Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old October 12th, 2011, 12:16 AM
AaLF's Avatar
AaLF AaLF is offline
Frequent Poster
 
Join Date: Feb 2005
Location: Sydney
Posts: 794
Default KEYLOGGER TESTS: Plz test and post your result.

I need to know what software win and lose against this series of keylogger vulnerabilities tests. If you guys can be so kind as to download and run the .exe much appreciated.

Here is a link to spyshelter.com

At the bottom right of their home page you will find a keylogger test file to download and check yourself for vulnerabilities.

Its a single .exe that opens up a panel to click on 6 tests. Simple easy & quick. I'm interested to see which HiPS SecuritySuites, (hippy)FWs & anti Keyloggers etc miss any. And your AV spotting the .exe as malware doesn't count as a pass. You gotta run the the tests.

Nothing adverse happened to me by downloading it except a bit of embarrassment by a few failures.

So let us know what software you tested with & how did it fare against the six simple quick tests?
__________________
SB | AG | LnS | EAM free | MR free
  #2  
Old October 12th, 2011, 01:09 AM
Noob's Avatar
Noob Noob is offline
Massive Poster
 
Join Date: Nov 2009
Posts: 5,229
Default Re: KEYLOGGER TESTS: Plz test and post your result.

Most HIPS will fail against these type of tests because these things are extremely focused on screen cap, sound log etc, and the HIPS were not made to protect specifically this situations. Unless you use another Anti Keylog software such as Zemana etc.
__________________
Emsisoft Anti-Malware v7.0.0.21 - Online Armor 6.0.0.1736
SRP - UAC - EMET

Browser: Google Chrome v25.xx

Windows 7 Ultimate x64
  #3  
Old October 12th, 2011, 01:18 AM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,766
Default Re: KEYLOGGER TESTS: Plz test and post your result.

Nod says
Access denied!


Details:
Web page: http://spyshelter.com
Category: Criminal Activities - Child Abuse Images, Criminal Skills, Hacking, Hate Speech, Illegal Drugs, Marijuana, Piracy and Copyright Theft

Comment: Web page was blocked because it matched prohibited categories.
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13
  #4  
Old October 12th, 2011, 01:24 AM
ichito's Avatar
ichito ichito is offline
Frequent Poster
 
Join Date: Jan 2011
Location: Poland - Cracow
Posts: 847
Default Re: KEYLOGGER TESTS: Plz test and post your result.

Quote:
Originally Posted by jmonge
Nod says
Access denied!
Haha Try Zemana site
BTW...SpyShelter pass all
__________________
"Who was not a rebel in his youth, this will be a pig in old age" - J. Piłsudski
SG.pl
  #5  
Old October 12th, 2011, 01:44 AM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,766
Default Re: KEYLOGGER TESTS: Plz test and post your result.

Zemana it is good no problem
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13
  #6  
Old October 12th, 2011, 01:58 AM
moontan's Avatar
moontan moontan is offline
Massive Poster
 
Join Date: Sep 2010
Location: Québec
Posts: 3,113
Default Re: KEYLOGGER TESTS: Plz test and post your result.

Quote:
Originally Posted by jmonge
...

Details:
Web page: http://spyshelter.com
Category: Criminal Activities - Child Abuse Images, Criminal Skills, Hacking, Hate Speech, Illegal Drugs, Marijuana, Piracy and Copyright Theft

is that included in the trial version?
__________________
| NoScript || Image for Linux + BootIt Bare Metal |

Last edited by moontan : October 12th, 2011 at 02:16 AM.
  #7  
Old October 12th, 2011, 02:10 AM
ichito's Avatar
ichito ichito is offline
Frequent Poster
 
Join Date: Jan 2011
Location: Poland - Cracow
Posts: 847
Default Re: KEYLOGGER TESTS: Plz test and post your result.

Quote:
Originally Posted by jmonge
Zemana it is good no problem
Hmmm...it looks that your web-filtering is some "silent and good friend of Zemana"
__________________
"Who was not a rebel in his youth, this will be a pig in old age" - J. Piłsudski
SG.pl
  #8  
Old October 12th, 2011, 02:19 AM
Noob's Avatar
Noob Noob is offline
Massive Poster
 
Join Date: Nov 2009
Posts: 5,229
Default Re: KEYLOGGER TESTS: Plz test and post your result.

Hahaha wonder why NOD would block SpyShelter
We need to report that!

Anyone can try this with OA highest setting just to check it out?
__________________
Emsisoft Anti-Malware v7.0.0.21 - Online Armor 6.0.0.1736
SRP - UAC - EMET

Browser: Google Chrome v25.xx

Windows 7 Ultimate x64
  #9  
Old October 12th, 2011, 02:22 AM
cm1971's Avatar
cm1971 cm1971 is offline
Frequent Poster
 
Join Date: Oct 2010
Posts: 727
Default Re: KEYLOGGER TESTS: Plz test and post your result.

Avira blocks it too. I just tried it and got an access denied from Avira.
  #10  
Old October 12th, 2011, 02:27 AM
Noob's Avatar
Noob Noob is offline
Massive Poster
 
Join Date: Nov 2009
Posts: 5,229
Default Re: KEYLOGGER TESTS: Plz test and post your result.

Blocks the .exe or the website?
__________________
Emsisoft Anti-Malware v7.0.0.21 - Online Armor 6.0.0.1736
SRP - UAC - EMET

Browser: Google Chrome v25.xx

Windows 7 Ultimate x64
  #11  
Old October 12th, 2011, 02:30 AM
cm1971's Avatar
cm1971 cm1971 is offline
Frequent Poster
 
Join Date: Oct 2010
Posts: 727
Default Re: KEYLOGGER TESTS: Plz test and post your result.

Both as far as I could tell...here is what it says.

Quote:
Warning

In order not to compromise your security, this page will not be accessed
The requested URL has been identified as a potentially dangerous website.
Further information as to why this page was blocked can be found here. A description of how to remove the block for this page is available here.



Requested URL: -http://www.spyshelter.com/download/AntiTest.exe-
Category/categories:
Malware

Last edited by JRViejo : October 12th, 2011 at 03:26 AM. Reason: De-linked Direct Download - JRViejo
  #12  
Old October 12th, 2011, 02:37 AM
Konata Izumi's Avatar
Konata Izumi Konata Izumi is offline
Very Frequent Poster
 
Join Date: Nov 2008
Posts: 1,512
Default Re: KEYLOGGER TESTS: Plz test and post your result.

spyshelter update has ceased lately.
do you think the site is compromised hence it gets blocked?
__________________
Win7PRO64bit | SUA | SRP | UAC | EMET | SpywareBlaster | MVPSHOST | OpenDNS | SandboxIE | Privoxy | Windows Image Backup .
built-in security + sandboxing fag.
  #13  
Old October 12th, 2011, 02:46 AM
AaLF's Avatar
AaLF AaLF is offline
Frequent Poster
 
Join Date: Feb 2005
Location: Sydney
Posts: 794
Default Re: KEYLOGGER TESTS: Plz test and post your result.

Quote:
Originally Posted by Konata Izumi
spyshelter update has ceased lately.
do you think the site is compromised hence it gets blocked?

Maybe or its some sorta unfriendly competitive rivalry. Odd that two dif. AVs can sniff something there. I have no AV up right now so I can't tell. Let's see what the others say.

Any other AVs getting jumpy knocking on Spyshelter's door?
__________________
SB | AG | LnS | EAM free | MR free
  #14  
Old October 12th, 2011, 03:01 AM
AlexC's Avatar
AlexC AlexC is offline
Very Frequent Poster
 
Join Date: Apr 2009
Posts: 1,111
Default Re: KEYLOGGER TESTS: Plz test and post your result.

SRP blocked the .exe
prevention, prevention, prevention...
__________________
Linux Mint 13 MATE x64

Last edited by AlexC : October 12th, 2011 at 03:20 AM.
  #15  
Old October 12th, 2011, 03:35 AM
tomazyk's Avatar
tomazyk tomazyk is offline
Frequent Poster
 
Join Date: Dec 2006
Location: Slovenia
Posts: 601
Default Re: KEYLOGGER TESTS: Plz test and post your result.

I tested it against Malware defender. Here are resaults:

Keylogging - PASSED
Webcam capture - did not test (got no cam connected and it would probably FAIL)
Screenshot - FAIL
Clipboard monitoring - FAIL
System protection - registry access 1 and 2 -PASSED; driver registering FAIL
Sound record - did not test (got no mic connected and it would probably FAIL)

MD did as I expected. I was only surprised for failing driver registering test.
Of course I have allowed test to run. Had I block the execution MD would pass 100%
__________________
ESET Nod32 AV • Sandboxie • EMET • OpenDNS
My security setup in detail
• Always remember you're unique, just like everyone else •

  #16  
Old October 12th, 2011, 04:10 AM
vojta vojta is offline
Frequent Poster
 
Join Date: Feb 2010
Posts: 461
Default Re: KEYLOGGER TESTS: Plz test and post your result.

I tested Personal Firewall in XP 32 with maxed up settings.

Keylogging - Passed
Webcam capture - No cam here
Screenshot - Passed
Clipboard monitoring - Passed
System protection - memory access 1 Passed, the rest Failed
Sound record - Not covered by PF

It also passed Zemana's Keylogging, Clipboard monitoring and Screenshot tests. I don't have the SSL test.

Of course, it alerted of all the tests, I had to alow them first.

Last edited by vojta : October 12th, 2011 at 05:04 AM.
  #17  
Old October 12th, 2011, 06:01 AM
phaser's Avatar
phaser phaser is offline
Infrequent Poster
 
Join Date: May 2010
Posts: 35
Default Re: KEYLOGGER TESTS: Plz test and post your result.

Quote:
Originally Posted by Konata Izumi
spyshelter update has ceased lately.
do you think the site is compromised hence it gets blocked?

A new beta for SpyShelter 6.0 is out, so I wouldn't worry.



Quote:
Originally Posted by cm1971
Both as far as I could tell...here is what it says.
Requested URL: -http://www.spyshelter.com/download/AntiTest.exe-
Category/categories:
Malware

Probably the keylogger test is now blocked by some vendors (like SpyCar and others, without being a real malware).
__________________
Windows 7 SP1 x64, WSA, Sandboxie
  #18  
Old October 12th, 2011, 06:14 AM
gambla gambla is offline
Regular Poster
 
Join Date: Sep 2007
Location: Frankfurt, Germany
Posts: 124
Default Re: KEYLOGGER TESTS: Plz test and post your result.

I tested Online Armor Free + Threatfire against it:


Keylogging - Passed (OA free)
Webcam capture - No cam here
Screenshot - failed
Clipboard monitoring - failed
System protection :
Test 1 - Passed (Threatfire)
Test 2 - Passed (Threatfire)
Sound record - Passed (OA free)

I'm pleased with the result.
__________________
___________________________________________
- OnlineArmor free - Avira AntiVir - Threatfire - EMET - Windows 7 Pro 64bit
  #19  
Old October 12th, 2011, 07:36 AM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,550
Default Re: KEYLOGGER TESTS: Plz test and post your result.

WSA blocks it as well as a win32 Malware Gen.
__________________
OS X 10.8.3 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
  #20  
Old October 12th, 2011, 07:46 AM
zakazak zakazak is offline
Frequent Poster
 
Join Date: Sep 2010
Posts: 229
Default Re: KEYLOGGER TESTS: Plz test and post your result.

CIS (the AV) blocks the file as well.
__________________
CIS & Mbam Pro
OpenDNS + DNSCrypt / EMET / UAC / Applocker
My complete "9 layers of protection" security setup
  #21  
Old October 12th, 2011, 07:55 AM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,550
Default Re: KEYLOGGER TESTS: Plz test and post your result.

Geeze either a lot of FP going on here or the site may have been compromised. I hope not,it will not look to good for SS if it has.
__________________
OS X 10.8.3 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
  #22  
Old October 12th, 2011, 08:16 AM
chris1341's Avatar
chris1341 chris1341 is offline
Frequent Poster
 
Join Date: Apr 2008
Location: Scotland
Posts: 624
Default Re: KEYLOGGER TESTS: Plz test and post your result.

I find the fact that AV's are blocking/detecting this file depressing. It has been available for some time and is from a known reputable vendor. Occassionally I need a reminder why I gave up on them in real time, things like this help! I suppose it could be classified as a PUP or the heuristics are detecting the behaviour but still. Could it be to avoid their users knowing they don't pass the test? Surely not

Anyway detection ain't the point here, ability to recognise and prevent the apps key/screen logging etc is.

I think you will find nowadays all the main HIPS OA, Comodo, Outpost etc do very well on the tests on 32 bit sysyems. On 64 bit it is a different story (not surprising given the patch gaurd issues) although keylogging protection seems to be much better now but screen capture protection still fairly poor.

I've been considering using HIPS again recently and on my Win 7 64 bit set-up (last month or so) I've tried Outpost, Comodo, Online Armor, Private Firewall and even Kaspersky 2012 HIPS against these tests. All passed the keylogging and they failed either the clipboard and/or some or all of the screen capture. Surprising (to me anyway) on my set-up Outpost was best as it was poor on 64 bit not long ago and even more so that PFW was by far the worse and furthest behind the very good 32 bit version (although to be fair none offerred the same degree of protection they did on 32 bit). Spyshelter itself of course passed all and WSA prevented all when in a https site.

I think we should find this type of thing interesting and perhaps even indicative but there should always be the regognition that developers could have designed their products to pass this particular test rather than to protect against the methods it uses.

Anyway.......
__________________
Chris

Last edited by chris1341 : October 12th, 2011 at 08:22 AM.
  #23  
Old October 12th, 2011, 08:18 AM
blacknight's Avatar
blacknight blacknight is offline
Very Frequent Poster
 
Join Date: Sep 2007
Location: Europe
Posts: 1,596
Default Re: KEYLOGGER TESTS: Plz test and post your result.

Quote:
Originally Posted by zakazak
CIS (the AV) blocks the file as well.


Yes, but if I allow the test, it says to that some registry's keys was modified: but they should be protected by default by Defense+ settings. So ??
__________________
We are such stuff
As dreams are made on.
  #24  
Old October 12th, 2011, 08:30 AM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,550
Default Re: KEYLOGGER TESTS: Plz test and post your result.

Quote:
Originally Posted by chris1341
I find the fact that AV's are blocking/detecting this file depressing. It has been available for some time and is from a known reputable vendor. Occassionally I need a reminder why I gave up on them in real time, things like this help! I suppose it could be classified as a PUP or the heuristics are detecting the behaviour but still. Could it be to avoid their users knowing they don't pass the test? Surely not

Anyway detection ain't the point here, ability to recognise and prevent the apps key/screen logging etc is.

I think you will find nowadays all the main HIPS OA, Comodo, Outpost etc do very well on the tests on 32 bit sysyems. On 64 bit it is a different story (not surprising given the patch gaurd issues) although keylogging protection seems to be much better now but screen capture protection still fairly poor.

I've been considering using HIPS again recently and on my Win 7 64 bit set-up (last month or so) I've tried Outpost, Comodo, Online Armor, Private Firewall and even Kaspersky 2012 HIPS against these tests. All passed the keylogging and they failed either the clipboard and/or some or all of the screen capture. Surprising (to me anyway) on my set-up Outpost was best as it was poor on 64 bit not long ago and even more so that PFW was by far the worse and furthest behind the very good 32 bit version (although to be fair none offerred the same degree of protection they did on 32 bit). Spyshelter itself of course passed all and WSA prevented all when in a https site.

I think we should find this type of thing interesting and perhaps even indicative but there should always be the regognition that developers could have designed their products to pass this particular test rather than to protect against the methods it uses.

Anyway.......
+10
__________________
OS X 10.8.3 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
  #25  
Old October 12th, 2011, 08:36 AM
ichito's Avatar
ichito ichito is offline
Frequent Poster
 
Join Date: Jan 2011
Location: Poland - Cracow
Posts: 847
Default Re: KEYLOGGER TESTS: Plz test and post your result.

I've checked site of SS (home and download) on VT:
Avira Clean site
BitDefender Clean site
Dr.Web Clean site
G-Data Clean site
Malc0de Database Clean site
MalwareDomainList Clean site
Opera Clean site
ParetoLogic Malware site
Phishtank Clean site
TrendMicro Clean site
Websense ThreatSeeker Unrated site
Wepawet Unrated site

It's obvious for me that site is clean and safe. There are many sites which are flagged as "suspicious/unsafe/danger" for one reason only...they are site of security apps or security forums.
__________________
"Who was not a rebel in his youth, this will be a pig in old age" - J. Piłsudski
SG.pl
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 11:23 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums