Other How do you run an effective scan for keyloggers?

Discussion in 'Software' started by freshsandwiches, 23 Sep 2011.

  1. freshsandwiches

    freshsandwiches Can I do science to it?

    Joined:
    9 Aug 2009
    Posts:
    552
    Likes Received:
    15
    As title.

    Asking for a friend as he formerly played wow. I saw his Character online while playing starcraft II.

    He's done a full scan with MSE but nothing detected.

    On the plus side it looks like it was a gold farmer. He now is lvl 82, has 525 mining, plus 30 days of game time courtesy of a game card bought on-line!
     
  2. RichCreedy

    RichCreedy Hey What Who

    Joined:
    24 Apr 2009
    Posts:
    4,699
    Likes Received:
    172
    remove hd from machine, and scan on a fully updated machine, with antivirus, and maybe malwarebytes antimalware.

    most av will find keyloggers
     
  3. Bede

    Bede Minimodder

    Joined:
    30 Sep 2007
    Posts:
    1,340
    Likes Received:
    40
    +1 to what RichCreedy said. If that doesn't find it then either scrap that hdd, or tell your friend not to use the same email and password across multiple websites.
     
  4. freshsandwiches

    freshsandwiches Can I do science to it?

    Joined:
    9 Aug 2009
    Posts:
    552
    Likes Received:
    15
    Thanks for the suggestions guys. Can keyloggers be so difficult to find that you have to scrap the HDD?
     
  5. sb1991

    sb1991 What's a Dremel?

    Joined:
    31 May 2010
    Posts:
    425
    Likes Received:
    31
    There's never a need to scrap it literally - a format will get rid of anything. Most of the time, a good antivirus will find keyloggers.
     
  6. bulldogjeff

    bulldogjeff The modding head is firmly back on.

    Joined:
    2 Mar 2010
    Posts:
    8,403
    Likes Received:
    634
    Down load a program called rapport. I use it with my bank log in details, it's designed purely to block key loggers. I'm guessing if it's on the PC it will protect everything rather than just bank log ins.

    Then again if you've been hacked it might be worth reinstalling and changing all thye pass words.
     
  7. thehippoz

    thehippoz What's a Dremel?

    Joined:
    19 Dec 2008
    Posts:
    5,780
    Likes Received:
    174
    keylogger can be ran strictly from memory.. after an exploit or embedded in certain software, it can be ran without writing anything to the disk.. that's what most guys don't understand- real hackers leave as little to investigate as possible in the aftermath =]

    even migrated into it's own process (this will show up like in task manager- but they usually migrate into a known process like explorer.exe or notepad.exe.. av can catch this)

    he was probably a puppet visiting certain websites and running dubious software is my guess.. too late the writer got what he wanted

    like in a browser exploit.. the memory exploited might only be good as long as the browser is open- so the hacker has a limited time to migrate it into a more stable process.. or he could choose to let it ride.. upload the keylogger and get lucky- av doesn't work in that case
     
    Last edited: 24 Sep 2011
  8. jimmyjj

    jimmyjj Minimodder

    Joined:
    20 Jul 2010
    Posts:
    663
    Likes Received:
    15
    If this guy has had some details compromised (Starcraft 2) then they may have also got other important information (banking information for example).

    This guys needs to:

    Format his hard drive and re-install windows.

    Change every password and log in he has.

    Monitor his bank accounts carefully over the next few days for suspicious activity.

    Ensure he has good quality up to date virus and malware protection. Some people rave about windows security essentials but others do not rate it. As an example you can buy Norton Antivirus OEM for about a tenner which is the cost of a (small) round of drinks.

    Take a crash course in basic computer security - concentrating on why it is not a good idea to download a lot of crap on to your PC and basic browser safety.

    He needs to do this NOW.

    It may seem like overkill, but if this was my machine I would settle for nothing less than the above.

    I personally know 2 people who have had bank accounts cleared out after installing key loggers and it was not a fun experience for them.
     
  9. Shabing

    Shabing What's a Dremel?

    Joined:
    27 Nov 2008
    Posts:
    130
    Likes Received:
    0
    Or just buy things from shops, and be less of a knobber.
     
  10. RichCreedy

    RichCreedy Hey What Who

    Joined:
    24 Apr 2009
    Posts:
    4,699
    Likes Received:
    172
    i see loads of machines that have problems with rapport

    malwarebytes, paid for version will do a flash scan of memory items everytime it updates, which can be hourly
     
  11. dynamis_dk

    dynamis_dk Grr... Grumpy!!

    Joined:
    23 Nov 2005
    Posts:
    3,598
    Likes Received:
    276
    Yeah, from personal experience I found rapport to be a pita

    One day it just stopped working. Personally I've got the paid version of Malwarebytes and its never let me down so far.
     
  12. bulldogjeff

    bulldogjeff The modding head is firmly back on.

    Joined:
    2 Mar 2010
    Posts:
    8,403
    Likes Received:
    634
    The version I use is downloaded direct from Natwest, it does nothing else other than protect my bank log in from key loggers. Maleware byte and programs like it are ok but you still have to do a scan manually. The way I use raport it's there all the time protecting pass words against key loggers. It works perfectly for me the way I use it.
     
  13. RichCreedy

    RichCreedy Hey What Who

    Joined:
    24 Apr 2009
    Posts:
    4,699
    Likes Received:
    172
    as i said paid for version, can be set to check memory after every update, which mine does

    free version doesn't run in the background, paid for does
     
  14. bulldogjeff

    bulldogjeff The modding head is firmly back on.

    Joined:
    2 Mar 2010
    Posts:
    8,403
    Likes Received:
    634
    Ah, I see. I've always used the free one, for the odd occasion that I've needed it.
     

Share This Page