Hidden Recorder

Hidden Recorder is a key logger that monitors and captures data from computers including screenshots, keystrokes, web cam and microphone data, instant messaging chat sessions, email, visited websites. It even can steal the password.0

General information:

Malware Name: Hidden Recorder
Malware Type: Key Logger
Company Name: Oleansoft
Company URL: http://oleansoft.com/
Threat Level: High Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

Oleansoft provides you the software Hidden Recorder that is an invisible and easy-to-use PC activity monitoring tool that captures screenshots of the active application window or the entire desktop at the predefined time intervals varying from 5 seconds to 1 hour and saves the recorded images to a specified directory on the hard drive.

Spyware Description:

Hidden Recorder is a key logger that monitors and captures data from computers including screenshots, keystrokes, web cam and microphone data, instant messaging chat sessions, email, visited websites. It even can steal the password.0

Characteristics/Symptoms:

    -> It can even steal the password. -> It is usually hidden from the user. -> It captures and logs keystrokes on the computer without the user's knowledge and consent. -> The logged data may be encrypted and is typically sent to a remote attacker.0

Additional information might be found here:

google Search at Google for Hidden Recorder
bing Search at Bing for Hidden Recorder
yahoo Search at Yahoo for Hidden Recorder

Processes Running:

HR.EXE

File information Created after Installation:

File Location Size (Bytes) Type
C:\Program Files\Oleansoft\HR\HRHELP.CHM 69793 Compiled HTML Help file
C:\WINDOWS\hrdir.ini 29 Configuration Settings
C:\WINDOWS\system\Winhr15.dll 3 Application Extension

Folder information Created after Installation:

Folder Location
C:\Program Files\Oleansoft\HR

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hidden Recorder DisplayName0
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hidden Recorder [NULL]0