kidlogger.exe

Teslain Kid logger

Tesline-Service s.r.l.

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘MS Shell Services’.
Publisher:
Teslain. www.rohos.com  (signed by Tesline-Service s.r.l.)

Product:
Teslain Kid logger

Description:
KidLogger control panel.

Version:
3, 1, 0, 1

MD5:
a8e8110f57d3067984c616c3652e7c77

SHA-1:
686e38024da9460f24acd50a71897a2a449feaa5

SHA-256:
281d76511fa5f0c438f91153aa2cb00d3f1750c8b7e60ccf6a5110f3e2b6030d

Scanner detections:
2 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/26/2024 5:42:33 PM UTC  (today)

Scan engine
Detection
Engine version

Kaspersky
not-a-virus:HEUR:Monitor.Win32.Kidlogger
15.0.0.562

NANO AntiVirus
Riskware.Win32.Kidlogger.dbygbg
0.30.24.2668

File size:
410.3 KB (420,152 bytes)

Product version:
3, 1, 0, 1

Copyright:
Copyright (C) Teslain 2005

Original file name:
KidLogger.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\kidlogger\kidlogger.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/14/2009 2:15:18 PM

Valid to:
12/15/2010 2:15:16 PM

Subject:
CN=Tesline-Service s.r.l., O=Tesline-Service s.r.l., L=Chisinau, S=MD, C=MD

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
010000000001258E18FB13

File PE Metadata
Compilation timestamp:
11/26/2010 5:53:35 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:qXbPfp0M10GhR/EIdUfuLSZLrDp8/zoEl3+WknSnv+q9kgR:qLX0Gb5UfuiC7blOWkI+gR

Entry address:
0x27638

Entry point:
E8, FD, B7, 00, 00, E9, 16, FE, FF, FF, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 6C, 61, 45, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 6C, 61, 45, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B...
 
[+]

Code size:
256 KB (262,144 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
MS Shell Services

Command:
C:\Program Files\kidlogger\kidlogger.exe -m


Scan kidlogger.exe - Powered by Reason Core Security