klrsx.exe

Master Keystroke Logger Pro Installation

ElectraSoft Trusted File

The application klrsx.exe, “Master Keystroke Logger Pro Installer” by ElectraSoft Trusted File has been detected as a potentially unwanted program by 12 anti-malware scanners. Accoriding to the detections, this has been classified as a kyelogger which is capable of recoring a user's keystrokes. The file has been seen being downloaded from www.electrasoft.com.
Publisher:
ElectraSoft  (signed by ElectraSoft Trusted File)

Product:
Master Keystroke Logger Pro Installation

Description:
Master Keystroke Logger Pro Installer

Version:
10.06.01

MD5:
d69115b434af388bc1cb04f8acc7ae68

SHA-1:
0878ae57b13da8ace923af37d9b8aa005ede0d60

SHA-256:
77badf97b2c07765de05c04e729e533356ef87de487c8343e035044ee028c191

Scanner detections:
12 / 68

Status:
Potentially unwanted

Explanation:
The software cotains keystroke monitoring/logging capablities which may or may not be installed without the user's knowledge.

Analysis date:
4/26/2024 6:06:24 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
2014.9-150528

Baidu Antivirus
Hacktool.Win32.MasterKeystrokeLogger
4.0.3.15528

ESET NOD32
Win32/MasterKeystrokeLogger.A potentially unsafe (variant)
9.11675

Fortinet FortiGate
Riskware/MasterKeystrokeLogger
5/28/2015

G Data
Win32.Application.Agent.KRVKSP
15.5.25

K7 AntiVirus
Unwanted-Program
13.204.16011

Malwarebytes
PUP.KeyLogger.MS
v2015.05.28.01

McAfee
Keylog-MasterKeystroke
5600.6751

Norman
Suspicious_Gen4.IJWNJ
11.20150528

Sophos
Generic PUA DF
4.98

Trend Micro House Call
TROJ_GEN.R047B04EH15
7.2.148

VIPRE Antivirus
Spyware.Keylogger
40500

File size:
2.5 MB (2,588,904 bytes)

Product version:
10.06.01

Copyright:
Copyright © since 1990

Trademarks:
ElectraSoft, Master Keystroke Logger Pro

Original file name:
klrsx.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\klrsx.exe

Digital Signature
Authority:
ElectraSoft Trusted File

Valid from:
7/1/2011 7:15:46 AM

Valid to:
6/28/2021 7:15:46 AM

Subject:
E=jon@electrasoft.com, CN=ElectraSoft Authentication, O=ElectraSoft Trusted File, L=Missouri City, S=Texas, C=US

Issuer:
E=jon@electrasoft.com, CN=ElectraSoft Authentication, O=ElectraSoft Trusted File, L=Missouri City, S=Texas, C=US

Serial number:
00ECBAF58765161E49

File PE Metadata
Compilation timestamp:
5/16/2015 6:32:38 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:bNCmpmhYERhdEnFBukzkCIw23i5pQduTLahpR2/ul/yoGVNY58bIEzW+/m/rF7k0:hKVESkAtw2QpsuHSp4ul/yow7zWYNc5

Entry address:
0x77F0

Entry point:
55, 8B, EC, 6A, FF, 68, F0, 00, 42, 00, 68, 38, C5, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, FC, E1, 41, 00, 33, D2, 8A, D4, 89, 15, 28, F4, 42, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, 24, F4, 42, 00, C1, E1, 08, 03, CA, 89, 0D, 20, F4, 42, 00, C1, E8, 10, A3, 1C, F4, 42, 00, 6A, 01, E8, 83, 4C, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, C3, 00, 00, 00, 59, E8, 6C, 22, 00, 00, 85, C0, 75, 08, 6A, 10, E8, B2, 00, 00, 00, 59, 33, F6, 89, 75...
 
[+]

Entropy:
6.5556

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
116 KB (118,784 bytes)

The file klrsx.exe has been seen being distributed by the following URL.

Remove klrsx.exe - Powered by Reason Core Security