View Full Version : Powered Keylogger Undetectable?
Searching_ _ _
September 30th, 2008, 01:18 AM
I wonder if it is still undetectable. http://www.wilderssecurity.com/images/smilies/dry.gif
Hasn't been updated since September 2007.
-{ Quote: "Powered Keylogger is a driver-based software keylogger that secretly captures keystrokes, mouse clicks and passwords, tracks sent and received emails, monitors Internet activity and logs launched applications. Powered Keylogger is undetectable by a list of firewalls and antivirus software, even anti-spyware/anti-keyloggers won`t locate it." }-
It uses a kernel level driver.
http://www.security-utilities.com/keylogger.html
Detection List (http://www.mykeylogger.com/detection-list/)
xtree
September 30th, 2008, 03:30 AM
-{ Quote: "I wonder if it is still undetectable. http://www.wilderssecurity.com/images/smilies/dry.gif
Hasn't been updated since September 2007.
It uses a kernel level driver.
" }-
Undetectable when installed beforehand?
Don't let it be installed. ;)
chrome_sturmen
September 30th, 2008, 03:37 AM
I just scanned the installer itself with superantispyware,malwarebytes antimalware, agnitum spyware scanner, avira, and kaspersky.
Only agnitum and avira detected the installer as malware.
jmonge
September 30th, 2008, 03:39 AM
-{ Quote: "I just scanned the installer itself with superantispyware,malwarebytes antimalware, agnitum spyware scanner, avira, and kaspersky.
Only agnitum and avira detected the installer as malware." }-
i tried it againts ProcessGuard stop the installer from installing after i allow to run.i think it uses some kernel tecniques.
trjam
September 30th, 2008, 03:50 AM
F-Secure 2009 pops it.
C:\Users\Austin\Desktop\powered_keylogger.exe Action: quarantined
Franklin
September 30th, 2008, 06:21 AM
Can't run in a tightened sandbox.
203183
203184
vijayind
September 30th, 2008, 07:12 AM
During installation and running, Comodo Defense+ finds it.
203185
lodore
September 30th, 2008, 07:13 AM
kaspersky blocks it.
riskware not-a-virus:monitor.win32.powerlogger
maybe someone can installl in a vm and see if anything detects it once active.
such as superantispyware, major av's,anti rootkit tools etc.
vijayind
September 30th, 2008, 08:24 AM
SAS doesn't detect it. I have Trend Micro 2009 , SAS Pro and Comodo on my spare system.
On installing, only Comodo Defense+ gave alerts. Both Trend Micro ans SAS-Pro were silent. Scanning memory and scanning in safe mode ( the directory of the keylogger) did not change anything. Both SAS Pro and Trend missed it cold !!
EDIT: A-Squared/Ikarus detects it as not-a-virus:Monitor.Win32.PowerLogger.220
Franklin
September 30th, 2008, 08:56 AM
Yes but is it really malware as it still needs installation with no rogue like symptoms and some may have a use for it?
Also it's advertised as to it's full capabilities.
Dark Star 72
September 30th, 2008, 09:26 AM
Detected by Prevx 2.0 and Prevx CSI as soon as the download to the desktop finished. Didn't need to try and install it.:thumb:
No reaction from GeSWall, presumably you would need to run it for GeSWall to detect it.
PROROOTECT
September 30th, 2008, 09:46 AM
I can not try, because that AVIRA AntiVir - CATCH IMMEDIATELY before downloading completely ...:-*
PROROOTECT
Firebytes
September 30th, 2008, 10:23 AM
Avast caught it as soon as I tried to download it.
PROROOTECT
September 30th, 2008, 10:34 AM
Avast bravo!... It seems, it is somewhat improved ... for this case ...:blink:
Firebytes
September 30th, 2008, 10:35 AM
Only 3 AVs flag the installer at ~VirusTotal link removed per policy. - Ron~ and Avast wasn't one of them. Maybe due to them using a different version of avast at VT.
I didn't try to install the logger to see how well it hides itself after installation.
trjam
September 30th, 2008, 10:40 AM
well obviously that tells you something about Virus Total as we have screenshots showing more catching it then they seem to show.
Franklin
September 30th, 2008, 11:15 AM
If I upload Powered Keylogger 2.2.exe to VT I get "file has already been analysed" which shows 15 detections on the 28th of this month with 35 scan engines.
If I hit re-analyze it shows 17 detections for todays date with 36 scan engines?
203191
203192
Firebytes
September 30th, 2008, 12:10 PM
~Link removed per policy. - Ron~
Oops, my bad....sorry Ronjor. I went back and read the policy on VT and Jotti results. Won't happen again.:-[
Firebytes
September 30th, 2008, 01:37 PM
-{ Quote: "If I upload Powered Keylogger 2.2.exe to VT I get "file has already been analysed" which shows 15 detections on the 28th of this month with 35 scan engines.
If I hit re-analyze it shows 17 detections for todays date with 36 scan engines?" }-
Franklin,
After reading your post and thinking about it for a bit I decided to download the logger again and upload it to VT a second time. This time I got the same results as you did 17/36 detections (Avast was one of them) so I am not sure what happened the first time I sent it to VT. The only thing I can think of is that when avast popped up the first time I downloaded it and I ignored the warning that Avast somehow corrupted changed the file?? This time I disabled Avast while downloading the file.
BrendanK.
September 30th, 2008, 08:29 PM
NIS 2009 gobbled it up.
Hugger
September 30th, 2008, 10:43 PM
Has anbody tried this against Defensewall?
djohn
October 1st, 2008, 12:16 AM
Nod32 detected it but not a word from threatfire at defaults.
farmerlee
October 1st, 2008, 01:47 AM
Dr Web cureit detects it after its installed.
Kees1958
October 2nd, 2008, 01:45 AM
-{ Quote: "Avast caught it as soon as I tried to download it." }-
Strange behaviour of Avast free
I have Avast standard shield only, no web based scnaner, Avast does not warn when writing to disk!, Right click and scan and it give a warning?
Would you check with the web shield disabled and write it to you hard disk (standard shield should catch it). This to find out whether it is a general inconsistency or only my set up.
Thanks
Kees1958
October 2nd, 2008, 01:48 AM
-{ Quote: "Has anbody tried this against Defensewall?" }-
Driver won't install
aigle
October 2nd, 2008, 07:08 AM
It will be interesting to see if KeyScrambler can defeat it once it,s installed!
farmerlee
October 2nd, 2008, 08:40 AM
Keyscrambler personal defeats it. Installed keyscrambler in xp sp3 then installed powered keylogger 2.2. Using IE6 powered keylogger records nothing but random keystrokes.
Firebytes
October 2nd, 2008, 10:30 AM
-{ Quote: "Strange behaviour of Avast free
I have Avast standard shield only, no web based scnaner, Avast does not warn when writing to disk!, Right click and scan and it give a warning?
Would you check with the web shield disabled and write it to you hard disk (standard shield should catch it). This to find out whether it is a general inconsistency or only my set up.
Thanks" }-
@Kees1958
When I initially attempted to download the logger the other day it immediately triggered Avast due to the webshield being active. I did later that day disable Avast completely and then download the logger to my desktop. After enabling Avast again I was able to right click the logger and scan it with Avast which then alerted on it.
I will disable the webshield by itself here in a few minutes and then attempt to download the logger again and see what happens. I will let you know what happens.
Firebytes
October 2nd, 2008, 10:37 AM
@kees1958
With webshield disabled I was able to download the file to my desktop with no alert from Avast. However, if I either try to run the file or if I right click and scan it, then it is picked up by Avast.
Hope this helps.
aigle
October 7th, 2008, 07:25 AM
KeyScrambler defeats this keylogger. :thumb:
Kees1958
October 7th, 2008, 07:35 AM
-{ Quote: "@kees1958
With webshield disabled I was able to download the file to my desktop with no alert from Avast. However, if I either try to run the file or if I right click and scan it, then it is picked up by Avast.
Hope this helps." }-
Thx for testing, strange the write check of the standard module does not catch it, while scanner and webshield will catch it.
cruelsister
October 7th, 2008, 07:41 AM
SEP11 won't allow download. But as this thing has been around for years (look at what AV's it was tested against), God forbid if a current AV would allow it.
aigle
October 7th, 2008, 05:42 PM
Installed hidden files n driver are easily detected by a good antirootkit scanner. Gmer detects it for example. Also RootRepeal can catch it.
Ed_H
October 8th, 2008, 12:52 PM
-{ Quote: "kaspersky blocks it.
riskware not-a-virus:monitor.win32.powerlogger
maybe someone can installl in a vm and see if anything detects it once active.
such as superantispyware, major av's,anti rootkit tools etc." }-
I just downloaded it and KIS 2009 did not pick it up. What settings are you using?
I also tried with Avira Premium and NIS 2009...both of them stopped the download.
Jedi1
October 9th, 2008, 02:40 PM
-{ Quote: "I just downloaded it and KIS 2009 did not pick it up. What settings are you using?." }-
Settings/Threats and Exclusions/ under Threats go to settings and enable other programs in adware and other programs.
Ed_H
October 9th, 2008, 04:46 PM
-{ Quote: "Settings/Threats and Exclusions/ under Threats go to settings and enable other programs in adware and other programs." }-
That did it...thanks!
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums