|
|
Question : KeyLogger problems..
|
|
Hello Gurus, I was stunned to discover yesterday that someone has put a keylooger on my pc (Spylo). I mean WOW ! how can I not have noticed ? I mean for sure they are supposed to be "invisible" but ..... Anyway my question is : is there a way to know if I have another keylogger on my pc ? I have to tell that I did not discover myself that spylo was installed on my pc... I was told !!! so I am afraid of something else... please help.
|
Answer : KeyLogger problems..
|
|
Keyloggers vary. Some can be detected by traditional programs like anti-spyware programs. For others, you have to use a rootkit detector because they use a device driver to hide themselves from the Windows API.
In your particular case, I suggest using both of the following:
(A) Traditional anti-malware: Autoruns: (1) Download Autoruns from: http://www.microsoft.com/technet/sysinternals/utilities/Autoruns.mspx (2) Run the program. It lists a bunch of things that start when Windows starts. (3) From the menu bar, select Options, and uncheck "Include Empty Locations" and "check" "Hide Microsoft Entries" Important -> Then click the Refresh button in the toolbar. (4) This will give you a shorter, more meaningful list. (5) Examine that list to see if you can spot a keylogger. (6) If not, or if not sure, you can use the File -> Save as.. option in Autoruns to save the list to a text file and then cut and paste it here.
In addition to the above, a rootkit detector is a must: (B) User RootkitRevealer: Download and run RootkitRevealer from: http://www.microsoft.com/technet/sysinternals/utilities/RootkitRevealer.mspx and click on "Scan" to scan your drives. It takes a while, so be patient. Try not to use the system too much during that time to avoid false positives. If it produces anything interesting, use "File -> Save As.." to save the results to a text file (Important -> you may need that file later) Copy-and-paste the results here, but if the results are very long, then just copy-and-paste the first 30 lines or so.
The above will detect just about every software keylogger. Note that hardware keyloggers cannot be detected by software.
|
|
|
|
|