This Keylogger Defeats Zemana And Comodo D+

Discussion in 'other anti-malware software' started by markedmanner, Feb 2, 2011.

Thread Status:
Not open for further replies.
  1. Noob

    Noob Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    6,491
    Probably it was not enabled during your test? :)

    Also, i hate VM's for that reason, they're so unstable for me :D (Or maybe i just feel it's unstable but really it is not)
     
  2. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,873
    Location:
    Outer space
    I'm sure it was enabled during the test.

    I have no problems with VM's, they're just slow sometimes, but that's just because it's heavy for normal consumer PC's to run two OS's plus their programs at the same time :p
     
  3. Barthez

    Barthez Registered Member

    Joined:
    Apr 28, 2010
    Posts:
    113
    Location:
    Poland
    ...but it will end soon. At least from ClearCloud DNS side. I contacted them (most likely not me only) via their contact form and i received response today, that they will remove your site from blacklist in next update.
     
    Last edited: Feb 4, 2011
  4. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    I can confirm that Prevx easily evades this keylogger with its SafeOnline module.
     
  5. Francis93

    Francis93 Registered Member

    Joined:
    Feb 1, 2011
    Posts:
    311
    The update is now in effect. The site is no longer blocked.

     
  6. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    The so-called "Block" by Process Guard gives no indication that the file is a keylogger. In fact, all PG has done in this case is to function as an anti-executable.
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    You may have guessed that I hold anti-executables in very low regard as security apps. . .

     
  7. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    6,944
    Location:
    USA
    Hi bellgamin
    But isn't the point that sometime, something else (malware) may try to start the executable, and that is when the execution blocker starts to earn its keep?
     
  8. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    Some do a little more then that like not saying anything, just doing it silently and accurately.
     
  9. Noob

    Noob Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    6,491
    I always consider that if the pop up at least tells me it's trying to key log my input, then i consider it blocked (In which Online Armor alerted about key log activities) :thumb:
     
  10. CloneRanger

    CloneRanger Registered Member

    Joined:
    Jan 4, 2006
    Posts:
    4,978
    Indeed, and that's fine with me :) as it's alerted & blocked an exe that wasn't known to my system = :thumb:

    Process Guard also alerts & blocks etc other useful things, it's not just an anti-exe ;)

    pg.gif

    Really :p

    Except that's not the whole story ! as PG would alert/block anything new you didn't double-click but tried to run, such as malware = The whole point = :thumb:
     
  11. Noob

    Noob Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    6,491
    I'm with Bellgamin opinion, but only if it's a lame Pop Up that doesn't shows or says any relevant information about the process/executable.
    (Ex. ProcessGuard Pop Ups, shows no relevant information = Crappy Pop Up with no real life usability IMO) There's no real benefit from it if it doesn't alerts your of something important :)

    At least Zemana, OA and some others alerted from key logging activities "xxxx program is trying to log your keys". :D
     
  12. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    6,944
    Location:
    USA
    SBIE blocks 16k I.jpg

    SBIE blocks 16k.jpg
     

    Attached Files:

    Last edited: Feb 5, 2011
  13. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    6,944
    Location:
    USA
    I agree. Through restriction configuring, Sandboxie can stop the logger from running.
     
  14. Noob

    Noob Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    6,491
    Tested this against F-Secure 2011 just for fun.
    All settings are maxed, it failed :)
     
  15. Noob

    Noob Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    6,491
    Vipre failed too because it didn't warn me of any suspicious activities (Vipre HIPS is more like an anti executable).
    It only warned me about "16k.exe wants to run" :)
     
  16. Espresso

    Espresso Registered Member

    Joined:
    Aug 1, 2006
    Posts:
    976
    The signature vendor is not on the TVL.


    You also have to uncheck "Automatically scan unrecognized files in the cloud".

    This is not signed by a trusted vendor, so the "Automatically trust files from trusted vendors" has no effect.

    The question is: when it is scanned in the cloud, is it trusted because of the Comodo signature or behaviour analysis?
     
  17. Noob

    Noob Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    6,491
    This! i asked the same thing at their forums, and they didn't give me a detailed answer. :cautious:
    Anyways, i'm still using Comodo CIS V5.3 and it's awesome :D
     
  18. kjdemuth

    kjdemuth Registered Member

    Joined:
    Jul 29, 2005
    Posts:
    2,974
    Location:
    Boston, MA
    Checking in the cloud is both the cloud scanner and I believe CIMA. The behavior blocker is coming supposedly.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.