kidlogger.exe

KidLogger

Tesline-Service s.r.l.

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘MS Shell Services’.
Publisher:
Tesline-service  (signed by Tesline-Service s.r.l.)

Product:
KidLogger

Description:
KidLogger control panel.

Version:
5, 6, 0, 1

MD5:
92d139ebb0dbf9a96dce91dc0edf36d1

SHA-1:
223e658b332b3d333b9aa3be6ecb585c67cb3a88

SHA-256:
16195bf082f2ee7c5b02c2a0c771c68d5ba014039573f8759a92c114a097827d

Scanner detections:
4 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/25/2024 1:35:05 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.HfsAdware
1.3.0.7400

Kaspersky
not-a-virus:HEUR:Monitor.Win32.Kidlogger
14.0.0.835

McAfee
Keylog-Kidlog
5600.6524

Sophos
Generic PUA CC (PUA)
4.98

File size:
418.3 KB (428,336 bytes)

Product version:
5, 6, 0, 1

Copyright:
Copyright (C) Teslain 2005

Original file name:
KidLogger.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\kidlogger\kidlogger.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
11/17/2010 2:42:13 PM

Valid to:
1/14/2013 4:15:16 PM

Subject:
CN=Tesline-Service s.r.l., O=Tesline-Service s.r.l., L=Chisinau, S=MD, C=MD

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012C5A7B63E2

File PE Metadata
Compilation timestamp:
4/14/2011 12:31:22 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:28ZculyZFR+uXXjB7G/JFS2OhzjRbaTI7QCw73qPmuE3P7c9k:2Bu45XNAzeRKm6meuw

Entry address:
0x291C8

Entry point:
E8, CD, B7, 00, 00, E9, 16, FE, FF, FF, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 60, 81, 45, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 60, 81, 45, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B...
 
[+]

Entropy:
6.3457

Code size:
264 KB (270,336 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
MS Shell Services

Command:
C:\Program Files\kidlogger\kidlogger.exe -m


Scan kidlogger.exe - Powered by Reason Core Security