PDA

View Full Version : keylogger



jus_sum_guy
09-02-2004, 03:54 AM
anyone know how i go abouts testing to see if it's in my comp??

googe
09-02-2004, 05:18 AM
use a virus scanner.

legendboy
09-02-2004, 08:22 AM
You will have to look thru your registery. Most keyloggers hide install files and also don't show up in running processes or show up in the start menu.

awd
09-02-2004, 09:22 AM
Well it really depends on the type of keylogger.

A "simple" Key Logger normally consists of two files: a DLL which does all the work and an EXE which loads the DLL and sets the hook. The logger is invoked on boot via an entry in your registry -- these ones are pretty easy to find.

But, some of the new gen loggers boast some pretty serioues attributes making them difficult to find and remove. Ie. Stealth mode -- running invisible in the process list.

Because a keylogger can involve dozens of files, and has as a primary goal complete stealth from the user, removing one manually can be a terrifying challenge to the average dude.

I have actually seen some newer ones that re-install themselves before the user reboots after they were removed!