Keyscrambler - Encrypt your Keystrokes


Recommended Posts

Keyscrambler - Protect your personal information from keyloggers

http://www.qfxsoftware.com/

Give keyloggers the finger.

"There is a 1 in a 1,000,000 (or more) chance that today you will be shot with a gun. Wouldn't it be great to be wearing a Kevlar vest on THAT day??"

Today I'm going to review a nifty little program called "Keyscrambler". I remembered hearing about this application a while ago and I even tried it out. Today someone referenced it in a "Keylogger Remover" thread. He was recommending it as a preemptive measure for 'next time'. That got my interest sparked again so I looked into it. I ended up buying the Premium Version. This may have been an impulse buy, but it's one of those applications that it will never hurts to have.

As you all know a keylogger is an application that runs on your system for the sole purpose of capturing all the keystrokes the user inputs (or inputs via other means) into the computer.

It's thru these types of applications that the hackers are able to steal confidential information when it is entered into a the web browser (other than phishing sites of course).

Most of the time, an Anti-virus and/or Anti-malware application will detect and remove a keylogger from a computer, but it just has to miss one once. I know that most of us think that we will never fall victim to a keylogger. We would have to be stupid, right? I think we are all smart enough not to fall for a fake antivirus ad, BUT what about a vulnerability via a 3rd party browser add-on? It could happen. Enter now the Keyscrambler.

Keyscrambler works at the keyboard driver level of the kernel (or as low as Microsoft will let it work on 64bit Windows). There is a 32bit and 64bit version. I'm running it on Windows 7 - 64bit without issue. As you start typing on the keyboard, the data gets encrypted. The entire path is encrypted, from the moment a key is pressed on the keyboard, until it reaches the box it was intended for. Once it reaches the intended location, the information is then decrypted.

A keylogger running on the system between the keyboard and the destination will just see encrypted gibberish. (Example of FL:KJERERLEJR:F)

Keyscrambler supports a plethora of applications. It has to support the application before it can encrypt the data entered into it. I found that it supports every web browser imaginable as well as all the popular email clients, IM messengers, accounting software, office software and more. Certain things that it does not encrypt would be something like the run box, but how often are you really entering your credit card information into the Windows run box?

As you type into a supported application a long green box appears in the corner of the screen. It shows you the encrypted output of what you are typing. If you prefer not to use the green bar, you can use a tray icon instead.

tpying.jpg

There are 3 versions of the application.

First, there is the Free Version. It supports IE and Firefox, Flock and that's it. If you use any other web browser you are out of luck.

Next is the Pro Version $29.99 - This supports IE and Firefox as well as all the other web browsers. It also supports Email clients, IM/ VoIP, Password Managers (including but not limited to Roboform), Zip applications, Text Editors, Music apps and Online games.

Finally we have the Premium Version $44.99. This one supports everything mentioned above. It also supports a few additional type of applications. Office, Finance, Tax, Accounting (Like QuickBooks), Networking, Encryption, File Managers and Windows log-in. A complete run down of the applications covered by the assorted versions is available on the company's website.

There is no monthly fee and its just a 1 time fee with free lifetime updates. Once you install the program you use your email address and your Product Key to show you bought the application. It does require the internet to validate. Though it doesn't look like it does any sort of activation. It just makes sure that the Product Key matches the email address.

To check out the functionality, I installed an antikeylogger tester. I had it test how well keyscrambler protected against a low level keyboard hook. I told it to record and started entering my login name and password into the Neowin.net sign in page via Firfox. Once I was finished I checked the antikeylogger tester and all I saw was gibberish, Hooray!!

keyloggertest.jpg

That's really all there is to say about this application. There aren't a lot of features. All it does is encrypt data entered into the computer so that keyloggers can't see it.

A video showing how keyscrambler does against a low-kernal mode keylogger.

For best results watch this video in HD

Edited by warwagon
Link to comment
https://www.neowin.net/forum/topic/835718-keyscrambler-encrypt-your-keystrokes/
Share on other sites

Good idea if it really does what it says, however the prices for the pro/premium versions are way too high. I would have said $9.99 for pro and it should work with all apps including Office etc. No way would I pay $45, and can't imagine many others doing so.

Just looked at their site and it's $12.99 to upgrade pro to premium, so it's cheaper to buy pro + the upgrade than premium, whacky pricing!

Remember if you use Roboform then there are no key presses to log, I assume that would be true for the other password managers.

Edited by m.keeley

Pretty stupid that you have to pay just to use it in other browsers, I am sick of everyone assuming that the entire world either uses IE, or Firefox (flock is a pretty strange choice given that its market share is even lower than Opera's). Also, a good idea, but I think the price is overkill given that being hijacked by keyloggers is pretty rare nowadays where most details are stolen through phishing.

Pretty stupid that you have to pay just to use it in other browsers, I am sick of everyone assuming that the entire world either uses IE, or Firefox (flock is a pretty strange choice given that its market share is even lower than Opera's). Also, a good idea, but I think the price is overkill given that being hijacked by keyloggers is pretty rare nowadays where most details are stolen through phishing.

Agreed. Will I ever use it? Doubtful. But cool product nonetheless.

If you use IE or Firefox, then it doesn't hurt to have the freeware version. It doesn't run any background processes, and you can configure it to show a tray icon instead of the annoying green bar.

Don't assume this is "a step ahead" of the bad guys.

A lot of keyloggers that are developed take this into consideration and are Anti-Keyscrambler and other stuff!

Might work against the older stuff (that newbies use)

:) No problem.

So which keyloggers do you know of that can get around keyscramblers? Care to give any examples or quote the source of your information?

Edited by warwagon
Man...this is for paranoid people.

I know of a certain person that has nearly a million dollars in trade accounts and online banks. If this person uses a program like keyscrambler to protect their investment accounts in the event a keylogger ever got installed, then would you still call them paranoid?

Edited by warwagon
I know of a certain person that has nearly a million dollars in trade accounts and online banks. If this person used a program like keyscrambler to protect their investment accounts in the event a keylogger ever got installed, would you still call them paranoid?
Yes. A person that worried about it would be using a nonce keyfob or some other form of 2-factor authentication. Furthermore, that person would never be using an untrusted workstation for online banking.

My wife and I have accounts with that much money in them and I wouldn't think about using a bank that allowed those funds to be transferred without some sort of reliable verification. Most of the banks and investment firms I use won't even allow notarized letters for common mail-based communication.

Also, I'd be interested if anyone has seen an analysis of Keyscrambler. What warwagon posted looks a lot like a brochure advertisement to me. Everything you get from a Google search is the same self-serving advertisement. Plus there's no information on how the software actually works (though it probably actually works very similarly to most keyloggers by installing a global hook for the keypress event). Any malware running with admin access could theoretically get your keystrokes, since the destination application must access them as well. All of these are hallmarks of a bogus application that simply gets marketed well.

A keylogger could probably do an API call to GetWindowText and it'd be as simple as that for any targeted application. It would be a trivial matter to search for password fields in browser html and do the same thing with the Windows API.

Edited by boogerjones
Man...this is for paranoid people.
If there was an open-source anti-keylogger product that had been independently tested for security vulnerabilities, I would happily give my money to its parent company. Untrusted workstations are a significant threat and keyloggers are the easiest way to get private information. Phishing scams only work on old ladies and other people who know nothing about technology.
If there was an open-source anti-keylogger product that had been independently tested for security vulnerabilities, I would happily give my money to its parent company. Untrusted workstations are a significant threat and keyloggers are the easiest way to get private information. Phishing scams only work on old ladies and other people who know nothing about technology.

agreed

i use SSH tunnels and stuff to avoid information leakage, this just protects from another type of leakage

KeyScrambler will protect you against the majority of keyloggers, but it is far from fool proof.

I think the only way a true keylogger could bypass KeyScrambler is to install a system driver. Even with UAC disabled, Windows should still prompt you before installing an unsigned driver.

But there are far simpler ways to bypass KeyScrambler:

- Install a plugin into the web browser to capture the keystrokes after they're decrypted.

- Or even simpler, just disable the KeyScrambler plugin, though you might notice the green bar is gone.

Heck, if you start IE InPrivate Browsing, it disables all addons including KeyScrambler.

But as I said before, it will protect you against the majority of keyloggers.

Heck, if you start IE InPrivate Browsing, it disables all addons including KeyScrambler.

Incorrect.....sorta

The personal version runs as an extension in IE. The paid versions do not. Same for firefox.

inprivatev.jpg

Edited by warwagon
Yes. A person that worried about it would be using a nonce keyfob or some other form of 2-factor authentication. Furthermore, that person would never be using an untrusted workstation for online banking.

Define untrusted. The person I was referring to is using their own machine not some random PC at some persons house, they have no control over. By Trusted workstation are you referring to a pc that is just for doing online banking and nothing else?

  • 2 weeks later...
  • 2 weeks later...
So which keyloggers do you know of that can get around keyscramblers? Care to give any examples or quote the source of your information?

These fancy "key scramblers" indeed work against two types of key-loggers:

- those using passive methods for recording keystrokes (making use of API like GetAsyncKeyState() or GetForegroundWindow()... ).

- and also those hooking API function calls (thus intercepting keyboard events).

However, none of those fancy scramblers stand a chance against two types of widely known and used key-loggers:

- Those implemented as part of a kernel-level rootkit. They act as the keyboard driver, and have low level access to the hardware itself.

- those implemented in a malware hypervisor. Those have more privileges than the OS Kernel itself.

All in all, those so called keyscramblers would have done a very good job 10 years ago, not now.

Well I thought I would test it

I downloaded keyscrambler premium in a vm along with Elite Keylogger

http://www.widestep.com/

Elite Keylogger works in low-kernel mode as a driver-based monitoring software recording every detail of PC and Internet activity. It is the optimum solution for homes, families, small and middle offices, as well as big companies with the need to monitor hundreds of employees. Elite Keylogger is driver mode low kernel Keylogger.

It did not record anything I was typing when I used key scrambler. Once I turned off keyscammbler it recorded just fine. So that is one example of keyscrammbler defeating a low kernal mode driver based keylogger.

Web of Trust is saying that widestep.com is very untrustworthy. Are you sure you didn't actually install a keylogger instead of a keylogger prevention? :)

EDIT: Durr... widestep is where you did get the keylogger from. :)

Yep if you read some of the comments on the score card of WOT it says they make key loggers lol.

Right now i'm in the process of making a video I will put on youtube, just in case someone doesn't believe me.

Ok here is the video. As i'm posting this yotuube is still improving the quality of the video. So by the time you read this it will probably be HD.

THis video is of the test I mentioned above.

Well I thought I would test it

I downloaded keyscrambler premium in a vm along with Elite Keylogger

http://www.widestep.com/

Quote -

Elite Keylogger works in low-kernel mode as a driver-based monitoring software recording every detail of PC and Internet activity. It is the optimum solution for homes, families, small and middle offices, as well as big companies with the need to monitor hundreds of employees. Elite Keylogger is driver mode low kernel Keylogger.

It did not record anything I was typing when I used key scrambler. Once I turned off keyscammbler it recorded just fine. So that is one example of keyscrammbler defeating a low kernal mode driver based keylogger.

During the video I also accidnetly got tong tied and called keyscramber keylogger.... OOPS!

For best results watch this video in HD

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • A group made up of dozens of cybersecurity experts, including several well-known veterans of the industry, published an open letter to the U.S. government asking it to lift the export control order on Anthropic’s Fable and Mythos models. According to the open letter, “this action has taken the best models away from [cybersecurity] defenders” who now can’t use the models to find vulnerabilities and make their software and products more secure. “To pull the best capabilities away from defenders without a good reason when our adversaries are rapidly advancing is dangerous,” read the letter. On Friday, the U.S. government ordered Anthropic to limit the export of Fable and Mythos, citing national security concerns, without explaining the specific reasons behind the order, according to Anthropic. In response, the company suspended access to the models to all users worldwide.     https://techcrunch.com/2026/06/15/cybersecurity-vets-protest-dangerous-us-government-ban-on-anthropics-most-powerful-models/
    • Vivaldi 8.0.4033.48 by Razvan Serea Vivaldi is a cross-platform web browser built for – and with – the web. A browser based on the Blink engine (same in Chrome and Chromium) that is fast, but also a browser that is rich in functionality, highly flexible and puts the user first. A browser that is made for you. Vivaldi is produced with love by a founding team of browser pioneers, including former CEO Jon Stephenson von Tetzchner, who co-founded and led Opera Software. Vivaldi’s interface is very customizable. Vivaldi combines simplicity and fashion to create a basic, highly customizable interface that provides everything a internet user could need. The browser allows users to customize the appearance of UI elements such as background color, overall theme, address bar and tab positioning, and start pages. Vivaldi features the ability to "stack" and "tile" tabs, annotate web pages, add notes to bookmarks and much more. Vivaldi 8.0.4033.48 changes: [Chromium] Update to 148.0.7778.267 ESR (includes security fixes from 149.0.7827.114/115) [Crash] When closing devtools with input caret in a CSS property field (VB-128998) [Linux][Media] Fetch an updated proprietary media support file (VB-129132) [Permissions] Global Permissions counter shows all permissions (64) as overridden (VB-127713) Download: Vivaldi 64-bit | 139.0 MB (Freeware) Download: Vivaldi 32-bit | ARM64 View: Vivaldi Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Two variants of the KAMRUI H2 mini PC receive deeper discounts on Amazon by Steven Parker KAMRUI (sister company of AceMagic) reached out to us, letting us know that they are applying further discounts to two of their H2 mini PC variants, and in times like these, every little helps. First off, it's the Core i5 14450HX 32GB+1TB variant, which already received a discount from $699 to $567.99 on Amazon, so you may be asking what you get for that. Its most important features are listed below. 32GB Memory Configuration, Exceptional Value. Driven by rising AI demand, the DDR memory supply is tightening, making high-capacity memory more valuable. KAMRUI maintains high-quality standards while offering strong value with a 32GB RAM + 1TB SSD configuration, which delivers excellent performance and storage. Intel i5-14450HX, HX-Class Performance Powered by the Intel Core i5-14450HX (10 cores/16 threads, up to 4.8GHz, 54W TDP)-HX series delivers desktop-class performance. Enjoy up to 120% higher multi-core performance vs. i7-1185G7 and stronger sustained performance than Ryzen 9 6900HX under heavy workloads. With 14450HX performance, it handles coding, compiling, Docker with ease, runs 10+ apps simultaneously—Excel, Chrome, Zoom, video editing—with smooth multitasking and fast load times. 32GB RAM & 1TB NVMe SSD - expandable up to 4TB Mini pc W-11 Pro equipped with 32GB (16GB×2) DDR4 dual-channel memory and a 1TB NVMe PCIe 4.0×4 SSD, mini pc delivers fast system response and efficient data access for demanding workloads. Dual M.2 slots support storage expansion up to 4TB. Large memory support running multiple virtual machines simultaneously, enabling fast deployment and isolated sandbox testing, significantly improving development efficiency and multitasking performance. HX-Class Heat Dissipation, Higher Productivity 14450HX Mini computers W-11 pro equipped with upgraded silent centrifugal fans, dual copper heat pipes, dual fin-stack cooling modules, and an optimized dual-airflow design, the processor can maintain ≥95% of multi-core performance even under long-duration heavy workloads. The HX platform is specifically designed for multitasking, rendering, and content creation, and multitasking, delivering desktop-class stability and powerful performance. Triple 4K Productivity Power Supports triple 4K displays and handles complex workflows like coding, data processing, and multitasking with ease. WiFi 6 delivers fast, reliable connectivity for video, conferencing, and transfers. Bluetooth 5.2 ensures stable, low-latency wireless connections. Versatile Connectivity This mini computer comes with 1x Type-C(10Gbps data transfer), 1x RJ45 Ethernet, 2x USB3.2 Gen2 (10Gbps), 4x USB3.2 Gen1 Type-A (5Gbps), PD output, 1x HDMI 2.0, 1x DP 1.4, and 1x 3.5mm audio jack. It offers versatile connectivity to connect multiple devices effortlessly, reducing the need for frequent plugging and unplugging. Small Size, Big Performance Mini PC measures just 5.04 × 5.04 × 1.63 inches, over 80% smaller than a traditional desktop, yet equipped with the high-performance 14450HX processor for near-desktop-level power. With VESA mounting support, it transforms cluttered desks into clean, organized setups. Normally costing $699, but now down to $ 535.79, which includes an additional 6% off the Amazon listed price. That equals a total of 24% off the MSRP. KAMRUI Hyper H2 (Core i5 14450HX 32GB+1TB) for $ 535.79 (was $699) Use code 2UD2IW7D for the above price during checkout (expires on June 30) Editors note: This appears to be listed as a "frequently returned item" on Amazon, but you should take into account the reviews on the page that discuss a completely different PC, it would seem that this is yet another recycled sales page that is now listing this newer item, possibly to retain the positive 4.5 star rating on the page. Next up, we have the Core i9 14900HX/32GB+1TB variant, which normally costs $799.99 but is already discounted to $759.99 on Amazon. Again, the most important highlights for this variant are listed below. Upgrade 14th Intel Core i9-14900HX Processor KAMRUI Mini Computers features the 14th Gen Intel Core i9-14900HX processor (up to 5.8GHz, TDP 55W, 36MB cache, 24C/32T), delivering 25%–40% higher performance than the i5-14450HX (24C/32T) and i7-1280P in multitasking, creative work, and high-load applications. Manufactured using Intel 7 (10 nm) process technology, Mini Computer efficiently allocates workloads to deliver faster response times, smoother operation, and heightened productivity. 32GB DDR4 & 1TB SSD - Expandable to 4TB KAMRUI Intel Core i9-14900HX mini PC features dual-channel 32GB DDR memory (expandable to 64GB) and 1TB NVMe PCIe 4.0×4 SSD, delivering speeds 40% faster than PCIe Gen3. The KAMRUI Micro PC features two M.2 2280 SSD slots, each expandable up to 2TB, effortlessly accommodating a high-capacity system drive and an ultra-fast cache drive. This achieves a perfect balance of speed, capacity, and flexibility, effortlessly handling large projects and high-speed workflows. 4K UHD Triple Display KAMRUI 14900HX Mini PC features a 4K@60Hz UHD graphics card (Intel UHD Graphics), supporting 4K@60Hz high-definition video playback for a premium visual experience. Mini Gaming PC incorporates an HDMI 2.0 port + DP 1.4 port + USB3.2 Gen2 Type-C port, supporting 4K triple display output. Mini PC can connect to three monitors to fulfil your multi-screen collaboration requirements. Ultra-high-definition visuals and ultra-fast connectivity significantly enhance your productivity. RJ45 LAN Port+WiFi6E+BT5.2 KAMRUI Mini PC features a 1.0Gbps LAN port, suitable for high-speed broadband environments in homes, offices, and large enterprises. Bluetooth 5.2 enables connection to peripherals such as headphones, mice, and keyboards. Dual-band WiFi 6E and BT 5.2 deliver enhanced interference resistance and more stable wireless signals. Regardless of your network environment's complexity, the KAMRUI H2 mini computer delivers a relatively stable and smooth network experience. Professional-Grade Cooling System KAMRUI Mini gaming PC features an upgraded silent centrifugal fan, dual copper heat pipes, and a dual-fin module. Its all-copper structure enhances thermal conductivity, boosting airflow efficiency by 35% and overall heat dissipation by 40%, ensuring the CPU can stably deliver up to 55W performance under full load. Upgraded aluminum heatsink keeps the SSD cool to maintain read/write speeds, ensuring desktop-level stability and power for demanding workloads. Compact Size, Infinite Possibilities KAMRUI H2 mini computers measure just 5.04 x 5.04 x 1.63 inches, a fraction of the size of a traditional desktop, yet deliver powerful performance for demanding workloads. With the included VESA mount, you can easily attach a small pc behind a monitor or place it in your TV cabinet, turning your display into a sleek mini PC while saving valuable desk space. Versatile Connectivity This KAMRUI mini gaming computer comes with 1*USB3.2 Gen2 Type-C(up to 10Gbps data transfer), 1*RJ45 Ethernet, 2*USB3.2 Gen2 (10Gbps), 4*USB3.2 Gen1 Type-A (5Gbps), 1*HDMI 2.0, 1*DC, 1*DP 1.4, and 1*3.5mm audio jack. It offers versatile connectivity to connect multiple devices effortlessly, reducing the need for frequent plugging and unplugging. Normally costing $799, but now down to $721.99, which includes an additional 5% off the Amazon listed price. That equals a total of 10% off the MSRP. KAMRUI Hyper H2 (Core i9 14900HX/32GB+1TB) for $ 721.99 (was $799) Use code AQ5Z6A47 for the above price during checkout (expires on June 30) KAMRUI claims that they offer lifetime technical support along with a 12-month warranty. For either of these mini PCs, should you encounter any issues during use, KAMRUI claims it will do its utmost to assist customers. As an Amazon Associate, we earn from qualifying purchases.
    • Good. I hope more people sue them for focusing on this worthless junk.
  • Recent Achievements

    • One Year In
      Console General earned a badge
      One Year In
    • One Year In
      Twozo Technologies earned a badge
      One Year In
    • One Month Later
      Twozo Technologies earned a badge
      One Month Later
    • Week One Done
      Twozo Technologies earned a badge
      Week One Done
    • Veteran
      branfont went up a rank
      Veteran
  • Popular Contributors

    1. 1
      +primortal
      513
    2. 2
      +Edouard
      201
    3. 3
      PsYcHoKiLLa
      108
    4. 4
      Steven P.
      89
    5. 5
      Nick H.
      71
  • Tell a friend

    Love Neowin? Tell a friend!