Computing.Net > Forums > Windows XP > how to tell if a keylogger has been

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

how to tell if a keylogger has been

Reply to Message Icon

Name: jtkld75
Date: July 12, 2004 at 15:31:23 Pacific
OS: xp home
CPU/Ram: 512/p4
Comment:

installed in my system? any one know any programs that i can run to find out? Thanks alot.



Sponsored Link
Ads by Google

Response Number 1
Name: tomtt
Date: July 12, 2004 at 15:46:35 Pacific
Reply:

This is what I have on the subject>>> Hackers (and sometimes employers) install keystroke loggers to record keystrokes. One of the better know is Invisible Keylogger Stealth ( IKS )which is a commercial utility (more likely to be used by employers than hackers). Arne Vidstrom has released the freeware klogger utility (more likely to be used by hackers and penetration testing teams). There are any number of freeware, shareware and commercial keystroke loggers available for every operating system. They are mostly written as keyboard device drivers and as such are invisible to the user of the PC. There are also hardware versions of keystroke loggers including keyboards that have a dual function - keyboards and keystroke logging and keystroke loggers that are little boxes that plug in between the keyboard cable and the PC. See my Penetration Testing Tip #22: Keystroke loggers and spy software / hardware for more information on software and hardware keystroke loggers.
OK. Thats all well and good but why is this tip in the registry section. It turns out that IKS uses NT's registry. You can use it to find whether IKS has been installed on the PC:

Hive: HKEY_LOCAL_MACHINE
Key: SYSTEM\CurrentControlSet\Services\iks
Name: DisplayName
Type: REG_SZ
Value: IKS
Name: LogName
Type: REG_MULTI_SZ
Value: \%SystemRoot%\iks.dat


The IKS documentation gives instructions on how to hide this "red flag". Even with values changed and the key name iks changed, search for the key "LogName" under Services for IKS's footprint.


0

Response Number 2
Name: michael2
Date: July 12, 2004 at 16:50:31 Pacific
Reply:

'Spybot' found a keylogger on my PC. I installed the logger on a spare PC that does not get net access and I was going to reformat anyway.
Spybot is free. Update it before you run it.


0

Response Number 3
Name: Alvaro Martin Gomez
Date: July 12, 2004 at 20:49:46 Pacific
Reply:

Hi.

Who's Watching Me claims to do that job efficiently. Not free, but you can try it for 90 days.

Hope this helps.


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows XP Forum Home


Sponsored links

Ads by Google


Results for: how to tell if a keylogger has been

How to tell if XP is Activated? www.computing.net/answers/windows-xp/how-to-tell-if-xp-is-activated/61146.html

How to tell if net use is capped? www.computing.net/answers/windows-xp/how-to-tell-if-net-use-is-capped/154742.html

32-bit OS? www.computing.net/answers/windows-xp/32bit-os/157602.html