Zip Password Recovery

Zip Password Recovery is a password recovery tool that may be used to gain unauthorized access to a computer and to a user s data. It is harmful if installed without the knowledge of the user.

General information:

Malware Name: Zip Password Recovery
Malware Type: Password Recovery Tool
Company Name: Datahjaelp
Company URL: http://www.datahjaelp.com/
Threat Level: Low Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

Datahjaelp provides you the software Zip Password Recovery that can recover lost passwords for zip archives, it uses a customizable brute force attack to recover passwords. You can pause the Zip Password Recovery at any time and it is optimized for background processing using idle time when the program is minimized. Zip Password Recovery saves the current state in fixed intervals and will automatically start from the last saved state.

Spyware Description:

Zip Password Recovery is a password recovery tool that may be used to gain unauthorized access to a computer and to a user s data. It is harmful if installed without the knowledge of the user.

Characteristics/Symptoms:

    -> It is harmful if installed without the knowledge of the user. -> It may be used to gain unauthorized access to a computer and to a user s data.

Additional information might be found here:

google Search at Google for Zip Password Recovery
bing Search at Bing for Zip Password Recovery
yahoo Search at Yahoo for Zip Password Recovery

Processes Running:

ZipPass.exe

File information Created after Installation:

File Location Size (Bytes) Type
C:\Program Files\Datahjaelp\Zip Password Recovery\License.txt 7067 Text Document
C:\Program Files\Datahjaelp\Zip Password Recovery\ZipPass.ini 72 Configuration Settings
desktop \Zip Password Recovery.lnk 1829 Shortcut

Folder information Created after Installation:

Folder Location
C:\Program Files\Datahjaelp\Zip Password Recover

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{13C85860-61FD-4110-892F-1EF2A80F066B}_is1 Changed
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{13C85860-61FD-4110-892F-1EF2A80F066B}_is1 SlowInfoCache
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{13C85860-61FD-4110-892F-1EF2A80F066B}_is1