XP Logon Password Logger

It is a program that runs in the background, recording all the keystrokes. Once keystrokes are logged, they are hidden in the machine for later retrieval, or shipped raw to the attacker. The attacker then peruses them carefully in the hopes of either finding passwords, or possibly other useful information that could be used to compromise the system or be used in a social engineering attack. For example, a key logger will reveal the contents of all e-mail composed by the user. Keylog programs are commonly included in rootkits and RATs (remote administration trojans).0

General information:

Malware Name: XP Logon Password Logger
Malware Type: Key Logger
Company Name: BlazingTools
Company URL: http://www.blazingtools.com/
Threat Level: Elevated Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation.

Company Description:

Spyware Description:

It is a program that runs in the background, recording all the keystrokes. Once keystrokes are logged, they are hidden in the machine for later retrieval, or shipped raw to the attacker. The attacker then peruses them carefully in the hopes of either finding passwords, or possibly other useful information that could be used to compromise the system or be used in a social engineering attack. For example, a key logger will reveal the contents of all e-mail composed by the user. Keylog programs are commonly included in rootkits and RATs (remote administration trojans).0

Characteristics/Symptoms:

    -> Monitor and capture data from computers -> Run in stealth mode -> Intercepts keystrokes from the keyboard and records them in a log -> Starts with the operating system0

Additional information might be found here:

google Search at Google for XP Logon Password Logger
bing Search at Bing for XP Logon Password Logger
yahoo Search at Yahoo for XP Logon Password Logger

Processes Running:

encoder.exe

File information Created after Installation:

File Location Size (Bytes) Type
C:\Documents and Settings\[USER]\Start Menu\Programs\XP Logon Password Logger\Download more Loggers.lnk 534 Shortcut
C:\Documents and Settings\[USER]\Start Menu\Programs\XP Logon Password Logger\Readme File.lnk 524 Shortcut
C:\Documents and Settings\[USER]\Start Menu\Programs\XP Logon Password Logger\XP Logon Password Logger.lnk 522 Shortcut

Folder information Created after Installation:

Folder Location
C:\Program Files\XP PL
C:\Program Files\XP PL\logs

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindowsCurrentVersionUninstallXP Password Logger 1.0 DisplayName
HKEY_LOCAL_MACHINE \SOFTWARE\BT\XP Password Logger\1.0 Program Group Name
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XP Password Logger 1.0 UninstallString