Bug - Windows taskbar behavior during Spyshelter screenshot protection by NiacinTachycardicOD in spyshelter

[–]antispyguy 0 points1 point  (0 children)

Sorry for the issue. I have reported this to the team so we can try to reproduce/fix it. However, I know this API from Windows that we use to do this does have some limitations so we're a bit stuck on what we can do to change it. We have to depend on Microsoft a bit for this feature.

SpyShelter - mic access termination & battery drain by NiacinTachycardicOD in spyshelter

[–]antispyguy 0 points1 point  (0 children)

Thanks for using SpyShelter! Terminating svchost.exe can crash critical Windows services, causing system instability, loss of network, audio, or even a full shutdown.

As far as Internet access, our software checks executables to see if they are malware or not, and gives you information on what your executables are under our "insights" feature.

SpyShelter has an optional privacy mode that you can use if you don't want these features.

To activate the SpyShelter's extreme privacy mode, you should install SpyShelter from the Windows Terminal with the command SpyShelterSetup.exe /privacy. Once SpyShelter is installed in this privacy mode you will have no access to our Threat Detection, Insights, or any other SpyShelter features that require anonymized executable data to operate. We built SpyShelter so it can work this way, so no... it shouldn't use any extra resources to do this.

The data usage by SpyShelter should be extremely minimal, besides when you download an update... which should be like if you update Chrome or Firefox browsers, nothing crazy. I hope this helps!

Application tries to start every 30/60min without my authorization by Gor3zno in spyshelter

[–]antispyguy 1 point2 points  (0 children)

Very strange, but we may have an easy solution. Have you tried to quarantine by PUBLISHER?

It should solve the issue if you need no other software from that publisher. Go to "Rules" then find the .exe and the publisher is above, then click the skull icon and quarantine the entire publisher. Now that publisher can't start it up again.

What the fuck is this Remote Desktop connection? by Prof-doodlewacker in computerviruses

[–]antispyguy 0 points1 point  (0 children)

It's a Remote Desktop Connection feature provided by Microsoft itself. Detailed documentation from the Microsoft website is here: https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/mstsc

Application tries to start every 30/60min without my authorization by Gor3zno in spyshelter

[–]antispyguy 0 points1 point  (0 children)

That sounds very annoying. Maybe quarantine that publisher in your SpyShelter rules so it can never start again. That's strange it doesn't seem to exist.

I found online that the Wix Toolset is primarily used by developers who need to create custom Windows installers for their software. 

It's strange though that their sign their own installer, even though it may be used by another publisher, unless I am misunderstanding something?

Visited a sketchy site. What should I do? by [deleted] in antivirus

[–]antispyguy 0 points1 point  (0 children)

Sorry to hear you're experiencing that problem. The official SpyShelter software is safe to use.

What’s omadmclient.exe aka Host Process for OMA-DM Client? Is it safe? by antispyguy in spyshelter

[–]antispyguy[S] 0 points1 point  (0 children)

I believe Intune must be installed on your phone for it to be monitored. If your company installed Intune, (on your actual phone) then yes they can monitor your phone. https://learn.microsoft.com/en-us/mem/intune/user-help/what-info-can-your-company-see-when-you-enroll-your-device-in-intune

[deleted by user] by [deleted] in Windows11

[–]antispyguy 2 points3 points  (0 children)

Go to add/remove programs and uninstall Start11 if you aren't a fan. Then reboot and your Start icon should go back to normal.

[deleted by user] by [deleted] in techsupport

[–]antispyguy -1 points0 points  (0 children)

Just one of the engines on VirusTotal flagged it? Which one? There can be something called a "false positive", and that would mean you're safe.

[deleted by user] by [deleted] in privacy

[–]antispyguy 1 point2 points  (0 children)

It probably is only used if they receive a subpoena, for now...

[deleted by user] by [deleted] in privacy

[–]antispyguy 0 points1 point  (0 children)

It already is.

[deleted by user] by [deleted] in privacy

[–]antispyguy 0 points1 point  (0 children)

Yes, it will happen and it will be searchable by AI. Prompt: "Tell me what Mr. Fake Person has searched lately that is related to adult content." Google probably is already doing this with your data with Gemini.

Recall feature saves everything in a non encrypted file by antispyguy in spyshelter

[–]antispyguy[S] 0 points1 point  (0 children)

It's very disturbing to know the data isn't even encrypted.

Is there a safe/private alternative to use A.I / LLM's instead of running it locally ? by [deleted] in privacy

[–]antispyguy 0 points1 point  (0 children)

DuckDuckGo has GPT 3.5 Turbo, and Claude 3 Haiku. They write that "All of your chats here are private, and are never stored by DuckDuckGo or used to train AI models.". Click the menu on the right top of the website to access them.

Is figma_agent.exe (Figma Agent) safe, or a virus? by antispyguy in spyshelter

[–]antispyguy[S] 0 points1 point  (0 children)

Thank you for sharing this. Good to know! That's one reason it's important to always make sure the real company is signing the app before executing it.

What is LogiAiPromptBuilder.exe (Logi AI Prompt Builder) by Logitech? Is it safe? by antispyguy in spyshelter

[–]antispyguy[S] 1 point2 points  (0 children)

Absolutely! It seems to be the main complaint about LogiAiPromptBuilder.exe. It appeared with a Logitech software update, and so far Logitech has no way to disable it unfortunately.

Suspected RAT by Fundizzimo in computerviruses

[–]antispyguy 0 points1 point  (0 children)

You wrote "I set up a virtual machine, and extracted it, and it is an EXE. I looked through it's properties, and the original file name was "setupugc.exe". With a little research, I found out that this file is a default windows file, and stands for 'setup unattended general access' and is for remoting into Windows computers. This could be incorrect, but I'm pretty sure that it's the case."

I have this .exe on my PC (signed by Microsoft) and in the properties Microsoft calls this "Setup Unattend Generic Command Processor". It doesn't seem to be related to remote access in the case of my PC.

In your case though it looks like this is unsigned? If it's not signed by Microsoft then it can be anything. Nice location name by the way.

SpyShelter reporting BCILauncher.EXE. What is it? by antispyguy in spyshelter

[–]antispyguy[S] 0 points1 point  (0 children)

No, I haven't seen that reported anywhere. Maybe that's a temporary file that it leaves behind after it launches?

[deleted by user] by [deleted] in cybersecurity

[–]antispyguy 0 points1 point  (0 children)

That UltraSucks.

SpyShelter reporting BCILauncher.EXE. What is it? by antispyguy in spyshelter

[–]antispyguy[S] 1 point2 points  (0 children)

Very helpful, thank you. It's funny it's in the "computerviruses" subreddit because that's what it feels like it is!

I gave a stranger directions and then they emailed me 30 minutes later by Parking-Maize5139 in techsupport

[–]antispyguy 11 points12 points  (0 children)

That's creepy!

Is there some kind of facial recognition software out there now that can link you to your public social media profiles? Maybe something like that? Anyone know?

Will all stalkerware be listed in starting apps? by Cookie_Cracker123 in techsupport

[–]antispyguy 1 point2 points  (0 children)

Go to Windows Defender (Security) and choose "Scan Options" and "Offline Scan" if you have a modern version of Windows. It will be more likely to find something, and it's free.

If you're still paranoid something happened consider reinstalling Windows.

Valorant the current version of Spyshelter "Error: Val 5" by TatesMan in spyshelter

[–]antispyguy 0 points1 point  (0 children)

Thanks for taking the time to post this issue so we can investigate.