Best Free Keylogger Lite

Threat Scorecard

Popularity Rank: 3,894
Threat Level: 10 % (Normal)
Infected Computers: 2,184
First Seen: November 26, 2019
Last Seen: February 3, 2026
OS(es) Affected: Windows

SpyHunter Detects & Remove Best Free Keylogger Lite

File System Details

Best Free Keylogger Lite may create the following file(s):
# File Name MD5 Detections
1. 479977cb3fcbf001e879b4bfce4f1aed_tmp3038.exe 479977cb3fcbf001e879b4bfce4f1aed 84
2. d9bb076692dd72337ba6cac58f00430a38d4081843548ec4ea396adf150fd7a6 647570f549305357a343a9d1182255ae 23
3. installer_free.exe 76e1e74420a575f8504002101ac5170f 19
4. 6.1.0_installer_free.exe bb55d6a650fdaf946ebcdd26c24f989d 15
5. d69b238438fc9b322b3f9000da2b5514503f59b9abb38d2f2cbae956165c9179 bf92df38e3ed45c23d581fec2c15b4f9 13
6. syscrb.exe 811620702659cf36f3e0bf0a499b1566 9
7. CBAccess.exe 880bc48473c99cd781ea6db706fc2ed3 4
More files

Analysis Report

General information

Family Name: PUP.Best Free Keylogger Lite
Signature status: No Signature

Known Samples

MD5: 5babb2841593aa81b486dccce953da72
SHA1: 910165fb3420ad029d58eddf923d71d3fb332007
SHA256: 16D30BDE7BE101E05DCD8F3A2665CE966DA59FDE9657F852A8F3D10B72191342
File Size: 2.56 MB, 2561536 bytes
MD5: d0c7e58ff85c49c4277f6776716a50ea
SHA1: 93e9fa7973330c33ec0f0f7598bb6d2376894b2d
SHA256: 16BFF1AF258714840BF5F2B1867D6307CB3AE357F329ED3DE63AEBE47006FC62
File Size: 7.74 MB, 7737345 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 8.2.0.0
Comments This installation was built with Inno Setup.
Company Name bestxsoftware
File Description
  • App Setup
  • syscrb
File Version 6.0.0.0
Internal Name syscrb.exe
Legal Copyright bestxsoftware © 2024
Original Filename syscrb.exe
Product Name App
Product Version
  • 8.2.0
  • 6.0.0.0

File Traits

  • .NET
  • NewLateBinding
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\temp\is-25ld8.tmp\93e9fa7973330c33ec0f0f7598bb6d2376894b2d_0007737345.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-7u97e.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-7u97e.tmp\image.bmp Generic Write,Read Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
Show More
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Encryption Used
  • BCryptOpenAlgorithmProvider
Process Shell Execute
  • CreateProcess
Keyboard Access
  • GetKeyState

Shell Command Execution

"C:\Users\Idqxouue\AppData\Local\Temp\is-25LD8.tmp\93e9fa7973330c33ec0f0f7598bb6d2376894b2d_0007737345.tmp" /SL5="$501F8,6911403,832512,c:\users\user\downloads\93e9fa7973330c33ec0f0f7598bb6d2376894b2d_0007737345"

Trending

Most Viewed

Loading...