kidlogger.exe

KidLogger

Tesline-Service s.r.l.

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘MS Shell Services’.
Publisher:
Tesline-service  (signed by Tesline-Service s.r.l.)

Product:
KidLogger

Description:
KidLogger control panel.

Version:
5, 6, 6, 1

MD5:
e808749870c16e00d5585b806cf2f286

SHA-1:
ea537f23e1e933cace35ee888952363f8f4938ae

SHA-256:
7961a8efdf6a7e24773d32f1be9e19b23312557d2ca7ba97c396e32bceae9544

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
8/4/2025 9:41:45 AM UTC  (today)

File size:
418.3 KB (428,344 bytes)

Product version:
5, 6, 6, 1

Copyright:
Copyright (C) Tesline-service s.r.l. 2005-2011

Original file name:
KidLogger.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States d'America)

Common path:
C:\Program Files\kidlogger\kidlogger.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
11/17/2010 3:42:13 PM

Valid to:
1/14/2013 5:15:16 PM

Subject:
CN=Tesline-Service s.r.l., O=Tesline-Service s.r.l., L=Chisinau, S=MD, C=MD

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012C5A7B63E2

File PE Metadata
Compilation timestamp:
8/22/2011 11:48:39 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:+rn+7xl0X4pYtK2PMbl4yySVnG3SwS9i2v5xX1GInMAHsaLaIr92kZY9k:+20XhPMbl3GznWLMA7nr

Entry address:
0x29488

Entry point:
E8, 9F, B8, 00, 00, E9, 16, FE, FF, FF, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 60, 81, 45, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 60, 81, 45, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B...
 
[+]

Code size:
264 KB (270,336 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
MS Shell Services

Command:
C:\Program Files\kidlogger\kidlogger.exe -m


Scan kidlogger.exe - Powered by Reason Core Security