Detecting Keylogging Programs

Xenon14

Platinum Member
Oct 9, 1999
2,065
0
0
I just accidentally found a key logging program running on my computer. Are there programs that can detect and remove keylogging and other spy programs?? Thanks
 

RossMAN

Grand Nagus
Feb 24, 2000
79,006
430
136
Ad-aware detects and removes spy ware.

Let's say you had a keylogging application running in your background that you didn't know about, ran Ad-aware that got rid of all spy ware and you have a firewall which detects all incoming/outgoing traffic ... could the keylogger program get past all that and still transit it's logs via the net?
 

xirtam

Diamond Member
Aug 25, 2001
4,693
0
0
Yes, there are. None that I like, though, because many of them include trojans of their own.

I've considered writing one, but am not paranoid enough to do it just for me. If others are interested, I might be motivated to pursue such a "calling."
 

xirtam

Diamond Member
Aug 25, 2001
4,693
0
0
It's possible, Rossman. I've seen programs written that actually feed off firewall code, but they're usually restricted to specific firewalls. So, "yes and no" would be a good response to that. How about, "not if you have a good firewall"?
 

Xenon14

Platinum Member
Oct 9, 1999
2,065
0
0
Pasted from my conversation with a friend. I just left all the info in:

in my startup it said Zero PopUP - uninstall
so i'm like wtf is this
i press uninsstall and it said file not found
i went to norton utilities, and pressed 'fix broken links"
then when it fixed, i pressed uninstall
and it's like "do u wish to uninstal SAM - Stealth Activity Monitor ?"
i'm sitting here, like wtf
when it "fixed the link" it found the wrong file for it
b/c hte zero popup no longer existed
i must have deleted it a while ago
i tried to uninstall and it wouldn't let me
so i look into taskmanager, and sur eenough sam.exe is running
 

Rallispec

Lifer
Jul 26, 2001
12,375
10
81
Originally posted by: Xenon14
Pasted from my conversation with a friend. I just left all the info in:

in my startup it said Zero PopUP - uninstall
so i'm like wtf is this
i press uninsstall and it said file not found
i went to norton utilities, and pressed 'fix broken links"
then when it fixed, i pressed uninstall
and it's like "do u wish to uninstal SAM - Stealth Activity Monitor ?"
i'm sitting here, like wtf
when it "fixed the link" it found the wrong file for it
b/c hte zero popup no longer existed
i must have deleted it a while ago
i tried to uninstall and it wouldn't let me
so i look into taskmanager, and sur eenough sam.exe is running


couldnt you just end the sam.exe task?

what OS are you using

 

Xenon14

Platinum Member
Oct 9, 1999
2,065
0
0
Win 2k Pro.

Yes, I could've ended Sam.exe and I did. However, prior to me knowing what Sam.exe did, I merely assumed that it was one of many executables that Windows runs on its own.
 

ThunderGirl

Senior member
Aug 17, 2001
606
0
0
ok I just dl adware. what does it mean when the summary is coming up w/ things? I don't want to wait to the end to find out LOL

ok done anyone know what cydoor is? it is all over the place on this adware box that shows the stuff in the end.

Yep I am not a geek when it comes to this stuff :(
 

HiveMaster

Banned
Apr 11, 2002
490
0
0
ok I just dl adware. what does it mean when the summary is coming up w/ things? I don't want to wait to the end to find out LOL

ok done anyone know what cydoor is? it is all over the place on this adware box that shows the stuff in the end.

Yep I am not a geek when it comes to this stuff

If you are running Kazaa lite, there is one of those "spyware" thingies (that is a technical term!) that you need to archive. I just check all the boxes and get rid of them.

Remember to run it again after you get rid of the ones you find.
 

dakata24

Diamond Member
Aug 7, 2000
6,366
0
76
dont forget to download the refupdate program that comes separate from ad-aware.. though it hasnt been updated since 6/23/02, periodically, the definitions for spyware is updated.
 

IcemanJer

Diamond Member
Mar 9, 2001
4,307
0
0
Originally posted by: Xenon14
Win 2k Pro.

Yes, I could've ended Sam.exe and I did. However, prior to me knowing what Sam.exe did, I merely assumed that it was one of many executables that Windows runs on its own.

there are usually a standard number of places where Windows look for instructions for loading startup programs (2 places in the registry, startup folder, Services, win.ini or boot.ini). you should go through them and know what each line of code or entry means and disable anything that you don't need.
 

Descartes

Lifer
Oct 10, 1999
13,968
2
0
I've seen programs written that actually feed off firewall code

Uhh......... huh? A firewall doesn't analyze the contents of the data at all; it simply restricts at the protocol header level. Also, any application, keylogged included, attempting to transmit to a server will generally use HTTP. This will look like a normal request on port 80 to the firewall; no different than when you're browsing these forums. Only an IDS is capable of actually analyzing the contents of the packets to discern vulnerabilities...
 

ThunderGirl

Senior member
Aug 17, 2001
606
0
0
ok is it bad if round like 39 things?

My husband (seperated) was at my computer and who knows what he did.
 

Vic

Elite Member
Jun 12, 2001
50,422
14,337
136
AdAware won't fix this little problem.

Stealth Activity Monitor (now called STARR) is legitimate keylogging software designed for businesses to monitor their employees and for parents who want to monitor their children. It is not a trojan, spyware, or a virus.

Bad news, someone with direct physical access and administrative rights to your machine installed that, this program can only be installed locally. I think you might have someone you need to confront about this. In the meantime, I'd be backing up and formatting if I were you.
 

dakata24

Diamond Member
Aug 7, 2000
6,366
0
76
Originally posted by: ThunderGirl
ok is it bad if round like 39 things?

My husband (seperated) was at my computer and who knows what he did.

nope. ive had 1 computer literally have 200-300 hits on it. it's probably just from hidden spyware when you install programs and cookies.

Bad news, someone with direct physical access and administrative rights to your machine installed that, this program can only be installed locally. I think you might have someone you need to confront about this. In the meantime, I'd be backing up and formatting if I were you

couldn't a piece of legitimate software been altered so that, on install, it would also install the keylogger as well without the users knowledge?
 

ThunderGirl

Senior member
Aug 17, 2001
606
0
0
ACK! I messed up!

I checked them and did exclude instead of continue *DOH*

I was not meant to do this. Darn my built in computer tech for leaving me GRRRRR :disgust: ;)

*edit* ok overreacted when I couldn't find an undo fast enough. All is good I found it. *thinks maybe I shouldn't be doing this stuff, I may just break my computer if you can call it one LOL*
 

Vic

Elite Member
Jun 12, 2001
50,422
14,337
136
Originally posted by: dakata24

couldn't a piece of legitimate software been altered so that, on install, it would also install the keylogger as well without the users knowledge?

Probably, but SAM aka STARR is $39 bucks a license (according to their site), little steep for spyware I think.
Anyway (once again, based off their site, I had never heard of this software before I googled it just now and I'm no fan of keyloggers), this doesn't look like spyware-type software. It looks like any one of those run-of-the-mill keyloggers for businesses and parents. Which is what I think is going on here.