Zemana AntiLogger 2.0 alpha beta soon :)

Discussion in 'other anti-malware software' started by osmandemi, Jul 25, 2016.

  1. rm22

    rm22 Registered Member

    Joined:
    Oct 26, 2014
    Posts:
    357
    Location:
    Canada
    Using SpywareShelter's Anti-Test tool, ZAL 2.30.2.37 Beta blocks execution of the tool & quarantines it. ZAL is passing the Keylogging and webcam tests, but FAILS screen capture, clipboard, sound and system tests. No improvement :(
     
  2. pling_man

    pling_man Registered Member

    Joined:
    Feb 11, 2010
    Posts:
    599
    Location:
    UK
    I wonder if this is because you added the tool as an exception (removing it from quarantine automatically marks it as an exception) so ZAL "trusts" it and allows it to do anything it wants. Did the keylogger actually get blocked or was it allowed to hook the keyboard but the keys were encrypted. It should prevent the hooking and the encryption driver is a second line of defence.

    It is worth removing the exception and trying again with Real Time Protection Disabled but ID Theft Protection Enabled.

    If it doesn't work then, I would suspect that the additional anti-logging features from v1.9 (clipboard, screen, webcam privacy) have not been implemented (yet?).
     
  3. rm22

    rm22 Registered Member

    Joined:
    Oct 26, 2014
    Posts:
    357
    Location:
    Canada
    the keystrokes are encrypted

    removed the exception and disabled Real Time Protection - test results are the same

    Weren't these in v1.9? I can't find any of the old documentation now.... They are not specifically listed as features in 2.x, but the "System Intrusion Protection" .i.e. the behavior blocker - I would think should be able to handle it
     
  4. pling_man

    pling_man Registered Member

    Joined:
    Feb 11, 2010
    Posts:
    599
    Location:
    UK
    The other anti-logging features were in v1.9 but they didn't work (for me) in Windows 10. Before that they worked ok in Windows 8, 8.1.

    As far as I can tell the System Intrusion Protection from 1.9 isn't implemented either, though parts of it may be used in the SSL Protection, now called SSL Intrusion Protection in the GUI (Latest version: 2.30.204.37).

    The best description I have found for ZALs features is the web page for the business product Zemana SafeOnline

    https://www.zemana.com/en-US/SafeOnline

    In the diagram, all of the real-time layers of the current ZAL can be seen:
    • Real Time Protection (also in ZAM) is an improved version of IntelliGuard (also in 1.9).
    • Pandora Cloud-Sandbox (heuristic scanning) (also in ZAM) is for 0-day protection.
    • SSL Intrusion Protection is for MitB protection (also in 1.9).
    • Keystroke Encryption driver (also in 1.9).
    The missing features seem to be:
    • System Intrusion Protection
    • Clipboard protection
    • Screen protection
    • Webcam protection.
    • Ability to create own allow/deny rules for Real Time Protection (HIPS)
    I hope these will be added (there doesn't seem to be much chance of the last one).

    There may be some issues under Windows 10 which might need to be resolved since these were previously not working in 1.9.

    It would be good if we could get some feedback on this from Zemana.
     
  5. rm22

    rm22 Registered Member

    Joined:
    Oct 26, 2014
    Posts:
    357
    Location:
    Canada
    so ZAL2 is currently the old ZAL-Free + ZAM....could be

    this link states the System Intrusion Protection is implemented, but it's not listed on the main web page so who knows...
    http://dl9.zemana.com/Website_Media/Zemana AntiLogger brochure_2016.pdf
     
  6. entropism

    entropism Registered Member

    Joined:
    Dec 9, 2004
    Posts:
    500
  7. Petrovic

    Petrovic Registered Member

    Joined:
    Mar 14, 2014
    Posts:
    81
    Location:
    Russia
    license key:
    ~ License Key Removed ~
     
    Last edited by a moderator: Sep 1, 2016
  8. Hezakiah

    Hezakiah Registered Member

    Joined:
    Aug 30, 2004
    Posts:
    166
    Location:
    SW Florida

    Awesome! Thank you. :thumb:
     
  9. JEAM

    JEAM Registered Member

    Joined:
    Feb 21, 2015
    Posts:
    576
    Does Zemana offer a chart somewhere that compares the features of ZAL to those of ZAM? I don't have a good handle on the differences between the two products.
     
  10. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    The only difference is that ZAL has these features in addition to ZAM:

    2016-09-02 (2).png
     
  11. daman1

    daman1 Registered Member

    Joined:
    Mar 27, 2009
    Posts:
    1,286
    Location:
    USA, MICHIGAN
    Yup so uninstall LAM and install ZAL, unless you don't want the added protection.
     
  12. JEAM

    JEAM Registered Member

    Joined:
    Feb 21, 2015
    Posts:
    576
    Very good, thanks. :thumb:

    So, that would suggest that ZAL should not be run alongside HitmanPro.Alert, but that maybe it's OK to run it along with MBAE or EMET?
     
  13. pling_man

    pling_man Registered Member

    Joined:
    Feb 11, 2010
    Posts:
    599
    Location:
    UK
    It runs fine alongside MBAE and EMET. You can run it with HMP.A but have to disable the keyboard encryption in HMP.A and use the ZAL for that.
     
  14. guest

    guest Guest

    In the latest version they have remove all the lines of text except the first 2
     
  15. pling_man

    pling_man Registered Member

    Joined:
    Feb 11, 2010
    Posts:
    599
    Location:
    UK
    Well those lines were only text introduced in the last release. I wonder if this page of the GUI will eventually have some controls?

    I can't see any other GUI changes.
     
  16. askmark

    askmark Registered Member

    Joined:
    Jul 7, 2016
    Posts:
    392
    Location:
    united kingdom
    I ran a ZAL smart scan on my win 7 x64 laptop and it said ntdll.dll was a "hollow process". More info said the process was ZAL.EXE itself!

    I checked the file on VT and all engines reported it as clean. It even said the file was trusted and safe.

    Is this a false positive?
     
  17. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,006
  18. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
  19. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,006
    That's normal.
    =
     
  20. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    Oh! Thanks for the info!
     
  21. JEAM

    JEAM Registered Member

    Joined:
    Feb 21, 2015
    Posts:
    576
    Thank you for the additional info!
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.