App Review Crystal Security 2014 (Manzaitest)

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
R

Ray Redbad

Thread author
Win7 Home Premium SP1 x64, user's account as admin
CS 3.2.0.86

Hi Kardo. Thanks for offering your product as freeware.

But it is in serious need of documentation!
Check on Malware mode; Intrusion Detection mode; Paranoid Companion mode??

Upon first run, I permitted my firewall to build an allow-all rule but there was nothing downloaded and the connection closed shortly thereafter.

I see where some data is built in a user's Roaming\Crystal Security folder with all of ~200 bytes in 10 objects.

That remained mostly unchanged after running a Paranoid Mode Advanced Checkup on about 18700 items, during which there were no outbound connections made. (Yes, Cloud: Connected.) Nor was anything presented in Overview or added to the White/Black lists.

Is there another area I can't find where a database and/or cache are stored?
Where?
Without such how exactly did Advanced Checkup do a... checkup?
And what did it do?
I'm seeing system32 objects being queried (taskeng, sppsvc, mmc) though one would expect that in a paranoid mode - that has not had 18700 objects scanned.
If, for example, somehow the whitelisted mmc was modified, maliciously or otherwise, would there be an alert?

Those system32 and some other objects have been queried and classified via port 443 hits to a google hosted service. So, that works quite nicely. :)

Once all that was done, in "Paths to monitor" I decided to add C:\Windows, C:\Users, D:\Downloads (the default for all apps that can download) and E:\ (where pointed are system and user TEMP and TMP variables as well as some application's temp and cache). I don't need the "entire computer" profiled.

I see when Intrusion Detection mode is selected there are three default paths (with E:\UserTEMP detected OK) but when I add others, they vanish upon an Apply. When I return to Paranoid Companion mode my paths are gone with the paths data from Intrusion Detection mode remaining. I believe there is a bug in your Areas.cs file handling or it needs improvement.

That Areas.cs issue aside, what is the difference between the Paranoid Companion and Intrusion Detection modes where the paths to monitor are populated exactly the same for each?

What is the maximum value that can be entered for Notification Duration?
1200 seems to work OK so far. I'd like to see separate timings for each notification so I could set a few seconds for an Always allow and much longer times, better yet a "forever" option, for the others.

Looking forward to the beta. Cheers.
 
Last edited by a moderator:
  • Like
Reactions: Kardo Kristal
R

Ray Redbad

Thread author
Well, I decided to start from scratch by deleting the Roaming folder and letting CS build a new one.

Even though I have, in Paranoid mode, these paths in Custom...
E:\
D:\Downloads
C:\Users
...there continue to be classifications/whitelists for C:\Windows\system32 (Notepad!), apps I have running from C:\Portables (Firefox) and even from a TruCrypt container, M:\ThunderbirdPortable.

As well, even though I have Upload unknown disabled and Uploads:0, an Upload.cs appeared with entries for several apps.

I suppose I just don't understand how your product works, so I'm just going to set it aside for now. And I've been using security apps for over 20 years and at this stage in my life, if the app isn't intuitive or acts against settings (or has no docs/help), I bow out.

I'll give the beta a look-see when you release it.

Thanks again.
 

Kardo Kristal

From Crystal Security
Verified
Top Poster
Developer
Well-known
Jul 12, 2014
1,143
@Ray Redbad

Hi, Thank you for your detailed feedback.
But it is in serious need of documentation!
Check on Malware mode; Intrusion Detection mode; Paranoid Companion mode??

Based on your valuable feedback, I decided to make some changes in Protection settings. I'll replace Protection levels with Analysis mode - In the next Beta user is able to choose what kind of files will be monitored and analyzed:

1. Created objects
2. Modified objects
3. Active processes
4. Autoruns
Is there another area I can't find where a database and/or cache are stored?
Where?
Without such how exactly did Advanced Checkup do a... checkup?
And what did it do?
I'm seeing system32 objects being queried (taskeng, sppsvc, mmc) though one would expect that in a paranoid mode - that has not had 18700 objects scanned.

All files processed via Checkup module will be checked with Internal database.. only suspicious and unknown files will be checked with cloud database. Internal database is integrated into executable file, so it is currently invisible for the user.
If, for example, somehow the whitelisted mmc was modified, maliciously or otherwise, would there be an alert?
Hmm, good point! Currently all whitelisted/blacklisted files will be skipped automatically to increase performance.
Once all that was done, in "Paths to monitor" I decided to add C:\Windows, C:\Users, D:\Downloads (the default for all apps that can download) and E:\ (where pointed are system and user TEMP and TMP variables as well as some application's temp and cache). I don't need the "entire computer" profiled.
Unfortunately multiple drives support is not yet available. I'll try to add this features in the next Beta version.
What is the maximum value that can be entered for Notification Duration?
1200 seems to work OK so far.
Another good point. :D - there is no limit at the moment (will be added).
I'd like to see separate timings for each notification so I could set a few seconds for an Always allow and much longer times, better yet a "forever" option, for the others.
Good suggestion. Thanks!

I'll try to make Crystal Security more understandable and easier to use for users. :)

Regards,
Kardo
 

Kardo Kristal

From Crystal Security
Verified
Top Poster
Developer
Well-known
Jul 12, 2014
1,143
Hello,

Made some changes in the next Beta (based on users feedback).

1. Possibility to choose what type of activity will be tracked and checked.

* Created objects
* Modified objects
* Active processes
* Autoruns

- It is possible to enable/disable each type of activity.
- Active processes module is fully updated - better monitoring and performance.
NB! Please note that Admin rights is required to track Active processes.

2. New feature: Trust applications with digital signature

- Enabled: all files with valid signatures will be added permanently to Whitelist without notification.
- Classification for files with valid signature: Safe [signed].
- Permanently means that internal and cloud check was skipped automatically.

3. Moved location of "Unknown files: Upload" option.

Preview screenshot of Protection settings:

protection-settings-png.17769


Regards,
Kardo
 

Attachments

  • Protection-settings.png
    Protection-settings.png
    35.3 KB · Views: 588

Kardo Kristal

From Crystal Security
Verified
Top Poster
Developer
Well-known
Jul 12, 2014
1,143
Hi,

Some information.

The next BETA version comes with installer.. ("next", "next", "next" and done). ;)
Shortcut will be created automatically so user is able to start program via desktop shortcut.
Main executable will be in Program Files\Crystal Security\ and program is listed under Add/Remove programs list (for easy removal).

There is a portable version as well as the addition.

Regards,
Kardo
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top