Hi
Plz move to correct topic if wrong
and I apologies if this has all ready been covered here
I have just downloaded and tested the spyshelter anti-keylogger/screen grab test http://www.spyshelter.com/
CIS 5.12 AV did detect the download (I reported as a FP) CIS kept quiet after this
all the tests failed -screen grab
copy clipboard
key strokes
webcam
I’m sure I’m missing something here 88)
is the fail due to me reporting this as a FP initially ?
Test applications such as this are not suitable for whitelisting. Also, it is common practice to detect them as a potentially dangerous application. I believe that this is in case they were installed on your computer without your being aware.
It is NOT a common practice. Just 3 (including comodo) out of 46 in virustotal treat it as bad file. Nearly all common AVs do not detect it as malware. I find Comodo like to treat this kind of test files as malware to avoid testing to be performed by end users. >:(
Don’t play with wordings. My major point is that Comodo like to bad listing this kind of testing files such that users are hard to perform the tests. This is NOT common for the other scanners to bad listing the files.
I seriously doubt that somebody who wants to use a leaktest of some sort (somebody with a more than average interest in computer security) will be put off by that.
They do this for the express purpose that files like this are used to test your security application!
If Comodo whitelists these types of files, guess what? The tests will fail because CIS will trust the application and it will be able to do whatever it wants to do to the users system.
So doesn’t it make more sense to give the user an alert that Comodo knows that this is a leaktest file, and let the user proceed with the test instead of allowing the file to run unhindered and thus fail the test?
Have you seen request to add CLI test to trust file?
I have never seen such requests but I do remember there are requests to exclude those tester files in bad list in the forum.
I do reported some FPs in the past but I can’t sure if any tester files are reported.
Anyway, the AntiTest.exe file had already been reported as FP as mentioned in previous replies by other members a week ago but I still find it included in Comodo’s bad list.