A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #19141  by r3shl4k1sh
 Wed May 01, 2013 9:30 pm
Elite Keylogger (sold by WideStep.com) is a keylogger for the good guys (like RATs)...

I wrote an article about this keylogger on how to detect and analyze it: http://www.malwaredigger.com/2013/05/el ... lysis.html

The operation of the keylloger is done using DLL injection to processes which hooks:

GetMessage
PeekMessage


In the article i show how to get into the configuration interface by bypassing the password(s) requirement.

I am not uploading the files of the keylogger since i think they include the captured information (windows password and so on) in the binary files themselves.
In order to get the files you can download a demo version of this keylogger from the company web site at:
http://www.widestep.com/