telling you that the file has been successfully unregistered.
  3. Now, go back to Registry and locate Registry key for StarLogger, as was done above. Right-click on it and select Delete.
  4. Last, manually delete all the files that you discovered in the SL directory, and remove the directory itself.

[Source]