I wouldn't call it stupid, but for sure it is not the best option to blame software with open source

Actually there is no need to install a key logger, I guess most people have their login credentials saved in ProfitUI's textfile for auto login anyways (which is a Bad Thing(tm) btw :P ). No virus scanner would be alarmed by an application just reading a text file...