Keyscrambler - Encrypt your Keystrokes


Recommended Posts

Keyscrambler - Protect your personal information from keyloggers

http://www.qfxsoftware.com/

Give keyloggers the finger.

"There is a 1 in a 1,000,000 (or more) chance that today you will be shot with a gun. Wouldn't it be great to be wearing a Kevlar vest on THAT day??"

Today I'm going to review a nifty little program called "Keyscrambler". I remembered hearing about this application a while ago and I even tried it out. Today someone referenced it in a "Keylogger Remover" thread. He was recommending it as a preemptive measure for 'next time'. That got my interest sparked again so I looked into it. I ended up buying the Premium Version. This may have been an impulse buy, but it's one of those applications that it will never hurts to have.

As you all know a keylogger is an application that runs on your system for the sole purpose of capturing all the keystrokes the user inputs (or inputs via other means) into the computer.

It's thru these types of applications that the hackers are able to steal confidential information when it is entered into a the web browser (other than phishing sites of course).

Most of the time, an Anti-virus and/or Anti-malware application will detect and remove a keylogger from a computer, but it just has to miss one once. I know that most of us think that we will never fall victim to a keylogger. We would have to be stupid, right? I think we are all smart enough not to fall for a fake antivirus ad, BUT what about a vulnerability via a 3rd party browser add-on? It could happen. Enter now the Keyscrambler.

Keyscrambler works at the keyboard driver level of the kernel (or as low as Microsoft will let it work on 64bit Windows). There is a 32bit and 64bit version. I'm running it on Windows 7 - 64bit without issue. As you start typing on the keyboard, the data gets encrypted. The entire path is encrypted, from the moment a key is pressed on the keyboard, until it reaches the box it was intended for. Once it reaches the intended location, the information is then decrypted.

A keylogger running on the system between the keyboard and the destination will just see encrypted gibberish. (Example of FL:KJERERLEJR:F)

Keyscrambler supports a plethora of applications. It has to support the application before it can encrypt the data entered into it. I found that it supports every web browser imaginable as well as all the popular email clients, IM messengers, accounting software, office software and more. Certain things that it does not encrypt would be something like the run box, but how often are you really entering your credit card information into the Windows run box?

As you type into a supported application a long green box appears in the corner of the screen. It shows you the encrypted output of what you are typing. If you prefer not to use the green bar, you can use a tray icon instead.

tpying.jpg

There are 3 versions of the application.

First, there is the Free Version. It supports IE and Firefox, Flock and that's it. If you use any other web browser you are out of luck.

Next is the Pro Version $29.99 - This supports IE and Firefox as well as all the other web browsers. It also supports Email clients, IM/ VoIP, Password Managers (including but not limited to Roboform), Zip applications, Text Editors, Music apps and Online games.

Finally we have the Premium Version $44.99. This one supports everything mentioned above. It also supports a few additional type of applications. Office, Finance, Tax, Accounting (Like QuickBooks), Networking, Encryption, File Managers and Windows log-in. A complete run down of the applications covered by the assorted versions is available on the company's website.

There is no monthly fee and its just a 1 time fee with free lifetime updates. Once you install the program you use your email address and your Product Key to show you bought the application. It does require the internet to validate. Though it doesn't look like it does any sort of activation. It just makes sure that the Product Key matches the email address.

To check out the functionality, I installed an antikeylogger tester. I had it test how well keyscrambler protected against a low level keyboard hook. I told it to record and started entering my login name and password into the Neowin.net sign in page via Firfox. Once I was finished I checked the antikeylogger tester and all I saw was gibberish, Hooray!!

keyloggertest.jpg

That's really all there is to say about this application. There aren't a lot of features. All it does is encrypt data entered into the computer so that keyloggers can't see it.

A video showing how keyscrambler does against a low-kernal mode keylogger.

For best results watch this video in HD

Edited by warwagon
Link to comment
https://www.neowin.net/forum/topic/835718-keyscrambler-encrypt-your-keystrokes/
Share on other sites

Good idea if it really does what it says, however the prices for the pro/premium versions are way too high. I would have said $9.99 for pro and it should work with all apps including Office etc. No way would I pay $45, and can't imagine many others doing so.

Just looked at their site and it's $12.99 to upgrade pro to premium, so it's cheaper to buy pro + the upgrade than premium, whacky pricing!

Remember if you use Roboform then there are no key presses to log, I assume that would be true for the other password managers.

Edited by m.keeley

Pretty stupid that you have to pay just to use it in other browsers, I am sick of everyone assuming that the entire world either uses IE, or Firefox (flock is a pretty strange choice given that its market share is even lower than Opera's). Also, a good idea, but I think the price is overkill given that being hijacked by keyloggers is pretty rare nowadays where most details are stolen through phishing.

Pretty stupid that you have to pay just to use it in other browsers, I am sick of everyone assuming that the entire world either uses IE, or Firefox (flock is a pretty strange choice given that its market share is even lower than Opera's). Also, a good idea, but I think the price is overkill given that being hijacked by keyloggers is pretty rare nowadays where most details are stolen through phishing.

Agreed. Will I ever use it? Doubtful. But cool product nonetheless.

If you use IE or Firefox, then it doesn't hurt to have the freeware version. It doesn't run any background processes, and you can configure it to show a tray icon instead of the annoying green bar.

Don't assume this is "a step ahead" of the bad guys.

A lot of keyloggers that are developed take this into consideration and are Anti-Keyscrambler and other stuff!

Might work against the older stuff (that newbies use)

:) No problem.

So which keyloggers do you know of that can get around keyscramblers? Care to give any examples or quote the source of your information?

Edited by warwagon
Man...this is for paranoid people.

I know of a certain person that has nearly a million dollars in trade accounts and online banks. If this person uses a program like keyscrambler to protect their investment accounts in the event a keylogger ever got installed, then would you still call them paranoid?

Edited by warwagon
I know of a certain person that has nearly a million dollars in trade accounts and online banks. If this person used a program like keyscrambler to protect their investment accounts in the event a keylogger ever got installed, would you still call them paranoid?
Yes. A person that worried about it would be using a nonce keyfob or some other form of 2-factor authentication. Furthermore, that person would never be using an untrusted workstation for online banking.

My wife and I have accounts with that much money in them and I wouldn't think about using a bank that allowed those funds to be transferred without some sort of reliable verification. Most of the banks and investment firms I use won't even allow notarized letters for common mail-based communication.

Also, I'd be interested if anyone has seen an analysis of Keyscrambler. What warwagon posted looks a lot like a brochure advertisement to me. Everything you get from a Google search is the same self-serving advertisement. Plus there's no information on how the software actually works (though it probably actually works very similarly to most keyloggers by installing a global hook for the keypress event). Any malware running with admin access could theoretically get your keystrokes, since the destination application must access them as well. All of these are hallmarks of a bogus application that simply gets marketed well.

A keylogger could probably do an API call to GetWindowText and it'd be as simple as that for any targeted application. It would be a trivial matter to search for password fields in browser html and do the same thing with the Windows API.

Edited by boogerjones
Man...this is for paranoid people.
If there was an open-source anti-keylogger product that had been independently tested for security vulnerabilities, I would happily give my money to its parent company. Untrusted workstations are a significant threat and keyloggers are the easiest way to get private information. Phishing scams only work on old ladies and other people who know nothing about technology.
If there was an open-source anti-keylogger product that had been independently tested for security vulnerabilities, I would happily give my money to its parent company. Untrusted workstations are a significant threat and keyloggers are the easiest way to get private information. Phishing scams only work on old ladies and other people who know nothing about technology.

agreed

i use SSH tunnels and stuff to avoid information leakage, this just protects from another type of leakage

KeyScrambler will protect you against the majority of keyloggers, but it is far from fool proof.

I think the only way a true keylogger could bypass KeyScrambler is to install a system driver. Even with UAC disabled, Windows should still prompt you before installing an unsigned driver.

But there are far simpler ways to bypass KeyScrambler:

- Install a plugin into the web browser to capture the keystrokes after they're decrypted.

- Or even simpler, just disable the KeyScrambler plugin, though you might notice the green bar is gone.

Heck, if you start IE InPrivate Browsing, it disables all addons including KeyScrambler.

But as I said before, it will protect you against the majority of keyloggers.

Heck, if you start IE InPrivate Browsing, it disables all addons including KeyScrambler.

Incorrect.....sorta

The personal version runs as an extension in IE. The paid versions do not. Same for firefox.

inprivatev.jpg

Edited by warwagon
Yes. A person that worried about it would be using a nonce keyfob or some other form of 2-factor authentication. Furthermore, that person would never be using an untrusted workstation for online banking.

Define untrusted. The person I was referring to is using their own machine not some random PC at some persons house, they have no control over. By Trusted workstation are you referring to a pc that is just for doing online banking and nothing else?

  • 2 weeks later...
  • 2 weeks later...
So which keyloggers do you know of that can get around keyscramblers? Care to give any examples or quote the source of your information?

These fancy "key scramblers" indeed work against two types of key-loggers:

- those using passive methods for recording keystrokes (making use of API like GetAsyncKeyState() or GetForegroundWindow()... ).

- and also those hooking API function calls (thus intercepting keyboard events).

However, none of those fancy scramblers stand a chance against two types of widely known and used key-loggers:

- Those implemented as part of a kernel-level rootkit. They act as the keyboard driver, and have low level access to the hardware itself.

- those implemented in a malware hypervisor. Those have more privileges than the OS Kernel itself.

All in all, those so called keyscramblers would have done a very good job 10 years ago, not now.

Well I thought I would test it

I downloaded keyscrambler premium in a vm along with Elite Keylogger

http://www.widestep.com/

Elite Keylogger works in low-kernel mode as a driver-based monitoring software recording every detail of PC and Internet activity. It is the optimum solution for homes, families, small and middle offices, as well as big companies with the need to monitor hundreds of employees. Elite Keylogger is driver mode low kernel Keylogger.

It did not record anything I was typing when I used key scrambler. Once I turned off keyscammbler it recorded just fine. So that is one example of keyscrammbler defeating a low kernal mode driver based keylogger.

Web of Trust is saying that widestep.com is very untrustworthy. Are you sure you didn't actually install a keylogger instead of a keylogger prevention? :)

EDIT: Durr... widestep is where you did get the keylogger from. :)

Yep if you read some of the comments on the score card of WOT it says they make key loggers lol.

Right now i'm in the process of making a video I will put on youtube, just in case someone doesn't believe me.

Ok here is the video. As i'm posting this yotuube is still improving the quality of the video. So by the time you read this it will probably be HD.

THis video is of the test I mentioned above.

Well I thought I would test it

I downloaded keyscrambler premium in a vm along with Elite Keylogger

http://www.widestep.com/

Quote -

Elite Keylogger works in low-kernel mode as a driver-based monitoring software recording every detail of PC and Internet activity. It is the optimum solution for homes, families, small and middle offices, as well as big companies with the need to monitor hundreds of employees. Elite Keylogger is driver mode low kernel Keylogger.

It did not record anything I was typing when I used key scrambler. Once I turned off keyscammbler it recorded just fine. So that is one example of keyscrammbler defeating a low kernal mode driver based keylogger.

During the video I also accidnetly got tong tied and called keyscramber keylogger.... OOPS!

For best results watch this video in HD

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Anthropic pulls Fable 5 and Mythos 5 after US export control order by Pradeep Viswanathan In April this year, Anthropic launched the Claude Mythos Preview frontier model with state-of-the-art cyber and coding capabilities for a select set of companies around the world. After preparing appropriate guardrails, early this week, Anthropic launched Claude Fable 5 and Mythos 5, its most capable AI models. Claude Fable 5 is for general users and comes with strict safeguards, while Mythos 5 is designed with fewer safeguards for cybersecurity and biology use cases. Today, Anthropic abruptly suspended access to its Fable 5 and Mythos 5 AI models for all customers after receiving an export control directive from the US government. The company received the directive from the government today at 5:21 p.m. ET, and the received letter did not provide any details regarding the national security concern. Anthropic understands that the government became aware of a method to bypass, or “jailbreak,” Fable 5, which might be the reason behind the directive. The order was issued under national security authorities and requires the company to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether they are inside or outside the United States. The restriction also applies to foreign national employees working at Anthropic. As a result, the company has disabled both models for all customers to ensure compliance. Access to previous Anthropic models like Opus and Sonnet is not affected by this government order. The company highlighted that it had developed strong safeguards to reduce the possibility that Fable is misused for tasks related to cybersecurity. In fact, many developers are complaining that the safeguards are going overboard. Additionally, the company worked with the US government, the UK AISI, multiple private third-party organizations, and internal teams to red-team Fable’s safeguards for thousands of hours. Finally, Anthropic noted that no testers have yet been able to find a universal jailbreak on Fable 5. As expected, Anthropic disagrees that a narrow potential jailbreak should lead to the recall of a commercial model used by hundreds of millions of people. It warned that applying this standard across the AI industry could effectively halt new frontier model deployments. Anthropic concluded by mentioning that it is working to restore access to Fable 5 and Mythos 5 as soon as possible and plans to share more details within the next 24 hours.
    • Brave Browser 1.91.172 is out.
    • Any Video Converter Free 9.2.3 by Razvan Serea Any Video Converter is an All-in-One video converting tool with an easy-to-use graphical interface, fast converting speed and excellent video quality. Any Video Converter supports all popular video formats and converts your videos to different video formats including MP4, MOV, MKV, M2TS, M4V, MPEG, AVI, WMV, ASF, OGV, WEBM, and more. It supports converting videos to customized percent (50%, 100%, 200%, and more) or resolution (480p, 720p, 1080p, 4K, and more); It supports encoding videos into x264, x265, h263p, xvid, mpeg, wmv, and more. Any Video Converter Free key features: Compatible with Windows 11/10/8.1/8/7 (32-64bit) User interface are available in 14 languages Convert all kinds of video formats including high-definition videos Extract audio from any videos and save as MP3/WMA for your mp3 player Take snapshot from any videos and build your own picture collection Support high-definition for both input and output Batch add videos from hard drive and batch convert Customize output parameters completely as you like Manage your output videos files by group or output profile Merge several video files into a single and long one Clip a video into segments Free Audio Filter: Adjust audio volume and add audio effects Crop frame size to remove black bars and retain what you want only Adjust the brightness, contrast, saturation Rotate or flip or add noise/sharpen effects Produce output video with subtitles of your own dialogue and much, much more... Any Video Converter Free 9.2.3 changelog: Fixed video download engine auto-update failures. Added custom speed control support in the speed change tool. Added support for downloading YouTube AI-generated subtitles. Added support for preserving original audio stream in the format convert tool (e.g., Dolby Atmos, DTS:X). Fixed other bugs and improved overall performance. Download: Any Video Converter Free 9.2.3 | 7.6 MB (Freeware) View: Any Video Converter Free Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Not sure what country you’re in but in many countries you can absolutely jail the sellers behind businesses… in fact I’d say in most countries you can do that
    • I guess we are done since you refuse to read my comment you replied to or my other comment in another thread you were also a part of here.
  • Recent Achievements

    • Dedicated
      jordanspringer earned a badge
      Dedicated
    • Rookie
      Rimplesnort went up a rank
      Rookie
    • One Year In
      Markus94287 earned a badge
      One Year In
    • One Month Later
      Markus94287 earned a badge
      One Month Later
    • Week One Done
      Markus94287 earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      505
    2. 2
      +Edouard
      175
    3. 3
      PsYcHoKiLLa
      155
    4. 4
      ATLien_0
      90
    5. 5
      Steven P.
      79
  • Tell a friend

    Love Neowin? Tell a friend!