Wilders Security Forums  

Go Back   Wilders Security Forums > Official Prevx Support Forum > Prevx Releases
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #26  
Old October 17th, 2012, 08:55 AM
pegas's Avatar
pegas pegas is online now
Frequent Poster
 
Join Date: May 2008
Location: Czech Republic
Posts: 631
Default Re: Keylogger

Quote:
Originally Posted by Triple Helix
Could be I just Tested Opera, IE9 32bit & 64bit and Firefox and they all passed my testing as I use US English I even tried Canadian French keyboard input and it worked fine. Attachment 235101

TH
I tried also another two test files (ClipBoard and Webcam logger) and WSA succeeded. I had a WSA prompt for the both files. So only Keylogger is where WSA failed in my case.
__________________
Sony VAIO SR19VN, Windows Vista Business 32 SP2 fully patched, Intel Core DUO P8400 2,26 GHz, 4GB RAM, ATI Radeon
with always latest stable release of Opera, Ad Muncher, CCleaner and Webroot SecureAnywhere.
  #27  
Old October 17th, 2012, 09:11 AM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,611
Default Re: Keylogger

Quote:
Originally Posted by pegas
I tried also another two test files (ClipBoard and Webcam logger) and WSA succeeded. I had a WSA prompt for the both files. So only Keylogger is where WSA failed in my case.

Hey this is the new pop-up window that IBK was talking about here in the recent test that needed user interaction: http://www.wilderssecurity.com/showp...4&postcount=51 and what Joe was mentioning: http://www.wilderssecurity.com/showp...2&postcount=14 Cool

TH

Name:  17-10-2012 9-02-30 AM.png
Views: 158
Size:  18.7 KB
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.145 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.

Last edited by Triple Helix : October 17th, 2012 at 09:17 AM.
  #28  
Old October 17th, 2012, 09:15 AM
trjam's Avatar
trjam trjam is offline
Incredibly Massive Poster
 
Join Date: Aug 2006
Location: North Carolina
Posts: 8,618
Default Re: Keylogger

WSA needs to be able to do this automatically if you choose so.
__________________
Webroot SecureAnywhere
  #29  
Old October 17th, 2012, 09:20 AM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,611
Default Re: Keylogger

Quote:
Originally Posted by trjam
WSA needs to be able to do this automatically if you choose so.

But that's why WSA got such a High score in that test:

Blocked 88.2%
User dependent 11.2%
Compromised 0.6%

TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.145 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.
  #30  
Old October 17th, 2012, 09:21 AM
trjam's Avatar
trjam trjam is offline
Incredibly Massive Poster
 
Join Date: Aug 2006
Location: North Carolina
Posts: 8,618
Default Re: Keylogger

I understand but it is the kid factor. You should be able to tick a setting so if this pops up, it chooses to block it automatically.
__________________
Webroot SecureAnywhere
  #31  
Old October 17th, 2012, 09:27 AM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,611
Default Re: Keylogger

Quote:
Originally Posted by trjam
I understand but it is the kid factor. You should be able to tick a setting so if this pops up, it chooses to block it automatically.

We had that same discussion about WSA's Firewall and the Auto Allow if a person try's to block a known good file such as svchost.exe it could break there PC. I'm sure Joe will chime in!

TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.145 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.
  #32  
Old October 17th, 2012, 09:34 AM
BoerenkoolMetWorst BoerenkoolMetWorst is offline
Very Frequent Poster
 
Join Date: Dec 2009
Location: Outer space
Posts: 2,053
Default Re: Keylogger

Quote:
Originally Posted by Triple Helix
Hey this is the new pop-up window that IBK was talking about here in the recent test that needed user interaction: http://www.wilderssecurity.com/showp...4&postcount=51 and what Joe was mentioning: http://www.wilderssecurity.com/showp...2&postcount=14 Cool

TH

Attachment 235105
Are you sure? This one only pops up if you have the "warn before blocking.." option ticked in Identity Shield settings. Besides, even if you block it, the malware would still run on your system, so WSA doesn't pass the test, so I think IBK is talking about another popup.
  #33  
Old October 17th, 2012, 09:38 AM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,611
Default Re: Keylogger

Quote:
Originally Posted by BoerenkoolMetWorst
Are you sure? This one only pops up if you have the "warn before blocking.." option ticked in Identity Shield settings. Besides, even if you block it, the malware would still run on your system, so WSA doesn't pass the test, so I think IBK is talking about another popup.

That could be true as I did ask Joe for a snapshot of the window that IBK mentioned and he couldn't supply me one at the time.

TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.145 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.
  #34  
Old October 17th, 2012, 09:47 AM
pegas's Avatar
pegas pegas is online now
Frequent Poster
 
Join Date: May 2008
Location: Czech Republic
Posts: 631
Default Re: Keylogger

Quote:
Originally Posted by Triple Helix
That could be true as I did ask Joe for a snapshot of the window and he couldn't supply me one at the time.

TH
TH can you check something for me?

I have blocked ClipBoard and Webcam logger test files and then the both files deleted from the Protected Applications list. Now I am trying to test the both files again but they are blocked even if I deleted them from the Protected Applications list. It looks like WSA remembers the action also for the already deleted files. I thought that if any file is deleted from the list and run this file again I will get a new prompt.

Can you confirm such behaviour?
__________________
Sony VAIO SR19VN, Windows Vista Business 32 SP2 fully patched, Intel Core DUO P8400 2,26 GHz, 4GB RAM, ATI Radeon
with always latest stable release of Opera, Ad Muncher, CCleaner and Webroot SecureAnywhere.
  #35  
Old October 17th, 2012, 09:55 AM
puff-m-d's Avatar
puff-m-d puff-m-d is offline
Massive Poster
 
Join Date: Feb 2002
Location: North Carolina, USA
Posts: 3,636
Default Re: Keylogger

Go to System Tools > System Control > Control Active Processes... If you block something under Protected Applications it adds the process to Control Active Processes as being blocked too. It might be that you need to delete them there. It may be under PC Security > Quarantine > Detection Configuration also as the process is added there also so would need deleting. I am not sure of this but one of these could very well be your problem...
__________________
Best regards,
Kent

AX64 Time Machine - Travel in Time
Current Version 1.1.0.996

Last edited by puff-m-d : October 17th, 2012 at 10:01 AM.
  #36  
Old October 17th, 2012, 10:08 AM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,611
Default Re: Keylogger

I didn't block anything and it only shows in Active processes when running and it's under Monitored and I tried a second time and no pop-up and for me there is nothing under Detection Configuration so I scanned the files and:

[u] c:\users\daniel\downloads\clipboardlogger.exe [MD5: ACF401027A26261C79EE0A622CB505AC] [Flags: 000A0000.12871]
[X] c:\users\daniel\downloads\keyboard.exe [MD5: 4015B96AD426FBC02F88E22E3CB850CB] [Flags: 00080810.11812]
[X] c:\users\daniel\downloads\webcamlogger.exe [MD5: 6026649E74B52F81576494F9C082DAC0] [Flags: 00080010.12870]


Wed 17-10-2012 09:43:53.0017 Monitoring process C:\Users\Daniel\Downloads\WebcamLogger.exe [6026649E74B52F81576494F9C082DAC0]. Type: 3 (12870)
Wed 17-10-2012 09:43:53.0017 Monitoring process C:\Users\Daniel\Downloads\WebcamLogger.exe [6026649E74B52F81576494F9C082DAC0]. Type: 4 (12870)
Wed 17-10-2012 09:43:53.0017 Monitoring process C:\Users\Daniel\Downloads\WebcamLogger.exe [6026649E74B52F81576494F9C082DAC0]. Type: 5 (12870)
Wed 17-10-2012 09:43:53.0017 Monitoring process C:\Users\Daniel\Downloads\WebcamLogger.exe [6026649E74B52F81576494F9C082DAC0]. Type: 7 (12870)
Wed 17-10-2012 09:43:53.0048 Monitoring process C:\Users\Daniel\Downloads\WebcamLogger.exe [6026649E74B52F81576494F9C082DAC0]. Type: 8 (12870)
Wed 17-10-2012 09:43:53.0048 Monitoring process C:\Users\Daniel\Downloads\WebcamLogger.exe [6026649E74B52F81576494F9C082DAC0]. Type: 6 (12870)
Wed 17-10-2012 09:56:23.0960 Monitoring process C:\Users\Daniel\Downloads\ClipBoardLogger.exe [ACF401027A26261C79EE0A622CB505AC]. Type: 3 (12871)
Wed 17-10-2012 09:56:23.0960 Monitoring process C:\Users\Daniel\Downloads\ClipBoardLogger.exe [ACF401027A26261C79EE0A622CB505AC]. Type: 4 (12871)
Wed 17-10-2012 09:56:23.0960 Monitoring process C:\Users\Daniel\Downloads\ClipBoardLogger.exe [ACF401027A26261C79EE0A622CB505AC]. Type: 5 (12871)
Wed 17-10-2012 09:56:23.0960 Monitoring process C:\Users\Daniel\Downloads\ClipBoardLogger.exe [ACF401027A26261C79EE0A622CB505AC]. Type: 7 (12871)
Wed 17-10-2012 09:56:23.0975 Monitoring process C:\Users\Daniel\Downloads\ClipBoardLogger.exe [ACF401027A26261C79EE0A622CB505AC]. Type: 8 (12871)
Wed 17-10-2012 09:56:23.0975 Monitoring process C:\Users\Daniel\Downloads\ClipBoardLogger.exe [ACF401027A26261C79EE0A622CB505AC]. Type: 6 (12871)
Wed 17-10-2012 09:58:00.0664 Monitoring process C:\Users\Daniel\Downloads\Keyboard.exe [4015B96AD426FBC02F88E22E3CB850CB]. Type: 3 (11812)
Wed 17-10-2012 09:58:00.0664 Monitoring process C:\Users\Daniel\Downloads\Keyboard.exe [4015B96AD426FBC02F88E22E3CB850CB]. Type: 4 (11812)
Wed 17-10-2012 09:58:00.0664 Monitoring process C:\Users\Daniel\Downloads\Keyboard.exe [4015B96AD426FBC02F88E22E3CB850CB]. Type: 5 (11812)
Wed 17-10-2012 09:58:00.0664 Monitoring process C:\Users\Daniel\Downloads\Keyboard.exe [4015B96AD426FBC02F88E22E3CB850CB]. Type: 7 (11812)
Wed 17-10-2012 09:58:00.0680 Monitoring process C:\Users\Daniel\Downloads\Keyboard.exe [4015B96AD426FBC02F88E22E3CB850CB]. Type: 8 (11812)
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.145 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.
  #37  
Old October 17th, 2012, 10:08 AM
pegas's Avatar
pegas pegas is online now
Frequent Poster
 
Join Date: May 2008
Location: Czech Republic
Posts: 631
Default Re: Keylogger

Quote:
Originally Posted by puff-m-d
Go to System Tools > System Control > Control Active Processes... If you block something under Protected Applications it adds the process to Control Active Processes as being blocked too. It might be that you need to delete them there. It may be under PC Security > Quarantine > Detection Configuration also as the process is added there also so would need deleting. I am not sure of this but one of these could very well be your problem...
Thx puff.

If you run the file it appears within the active processes with status Monitor but you cannot delete this process you can only terminate it. As for the Detection Configuration the file is not listed here when runs.
__________________
Sony VAIO SR19VN, Windows Vista Business 32 SP2 fully patched, Intel Core DUO P8400 2,26 GHz, 4GB RAM, ATI Radeon
with always latest stable release of Opera, Ad Muncher, CCleaner and Webroot SecureAnywhere.
  #38  
Old October 17th, 2012, 10:15 AM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,611
Default Re: Keylogger

Quote:
Originally Posted by pegas
Thx puff.

If you run the file it appears within the active processes with status Monitor but you cannot delete this process you can only terminate it. As for the Detection Configuration the file is not listed here when runs.

That's true as the files don't install and just run in the users area so termination is the only option. But you can add them to Detection Configuration.

TH

Name:  17-10-2012 10-17-22 AM.png
Views: 135
Size:  36.4 KB
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.145 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.

Last edited by Triple Helix : October 17th, 2012 at 10:21 AM.
  #39  
Old October 17th, 2012, 10:15 AM
puff-m-d's Avatar
puff-m-d puff-m-d is offline
Massive Poster
 
Join Date: Feb 2002
Location: North Carolina, USA
Posts: 3,636
Default Re: Keylogger

Do you have the following box checked under Settings?
Attached Images
 
__________________
Best regards,
Kent

AX64 Time Machine - Travel in Time
Current Version 1.1.0.996
  #40  
Old October 17th, 2012, 10:17 AM
puff-m-d's Avatar
puff-m-d puff-m-d is offline
Massive Poster
 
Join Date: Feb 2002
Location: North Carolina, USA
Posts: 3,636
Default Re: Keylogger

Quote:
Originally Posted by trjam
WSA needs to be able to do this automatically if you choose so.
Check my above post. This may be what you are looking for... By default it is unchecked.
__________________
Best regards,
Kent

AX64 Time Machine - Travel in Time
Current Version 1.1.0.996
  #41  
Old October 17th, 2012, 10:22 AM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,611
Default Re: Keylogger

Quote:
Originally Posted by puff-m-d
Do you have the following box checked under Settings?

I have it checked.

TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.145 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.
  #42  
Old October 17th, 2012, 10:27 AM
puff-m-d's Avatar
puff-m-d puff-m-d is offline
Massive Poster
 
Join Date: Feb 2002
Location: North Carolina, USA
Posts: 3,636
Default Re: Keylogger

What it sounds like then is the files are not blacklisted yet as they are being monitored. I do not believe you will get the pop-up on any monitored file, you only will if the file has been blacklisted.
__________________
Best regards,
Kent

AX64 Time Machine - Travel in Time
Current Version 1.1.0.996
  #43  
Old October 17th, 2012, 10:33 AM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,611
Default Re: Keylogger

Since I have now Blocked under Detection Configuration when I try to Execute I get this pop-up.

TH

Name:  17-10-2012 10-30-10 AM.png
Views: 130
Size:  13.5 KB
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.145 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.
  #44  
Old October 17th, 2012, 10:35 AM
puff-m-d's Avatar
puff-m-d puff-m-d is offline
Massive Poster
 
Join Date: Feb 2002
Location: North Carolina, USA
Posts: 3,636
Default Re: Keylogger

Cool ... That proves it!
__________________
Best regards,
Kent

AX64 Time Machine - Travel in Time
Current Version 1.1.0.996
  #45  
Old October 17th, 2012, 10:37 AM
pegas's Avatar
pegas pegas is online now
Frequent Poster
 
Join Date: May 2008
Location: Czech Republic
Posts: 631
Default Re: Keylogger

Quote:
Originally Posted by Triple Helix
That's true as the files don't install and just run in the users area so termination is the only option. But you can add them to Detection Configuration.

TH

Attachment 235109
Yes, you can add them. However it changes nothing as regards WSA prompts. You can have files added with any status but you won't be having WSA warning.
__________________
Sony VAIO SR19VN, Windows Vista Business 32 SP2 fully patched, Intel Core DUO P8400 2,26 GHz, 4GB RAM, ATI Radeon
with always latest stable release of Opera, Ad Muncher, CCleaner and Webroot SecureAnywhere.
  #46  
Old October 17th, 2012, 11:11 AM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,582
Default Re: Keylogger

Quote:
Originally Posted by trjam
I understand but it is the kid factor. You should be able to tick a setting so if this pops up, it chooses to block it automatically.

It does, by default.
  #47  
Old October 17th, 2012, 11:44 AM
WebrootPartner WebrootPartner is offline
Infrequent Poster
 
Join Date: Oct 2012
Location: Hungary
Posts: 1
Default Re: Keylogger

Hello,

we have just done a keylogger test with ID Shield and found it is not protecting at all, all keystrokes are logged by the test keylogger that is actually being monitored by WSA (not Allow).

Further investigation showed us that it has to be related to some kind of keyboard driver issue, because if you eg. install 2 keyboards HU and EN and you happen to select EN to be the active keyboard the keylogger still logs the HU keyboard characters on that key.
See screenshot:

Name:  WSA-ID-shield-not-working.png
Views: 114
Size:  59.0 KB
http://www.filedropper.com/wsa-id-shield-not-working

So this bug might effect every non-EN keyboard users, which is rather very sad.
How can it happen with such a promoted feature in WSA?
It is a serious bug - I actually remember that in November 2011 this function worked pretty good, I personally did several demo with it successfully in NOV-DEC 2011, but it does not work at all now.


I also reported this bug to the team represented Webroot on Infosec London this April.

Please fix this bug as soon as possible!

Br,
Gyozo
  #48  
Old October 17th, 2012, 12:30 PM
szaki2 szaki2 is offline
Infrequent Poster
 
Join Date: Apr 2012
Location: Hungary
Posts: 20
Default Re: Keylogger

Yes Hungarian Windows
I try with windows xp and Bussines! version of WSA and padlock and identity shield not work.

Last edited by szaki2 : October 17th, 2012 at 12:36 PM.
  #49  
Old October 17th, 2012, 12:52 PM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,611
Default Re: Keylogger

With these Simulators and real Keyloggers the Identity Shield only protects Browsers when on HTTPS sites by default and you can set HTTP to Max to get the Padlock on the Tray Icon for all websites it's doesn't protect other applications only if it's a true Keylogger then WSA will detect as malware and remove it. Please read the Online Help File for more info: https://detail.webrootanywhere.com/a...ity_Protection

Thanks,

TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.145 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.

Last edited by Triple Helix : October 17th, 2012 at 01:01 PM. Reason: correction
  #50  
Old October 17th, 2012, 01:31 PM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,582
Default Re: Keylogger

Quote:
Originally Posted by WebrootPartner
Hello,

we have just done a keylogger test with ID Shield and found it is not protecting at all, all keystrokes are logged by the test keylogger that is actually being monitored by WSA (not Allow).

Further investigation showed us that it has to be related to some kind of keyboard driver issue, because if you eg. install 2 keyboards HU and EN and you happen to select EN to be the active keyboard the keylogger still logs the HU keyboard characters on that key.
See screenshot:

So this bug might effect every non-EN keyboard users, which is rather very sad.
How can it happen with such a promoted feature in WSA?
It is a serious bug - I actually remember that in November 2011 this function worked pretty good, I personally did several demo with it successfully in NOV-DEC 2011, but it does not work at all now.


I also reported this bug to the team represented Webroot on Infosec London this April.

Please fix this bug as soon as possible!

Br,
Gyozo

Could you let me know if this is just on other characters or on alphanumeric characters? We will generally let non-alphanumeric characters through as the OS handles them differently to where they can't be hidden safely without impacting the entry of some keystrokes.
 

Wilders Security Forums > Official Prevx Support Forum > Prevx Releases « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:19 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums