kidlogger.exe

Teslain Kid logger

Tesline-Service s.r.l.

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘MS Shell Services’.
Publisher:
Teslain. www.rohos.com  (signed by Tesline-Service s.r.l.)

Product:
Teslain Kid logger

Description:
KidLogger control panel.

Version:
3, 1, 0, 1

MD5:
70c054afcec3e59bcd52cb6b5f8bf8d7

SHA-1:
1eb39a1452132ab0e2a26782e67ee6468e381ea8

SHA-256:
7628c9baaa9d454d6b8ec294c8e6bb88c6aff809b592bd0d16e350c4b22117c6

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/26/2024 6:36:14 PM UTC  (today)

Scan engine
Detection
Engine version

Kaspersky
not-a-virus:HEUR:Monitor.Win32.Kidlogger
15.0.2.529

File size:
414.3 KB (424,248 bytes)

Product version:
3, 1, 0, 1

Copyright:
Copyright (C) Teslain 2005

Original file name:
KidLogger.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\kidlogger\kidlogger.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
11/17/2010 3:42:13 PM

Valid to:
1/14/2013 5:15:16 PM

Subject:
CN=Tesline-Service s.r.l., O=Tesline-Service s.r.l., L=Chisinau, S=MD, C=MD

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012C5A7B63E2

File PE Metadata
Compilation timestamp:
1/24/2011 9:59:01 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:jMB5tUcymHD6YkjYSnzPqc4CSBIOhjhJpmN7M2c8KpwP6NlHYW9k:jMhynjNb4BIIu71c05

Entry address:
0x28438

Entry point:
E8, CD, B7, 00, 00, E9, 16, FE, FF, FF, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 50, 71, 45, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 50, 71, 45, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B...
 
[+]

Entropy:
6.3393

Code size:
260 KB (266,240 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
MS Shell Services

Command:
C:\Program Files\kidlogger\kidlogger.exe -m


Scan kidlogger.exe - Powered by Reason Core Security