PDA

View Full Version : Powered Keylogger Undetectable?


Searching_ _ _
September 30th, 2008, 01:18 AM
I wonder if it is still undetectable. http://www.wilderssecurity.com/images/smilies/dry.gif
Hasn't been updated since September 2007.
-{ Quote: "Powered Keylogger is a driver-based software keylogger that secretly captures keystrokes, mouse clicks and passwords, tracks sent and received emails, monitors Internet activity and logs launched applications. Powered Keylogger is undetectable by a list of firewalls and antivirus software, even anti-spyware/anti-keyloggers won`t locate it." }-

It uses a kernel level driver.

http://www.security-utilities.com/keylogger.html

Detection List (http://www.mykeylogger.com/detection-list/)

xtree
September 30th, 2008, 03:30 AM
-{ Quote: "I wonder if it is still undetectable. http://www.wilderssecurity.com/images/smilies/dry.gif
Hasn't been updated since September 2007.

It uses a kernel level driver.
" }-

Undetectable when installed beforehand?
Don't let it be installed. ;)

chrome_sturmen
September 30th, 2008, 03:37 AM
I just scanned the installer itself with superantispyware,malwarebytes antimalware, agnitum spyware scanner, avira, and kaspersky.

Only agnitum and avira detected the installer as malware.

jmonge
September 30th, 2008, 03:39 AM
-{ Quote: "I just scanned the installer itself with superantispyware,malwarebytes antimalware, agnitum spyware scanner, avira, and kaspersky.

Only agnitum and avira detected the installer as malware." }-
i tried it againts ProcessGuard stop the installer from installing after i allow to run.i think it uses some kernel tecniques.

trjam
September 30th, 2008, 03:50 AM
F-Secure 2009 pops it.

C:\Users\Austin\Desktop\powered_keylogger.exe Action: quarantined

Franklin
September 30th, 2008, 06:21 AM
Can't run in a tightened sandbox.
203183
203184

vijayind
September 30th, 2008, 07:12 AM
During installation and running, Comodo Defense+ finds it.
203185

lodore
September 30th, 2008, 07:13 AM
kaspersky blocks it.
riskware not-a-virus:monitor.win32.powerlogger
maybe someone can installl in a vm and see if anything detects it once active.
such as superantispyware, major av's,anti rootkit tools etc.

vijayind
September 30th, 2008, 08:24 AM
SAS doesn't detect it. I have Trend Micro 2009 , SAS Pro and Comodo on my spare system.
On installing, only Comodo Defense+ gave alerts. Both Trend Micro ans SAS-Pro were silent. Scanning memory and scanning in safe mode ( the directory of the keylogger) did not change anything. Both SAS Pro and Trend missed it cold !!

EDIT: A-Squared/Ikarus detects it as not-a-virus:Monitor.Win32.PowerLogger.220

Franklin
September 30th, 2008, 08:56 AM
Yes but is it really malware as it still needs installation with no rogue like symptoms and some may have a use for it?

Also it's advertised as to it's full capabilities.

Dark Star 72
September 30th, 2008, 09:26 AM
Detected by Prevx 2.0 and Prevx CSI as soon as the download to the desktop finished. Didn't need to try and install it.:thumb:
No reaction from GeSWall, presumably you would need to run it for GeSWall to detect it.

PROROOTECT
September 30th, 2008, 09:46 AM
I can not try, because that AVIRA AntiVir - CATCH IMMEDIATELY before downloading completely ...:-*

PROROOTECT

Firebytes
September 30th, 2008, 10:23 AM
Avast caught it as soon as I tried to download it.

PROROOTECT
September 30th, 2008, 10:34 AM
Avast bravo!... It seems, it is somewhat improved ... for this case ...:blink:

Firebytes
September 30th, 2008, 10:35 AM
Only 3 AVs flag the installer at ~VirusTotal link removed per policy. - Ron~ and Avast wasn't one of them. Maybe due to them using a different version of avast at VT.

I didn't try to install the logger to see how well it hides itself after installation.

trjam
September 30th, 2008, 10:40 AM
well obviously that tells you something about Virus Total as we have screenshots showing more catching it then they seem to show.

Franklin
September 30th, 2008, 11:15 AM
If I upload Powered Keylogger 2.2.exe to VT I get "file has already been analysed" which shows 15 detections on the 28th of this month with 35 scan engines.

If I hit re-analyze it shows 17 detections for todays date with 36 scan engines?
203191

203192

Firebytes
September 30th, 2008, 12:10 PM
~Link removed per policy. - Ron~


Oops, my bad....sorry Ronjor. I went back and read the policy on VT and Jotti results. Won't happen again.:-[

Firebytes
September 30th, 2008, 01:37 PM
-{ Quote: "If I upload Powered Keylogger 2.2.exe to VT I get "file has already been analysed" which shows 15 detections on the 28th of this month with 35 scan engines.

If I hit re-analyze it shows 17 detections for todays date with 36 scan engines?" }-

Franklin,

After reading your post and thinking about it for a bit I decided to download the logger again and upload it to VT a second time. This time I got the same results as you did 17/36 detections (Avast was one of them) so I am not sure what happened the first time I sent it to VT. The only thing I can think of is that when avast popped up the first time I downloaded it and I ignored the warning that Avast somehow corrupted changed the file?? This time I disabled Avast while downloading the file.

BrendanK.
September 30th, 2008, 08:29 PM
NIS 2009 gobbled it up.

Hugger
September 30th, 2008, 10:43 PM
Has anbody tried this against Defensewall?

djohn
October 1st, 2008, 12:16 AM
Nod32 detected it but not a word from threatfire at defaults.

farmerlee
October 1st, 2008, 01:47 AM
Dr Web cureit detects it after its installed.

Kees1958
October 2nd, 2008, 01:45 AM
-{ Quote: "Avast caught it as soon as I tried to download it." }-

Strange behaviour of Avast free

I have Avast standard shield only, no web based scnaner, Avast does not warn when writing to disk!, Right click and scan and it give a warning?


Would you check with the web shield disabled and write it to you hard disk (standard shield should catch it). This to find out whether it is a general inconsistency or only my set up.

Thanks

Kees1958
October 2nd, 2008, 01:48 AM
-{ Quote: "Has anbody tried this against Defensewall?" }-

Driver won't install

aigle
October 2nd, 2008, 07:08 AM
It will be interesting to see if KeyScrambler can defeat it once it,s installed!

farmerlee
October 2nd, 2008, 08:40 AM
Keyscrambler personal defeats it. Installed keyscrambler in xp sp3 then installed powered keylogger 2.2. Using IE6 powered keylogger records nothing but random keystrokes.

Firebytes
October 2nd, 2008, 10:30 AM
-{ Quote: "Strange behaviour of Avast free

I have Avast standard shield only, no web based scnaner, Avast does not warn when writing to disk!, Right click and scan and it give a warning?


Would you check with the web shield disabled and write it to you hard disk (standard shield should catch it). This to find out whether it is a general inconsistency or only my set up.

Thanks" }-

@Kees1958

When I initially attempted to download the logger the other day it immediately triggered Avast due to the webshield being active. I did later that day disable Avast completely and then download the logger to my desktop. After enabling Avast again I was able to right click the logger and scan it with Avast which then alerted on it.

I will disable the webshield by itself here in a few minutes and then attempt to download the logger again and see what happens. I will let you know what happens.

Firebytes
October 2nd, 2008, 10:37 AM
@kees1958

With webshield disabled I was able to download the file to my desktop with no alert from Avast. However, if I either try to run the file or if I right click and scan it, then it is picked up by Avast.

Hope this helps.

aigle
October 7th, 2008, 07:25 AM
KeyScrambler defeats this keylogger. :thumb:

Kees1958
October 7th, 2008, 07:35 AM
-{ Quote: "@kees1958

With webshield disabled I was able to download the file to my desktop with no alert from Avast. However, if I either try to run the file or if I right click and scan it, then it is picked up by Avast.

Hope this helps." }-

Thx for testing, strange the write check of the standard module does not catch it, while scanner and webshield will catch it.

cruelsister
October 7th, 2008, 07:41 AM
SEP11 won't allow download. But as this thing has been around for years (look at what AV's it was tested against), God forbid if a current AV would allow it.

aigle
October 7th, 2008, 05:42 PM
Installed hidden files n driver are easily detected by a good antirootkit scanner. Gmer detects it for example. Also RootRepeal can catch it.

Ed_H
October 8th, 2008, 12:52 PM
-{ Quote: "kaspersky blocks it.
riskware not-a-virus:monitor.win32.powerlogger
maybe someone can installl in a vm and see if anything detects it once active.
such as superantispyware, major av's,anti rootkit tools etc." }-

I just downloaded it and KIS 2009 did not pick it up. What settings are you using?

I also tried with Avira Premium and NIS 2009...both of them stopped the download.

Jedi1
October 9th, 2008, 02:40 PM
-{ Quote: "I just downloaded it and KIS 2009 did not pick it up. What settings are you using?." }-

Settings/Threats and Exclusions/ under Threats go to settings and enable other programs in adware and other programs.

Ed_H
October 9th, 2008, 04:46 PM
-{ Quote: "Settings/Threats and Exclusions/ under Threats go to settings and enable other programs in adware and other programs." }-

That did it...thanks!