PDA

View Full Version : How to tell if machine has Keylogger?



kennyboy
03-20-2005, 09:46 AM
I live in a dodgy part of the world, where internet cafes are known to have keyloggers. Is there a way of telling if one is operating on a particular machine?

Thanks for any help.

100%
03-20-2005, 09:51 AM
i don't think so - they normally hide themselves from the running processes

found this - maybe itll help
http://www.pestpatrol.com/Support/About/About_KeyLoggers.asp
post if you find answer.

Maybe also if you run a spyware program something willl come up
but actually what if you used HijackthisLog - i'm sure it would register.
Download herehttp://www.download.com/3000-8022-10227353.html
put in the Log file here for analysis - http://www.hijackthis.de/
(Hijack this doesnt require installation hence can be easily runin cybercafes)

I guess youd have to run several keyloggers on your machine - and test which ones show

kennyboy
03-20-2005, 10:36 AM
15% Some interesting info at Pest Patrol but not answers really.

HijackThis is a nice one, but it is so complex in what it reports that to spot a rogue entry in one of the cyber cafe machines would be difficult, as I wouldnt have time to post the results on any forums.

Trouble is, I am having to do my internet banking using these machines, and makes me very nervous about putting in passwords etc. Difficult isn't it..

harrycary
03-20-2005, 12:03 PM
no admin rights.
doubtful you can do much.

uNz[i]
03-20-2005, 12:20 PM
Banking on the internet is the last thing I'd want to try, no matter how secure the protocols and servers are supposed to be. :ph34r:

Wouldn't it be just as easy to nip down to the bank as it is to nip down to the internet cafe?

100%
03-20-2005, 12:56 PM
i still think you could use hijackthis to find out if there is one on
and the analyser http://www.hijackthis.de/ is pretty simple
the only problem is that youd probably have to reboot to get of the system.
or if you find a keylogger on the system then simply goto another pc or cafe

kennyboy
03-21-2005, 10:24 AM
Many thanks for all the suggestions guys. Unfortunately, it is not easy to 'pop down to the bank" as my money is paid into a bank in UK and I live in Philippines, but the thread has given me some things to try.

Also had the idea of putting all the confidential stuff on floppy, and pasting it in, which should foil the keyloggers, but doesnt get past the screen capture thingys. But anyway, very grateful for the help.

Regards
Ken

4play
03-21-2005, 11:29 AM
try downloading a linux live cd and booting into that. guarenteed no keyloogers. just hope the internet cafe will elt you do it.

trajillo
03-21-2005, 11:56 AM
umm check if the keyboard is connected to the printer...

Filliz
03-21-2005, 05:00 PM
I found a keylogger on my machine this week :angry:
I installed Hitman pro and when it was Spy sweepers turn to do the cleaning,it discovered the keylogger.

In other words,SB S&D and Adaware (fully updated) both failed to find it.
Wonder how long that thing has been on my computer :dry:

Really enjoyed myself today,changing all my passwords to all my accounts I can think of. :pinch:

Hitman Pro is a nice app really,but I think it's only available in Dutch.
There's an English version of it coming out somewhere next month though.
Or so they say.

If you're not familiar with it, Hitman Pro combines the engines of multiple programs to create one powerful spyware cleaner. Current engines:

Ad-Aware SE (6.2)
Spy Sweeper 3
Spybot Search & Destroy 1.3
CWShredder 2.13
SpywareBlaster 3.2
Spyware Block List
Sysclean Package
SuperDAT VirusScan

It configures all these apps automatically with the best and most effective settings.
All you have to do the first time is accept the TOS of the various apps during setup.
If you already have one of these apps installed,it just redownloads and reinstalls them for you.
Quite scary though seeing it taking over your computer the first time you run it :lookaroun

There should be an English guide on setting it up here (http://gateway.homeunix.org/library/_thema/_computer/_hitman/hitmanpro-high.html) but it looks like the page can't be accessed.

numba1xclusive
03-21-2005, 05:05 PM
15% Some interesting info at Pest Patrol but not answers really.

HijackThis is a nice one, but it is so complex in what it reports that to spot a rogue entry in one of the cyber cafe machines would be difficult, as I wouldnt have time to post the results on any forums.

Trouble is, I am having to do my internet banking using these machines, and makes me very nervous about putting in passwords etc. Difficult isn't it..

Why would u do ur internet banking on an unsecure computer and with tons of spyware. I went to india over the summer, and went to an internet cafe. Since their IE was jacked, I jsut dled firefox. HAve u tried doing that? USually, most of them dont check their pcs to what people put.

herauthon
03-26-2005, 11:55 PM
According to the administrator
your "HERE" link was indeed valid for a period
of time, unfortunatly, due to a media sweep,
correction of maps/files and disks, upgrade
of the server you have to find it HERE (http://gateway.homeunix.org/thema/hitman2)

If you don't believe me, i am the administrator,
i hope i served you.

[high = broadband][low = modem/isdn users]
high-version (http://gateway.homeunix.org/thema/hitman2/hitmanpro-high.html)
low-version (http://gateway.homeunix.org/thema/hitman2/hitmanpro-low.html)
a yet faster version is on the factorybeld..

100%
03-30-2005, 08:27 AM
just found this

KeyloggerStoppper - http://www.eurodownload.com/download-software/6396/Keylogger-Stopper.html
never tried it

Keylogger Stopper is a sophisticated software to disable keylogger from working on your PC. Using highly efficient technology, Keylogger Stopper will monitor all keylogging activities and disable them by blocking and crippling their hooking processes. This will ensure that all keyloggers will give an empty output in their secretly recorded file no matter how many keyloggers are running on your PC.