![]() |
|
#1
|
||||
|
||||
|
I need to know what software win and lose against this series of keylogger vulnerabilities tests. If you guys can be so kind as to download and run the .exe much appreciated.
Here is a link to spyshelter.com At the bottom right of their home page you will find a keylogger test file to download and check yourself for vulnerabilities. Its a single .exe that opens up a panel to click on 6 tests. Simple easy & quick. I'm interested to see which HiPS SecuritySuites, (hippy)FWs & anti Keyloggers etc miss any. And your AV spotting the .exe as malware doesn't count as a pass. You gotta run the the tests. Nothing adverse happened to me by downloading it except a bit of embarrassment by a few failures. So let us know what software you tested with & how did it fare against the six simple quick tests?
__________________
SB | AG | LnS | EAM free | MR free |
|
#2
|
||||
|
||||
|
Most HIPS will fail against these type of tests because these things are extremely focused on screen cap, sound log etc, and the HIPS were not made to protect specifically this situations. Unless you use another Anti Keylog software such as Zemana etc.
__________________
Emsisoft Anti-Malware v7.0.0.21 - Online Armor 6.0.0.1736 SRP - UAC - EMET Browser: Google Chrome v25.xx Windows 7 Ultimate x64 |
|
#3
|
||||
|
||||
|
Nod says
Access denied! Details: Web page: http://spyshelter.com Category: Criminal Activities - Child Abuse Images, Criminal Skills, Hacking, Hate Speech, Illegal Drugs, Marijuana, Piracy and Copyright Theft Comment: Web page was blocked because it matched prohibited categories.
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13 |
|
#4
|
||||
|
||||
|
Quote:
Try Zemana site ![]() BTW...SpyShelter pass all ![]()
__________________
"Who was not a rebel in his youth, this will be a pig in old age" - J. Piłsudski SG.pl |
|
#5
|
||||
|
||||
|
Zemana it is good no problem
![]()
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13 |
|
#6
|
||||
|
||||
|
Quote:
is that included in the trial version? ![]()
__________________
| NoScript || Image for Linux + BootIt Bare Metal | Last edited by moontan : October 12th, 2011 at 02:16 AM. |
|
#7
|
||||
|
||||
|
Quote:
![]()
__________________
"Who was not a rebel in his youth, this will be a pig in old age" - J. Piłsudski SG.pl |
|
#8
|
||||
|
||||
|
Hahaha wonder why NOD would block SpyShelter
We need to report that! Anyone can try this with OA highest setting just to check it out? ![]()
__________________
Emsisoft Anti-Malware v7.0.0.21 - Online Armor 6.0.0.1736 SRP - UAC - EMET Browser: Google Chrome v25.xx Windows 7 Ultimate x64 |
|
#9
|
||||
|
||||
|
Avira blocks it too. I just tried it and got an access denied from Avira.
|
|
#10
|
||||
|
||||
|
Blocks the .exe or the website?
![]()
__________________
Emsisoft Anti-Malware v7.0.0.21 - Online Armor 6.0.0.1736 SRP - UAC - EMET Browser: Google Chrome v25.xx Windows 7 Ultimate x64 |
|
#11
|
||||
|
||||
|
Both as far as I could tell...here is what it says.
Quote:
Last edited by JRViejo : October 12th, 2011 at 03:26 AM. Reason: De-linked Direct Download - JRViejo |
|
#12
|
||||
|
||||
|
spyshelter update has ceased lately.
do you think the site is compromised hence it gets blocked?
__________________
Win7PRO64bit | SUA | SRP | UAC | EMET | SpywareBlaster | MVPSHOST | OpenDNS | SandboxIE | Privoxy | Windows Image Backup . built-in security + sandboxing fag. |
|
#13
|
||||
|
||||
|
Quote:
Maybe or its some sorta unfriendly competitive rivalry. Odd that two dif. AVs can sniff something there. I have no AV up right now so I can't tell. Let's see what the others say. Any other AVs getting jumpy knocking on Spyshelter's door?
__________________
SB | AG | LnS | EAM free | MR free |
|
#14
|
||||
|
||||
|
SRP blocked the .exe
prevention, prevention, prevention...
__________________
Linux Mint 13 MATE x64 Last edited by AlexC : October 12th, 2011 at 03:20 AM. |
|
#15
|
||||
|
||||
|
I tested it against Malware defender. Here are resaults:
Keylogging - PASSED Webcam capture - did not test (got no cam connected and it would probably FAIL) Screenshot - FAIL Clipboard monitoring - FAIL System protection - registry access 1 and 2 -PASSED; driver registering FAIL Sound record - did not test (got no mic connected and it would probably FAIL) MD did as I expected. I was only surprised for failing driver registering test. Of course I have allowed test to run. Had I block the execution MD would pass 100% ![]()
__________________
ESET Nod32 AV • Sandboxie • EMET • OpenDNS My security setup in detail • Always remember you're unique, just like everyone else • |
|
#16
|
|||
|
|||
|
I tested Personal Firewall in XP 32 with maxed up settings.
Keylogging - Passed Webcam capture - No cam here Screenshot - Passed Clipboard monitoring - Passed System protection - memory access 1 Passed, the rest Failed Sound record - Not covered by PF It also passed Zemana's Keylogging, Clipboard monitoring and Screenshot tests. I don't have the SSL test. Of course, it alerted of all the tests, I had to alow them first. Last edited by vojta : October 12th, 2011 at 05:04 AM. |
|
#17
|
||||
|
||||
|
Quote:
A new beta for SpyShelter 6.0 is out, so I wouldn't worry. Quote:
Probably the keylogger test is now blocked by some vendors (like SpyCar and others, without being a real malware).
__________________
Windows 7 SP1 x64, WSA, Sandboxie |
|
#18
|
|||
|
|||
|
I tested Online Armor Free + Threatfire against it:
Keylogging - Passed (OA free) Webcam capture - No cam here Screenshot - failed Clipboard monitoring - failed System protection : Test 1 - Passed (Threatfire) Test 2 - Passed (Threatfire) Sound record - Passed (OA free) I'm pleased with the result. ![]()
__________________
___________________________________________ - OnlineArmor free - Avira AntiVir - Threatfire - EMET - Windows 7 Pro 64bit |
|
#19
|
||||
|
||||
|
WSA blocks it as well as a win32 Malware Gen.
__________________
OS X 10.8.3 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB. |
|
#20
|
|||
|
|||
|
CIS (the AV) blocks the file as well.
__________________
CIS & Mbam Pro
OpenDNS + DNSCrypt / EMET / UAC / Applocker My complete "9 layers of protection" security setup |
|
#21
|
||||
|
||||
|
Geeze either a lot of FP going on here or the site may have been compromised. I hope not,it will not look to good for SS if it has.
__________________
OS X 10.8.3 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB. |
|
#22
|
||||
|
||||
|
I find the fact that AV's are blocking/detecting this file depressing. It has been available for some time and is from a known reputable vendor. Occassionally I need a reminder why I gave up on them in real time, things like this help! I suppose it could be classified as a PUP or the heuristics are detecting the behaviour but still. Could it be to avoid their users knowing they don't pass the test? Surely not
Anyway detection ain't the point here, ability to recognise and prevent the apps key/screen logging etc is. I think you will find nowadays all the main HIPS OA, Comodo, Outpost etc do very well on the tests on 32 bit sysyems. On 64 bit it is a different story (not surprising given the patch gaurd issues) although keylogging protection seems to be much better now but screen capture protection still fairly poor. I've been considering using HIPS again recently and on my Win 7 64 bit set-up (last month or so) I've tried Outpost, Comodo, Online Armor, Private Firewall and even Kaspersky 2012 HIPS against these tests. All passed the keylogging and they failed either the clipboard and/or some or all of the screen capture. Surprising (to me anyway) on my set-up Outpost was best as it was poor on 64 bit not long ago and even more so that PFW was by far the worse and furthest behind the very good 32 bit version (although to be fair none offerred the same degree of protection they did on 32 bit). Spyshelter itself of course passed all and WSA prevented all when in a https site. I think we should find this type of thing interesting and perhaps even indicative but there should always be the regognition that developers could have designed their products to pass this particular test rather than to protect against the methods it uses. Anyway.......
__________________
Chris Last edited by chris1341 : October 12th, 2011 at 08:22 AM. |
|
#23
|
||||
|
||||
|
Quote:
Yes, but if I allow the test, it says to that some registry's keys was modified: but they should be protected by default by Defense+ settings. So ??
__________________
We are such stuff As dreams are made on. |
|
#24
|
||||
|
||||
|
Quote:
__________________
OS X 10.8.3 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB. |
|
#25
|
||||
|
||||
|
I've checked site of SS (home and download) on VT:
Avira Clean site BitDefender Clean site Dr.Web Clean site G-Data Clean site Malc0de Database Clean site MalwareDomainList Clean site Opera Clean site ParetoLogic Malware site Phishtank Clean site TrendMicro Clean site Websense ThreatSeeker Unrated site Wepawet Unrated site It's obvious for me that site is clean and safe. There are many sites which are flagged as "suspicious/unsafe/danger" for one reason only...they are site of security apps or security forums.
__________________
"Who was not a rebel in his youth, this will be a pig in old age" - J. Piłsudski SG.pl |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|