EQSECURITY FAILS AKLT (Anti Key Logger Test)

Discussion in 'other anti-malware software' started by TerryWood, Jul 11, 2008.

Thread Status:
Not open for further replies.
  1. hammerman

    hammerman Registered Member

    Joined:
    Jul 14, 2007
    Posts:
    283
    Location:
    UK
    Thanks LoneWolf.

    Do you get the message (post #11) that the screenshot has been saved successfully? Has the .jpg file been created when you look in the folder in which AKLT is located?
     
  2. LoneWolf

    LoneWolf Registered Member

    Joined:
    Jan 2, 2006
    Posts:
    3,792
    Yes to both questions.
    But the JPEG image is still only a black screen, nothing recorded. :thumb:
     
  3. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,485
    Location:
    U.S.A. (South)
    Thanks hammerman for nailing down the exact item and indeed it escapes EQS. Another reason why it would be nice to see this and some other improvements/preventions added to form and complete a final version 4.

    Since i'm a english only literate, it behooves me to just be content with what is untill or unless we are greeted one day with a final 4 that also addresses this little quirk too.

    EASTER
     
  4. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,167
    Location:
    UK / Pakistan
    Same finding on my system. Did not test screen shots protection.
     
  5. TerryWood

    TerryWood Registered Member

    Joined:
    Jan 14, 2006
    Posts:
    1,065
    Hi all

    Can this be put right by additional rules? (I'm thinking here of Alcyons)

    Terry
     
  6. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,167
    Location:
    UK / Pakistan
    I don,t think so.
     
  7. Alcyon

    Alcyon Registered Member

    Joined:
    Jan 16, 2008
    Posts:
    438
    Location:
    Montr?al, Canada
    For EQS v3.41, there's nothing to do about GetKeyboardState and GetRawInputData but for the screenshot2 poc, like i've said earlier, you can whitelist all default win xp apps and your installed third-party applications dealing with jpg (plus the other formats) followed by a "prompt and block" rule for the same extensions in the application rules section of file protection settings. I'll probably post an example soon.
     
  8. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,485
    Location:
    U.S.A. (South)
    I would hope the beta 4.0 link was still good but by now i'm not so sure, but once again, it absolutely STOPS/BLOCKS aklt 3.0 keylog test "all of them" above the 2 screenshots that are evasive although i been able to block the first one, the second one gets taken regardless.

    I also stand corrected on EQS 3.41 driver which is a chief componant of this HIPS. The 75Kb refers to old 3.40 and 3.41's driver(s) is larger, i been able to find from my own past downloads, EQS driver measures, of 107, 110, 111, and the current 112 that i been using for quite awhile and Alcyon's 3.41 RulesSets seem to work fine with it.

    This tells me active improvements were implimented into this particular componant as well as some dll's which defintely have to do with the sandbox feature, but i don't bother with that feature hardly at all.

    EASTER
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.