The only way they could capture your keystrokes is if you are using something like VNC or Remote Desktop and they middle-man your connection, or if they've cracked your machine and installed a keylogger. In either case, unless they're being stupid, they've taken steps to hide the attack's existence, and you may not notice any subtle inconsistencies that would tip you off. Traceroute would uncover the first kind (if they're stupid), and the process list would uncover the second kind (if they're stupid). And regardless, by the time you notice, they already probably have some kind of sensitive data that will be used to propogate further attacks (passwords) or carry out other nefarious activities (CC #'s, SSN, etc...).