Interesting keylogger test

Discussion in 'other anti-malware software' started by aigle, Dec 1, 2007.

Thread Status:
Not open for further replies.
  1. Wordward

    Wordward Former Poster

    Joined:
    Jan 12, 2007
    Posts:
    707
    Ok I downloaded and install Webroot Firewall and that failed also. BTW.........what a dumb and ugly GUI. I will never use Webroot Firewall.

    Did you have the Learning Mode off, Process Monitor set on High, and the Dynamic Security Agent Protection enabled under the Advanced settings?
     
  2. LoneWolf

    LoneWolf Registered Member

    Joined:
    Jan 2, 2006
    Posts:
    3,784
    Hmmm...
    Anyone else have something they can throw at this test o_O
    More app's are failing then passing here. :gack:
     
  3. WSFuser

    WSFuser Registered Member

    Joined:
    Oct 7, 2004
    Posts:
    10,639
    Has anyone tried Mamutu or Prevx against it?
     
  4. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    This alert is very common with CFP but not with other HIPS, according to my observation.
     
  5. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    EQS v 3.41

    Is there a newer version than this?
     
  6. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Don,t expect them to catch it!
     
  7. TerryWood

    TerryWood Registered Member

    Joined:
    Jan 14, 2006
    Posts:
    1,039
    Hi All

    I tried MOK (MouseOnlyKeyboard) with this KeyLogger. The only thing it records is the pressing of Control Key when you are pasting into a login box. As far as I can see it does not copy the actual data going into the login box.

    Poor mans KeyScrambler but it seems to work

    Terry
     
  8. dmenace

    dmenace Registered Member

    Joined:
    Nov 29, 2006
    Posts:
    275
    Good work fellas,

    More tests to improve / benchmark HIPS software!
     
  9. guest

    guest Guest

    keyscrambler passed
    anti keylogger elite fail.
     
  10. Hawk82

    Hawk82 Registered Member

    Joined:
    Feb 11, 2007
    Posts:
    29
    Zone Alarm Anti-spyware 7.0.462 failed. But i guess if the program wanted to steal some data it would have to make an outbound connection...then it would get caught by most firewalls :D
     
  11. TerryWood

    TerryWood Registered Member

    Joined:
    Jan 14, 2006
    Posts:
    1,039
    Hi All

    Anybody got any comments on how Sandboxie would perform against this keylogger test?

    Maybe Aigle has done some work on it?

    Look forward to comments

    Terry
     
  12. Vettetech

    Vettetech Former Poster

    Joined:
    Nov 24, 2007
    Posts:
    339
  13. alfa1

    alfa1 Registered Member

    Joined:
    May 3, 2006
    Posts:
    61
    Thank you very much for your reply, much appreciate....:thumb:

    Personally I can not judge myself expert as you even if in this particulare case I reach the same conclusions...:D


    Do you think it is due to a different D+ approach or there is a particular explanation that is able to explain the different behavior compared to "traditional" HIPS?

    Txs in advance and bye bye from Italy...:p
     
  14. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    SBIE has never stopped any keyloggers in my experience. It,s well known. Correct me if I am wrong.
     
  15. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    I am not sure, out of my expertise.

    I think it may be related to some default settings in those HIPS that avoid some particular popups related to some legit system processes/ dlls etc, a way to avoid too many popups. I know SSM free avoids many popups related to system dlls. It may be a similar thing.

    I found this popup too annoying with CFP.
     
  16. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    What do u mean by this? U will find loads of such software on internet!
     
  17. ErikAlbert

    ErikAlbert Registered Member

    Joined:
    Jun 16, 2005
    Posts:
    9,455
    That keylogger test is completely removed by my frozen snapshot during reboot, including the .zip-file, like any other "change" on my system partition.
     
  18. SystemJunkie

    SystemJunkie Resident Conspiracy Theorist

    Joined:
    Mar 3, 2006
    Posts:
    1,500
    Location:
    Germany
    indeed strange thing,
    zone alarm fails most keylogger tests. Beside I found a vulnerability in process guard 3.41, lol,
    you can kill processes via simple method and pg doesn´t take any notice of that.
     
  19. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    It,s very much expected. I wonder why u even bother for this testing. Were u really expecting it to bypass frozen snapshot? It,s a very simple piece of software, not intended to bypass any boot to restore setup!
     
  20. jrmhng

    jrmhng Registered Member

    Joined:
    Nov 4, 2007
    Posts:
    1,268
    Location:
    Australia
    From what I have read, sandboxie allows for system hooks inside the sandbox. So if this is run and in the same sandbox session you type in your banking details, it would be logged. However if you clear your sandbox, the keylogger should go with it.

    Check out http://www.sandboxie.com/index.php?DetectingKeyLoggers for more details.

    Has anyone tried this with DSA properly i.e. learning mode off?
     
  21. ErikAlbert

    ErikAlbert Registered Member

    Joined:
    Jun 16, 2005
    Posts:
    9,455
    I take any opportunity to test my frozen snapshot. I expected from PC Security to lock my data partition, it failed. Why would I expect more or less from FDISR, it can fail too, just like any other software.
     
  22. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    It can but I will really never expect FDISR frozen snapshot to fail against this tiny keylogger software- no grounds at all for that. Did u really expect so?
     
  23. ErikAlbert

    ErikAlbert Registered Member

    Joined:
    Jun 16, 2005
    Posts:
    9,455
    No, but I expected from PC Security doing its job also and it didn't. Getting tired of trusting softwares. ;)
     
  24. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    So my guess was right. You just wanted to drag ur frozen snapshot in the thread.:) Am I right?
     
  25. MaB69

    MaB69 Registered Member

    Joined:
    Dec 9, 2005
    Posts:
    540
    Location:
    Paris
    Hi,

    No offense ErikAlbert but between two reboot, the keylogger already done it's job

    My opinion : freeze less, layer more ;) :p

    MaB
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.