Page 1 of 3 123 LastLast
Results 1 to 10 of 24

Thread: Keylogger

  1. #1
    Join Date
    Apr 2012
    Posts
    13
    Thanks
    0
    Thanked 0 Times in 0 Posts
    Rep Power
    0

    Keylogger

    How does one go about detecting a keylogger or other similar utility that may have been installed on a computer. How does one locate the data that has been stored and remove it as well as the offensive utility.
    Note: This a personal home computer not a work or employer owned system. Thanks in advance.




  2. #2
    Join Date
    Mar 2012
    Location
    Cardboard box
    Posts
    113
    Thanks
    2
    Thanked 4 Times in 4 Posts
    Rep Power
    2
    No expert, but will careful inspection of lsof help?
    distrACT -- an open community

  3. #3
    Join Date
    Apr 2012
    Location
    Netland
    Posts
    35
    Thanks
    0
    Thanked 1 Time in 1 Post
    Rep Power
    0
    Not really sure about Linux but if you are using windows, however, you might want to open up the task manager. Do we have a task manager in Linux?

  4. #4
    Join Date
    Apr 2012
    Location
    Tennessee
    Posts
    66
    Thanks
    2
    Thanked 1 Time in 1 Post
    Rep Power
    2
    There is a task manager in most, if not all, Linux distributions. The menu to access it can vary depending on what you are running, but I believe it is normally found under the 'System' menu with the title 'Task Manager'. I am trying to remember what you can enter when pressing ALT + F2 to pull up the Run Program menu, but my mind is drawing a blank. I must say that I am not too familiar with having a key logger (or a problem with one) on any Linux system, was this a key logger that you installed?

  5. #5
    Join Date
    Apr 2012
    Posts
    84
    Thanks
    5
    Thanked 1 Time in 1 Post
    Rep Power
    2
    1. I am Assuming windows.
    2. I am assuming the machine is on.
    3. You can do the same in linux, I just don't know the tools.

    Ok Firstly. You wanna stop using your plugged in keyboard. Go to the onscreen keyboard on the screen - this will not be logged by a keylogger.

    Secondly. You wanna find out what ports you have open, and where they are connecting to. Close all web browsers and everything connecting outwards. If you see anything going out, not the ip address.

    Open a process viewer (task manager will do) look for any processes taking up more ram / cpu than the others. Download and install process explorer from sys internals. Use this to "varify" all processes running. Right click process, click properties, click varify.

    If any do not varify. They are suspect.

    Disconnect the machine from the internet. If it is a text keylogger you need to look for several things. Any stange exes, and any strange text files. To find these. I would boot into a linux live cd. Grep for exe. See what you find. Grep for .txt or .log see what you find.

    If you are still unsure. Type in some random characters onto the live running machine using your keyboard. Make it a unique string. so like "hdnsnakaishtbam292834dsa" something you would not have typed before. Boot into linux, and do a grep for that string. If you find it saved in a text file, or find it anywhere on the drive OTHER THAN the pagefile.sys. You have a keylogger on your machine. Once you find out where your string is stored, you have the temp file of the keylogger. Google its name, and check the folder where it is saved. You will likely find the keylogger hidding in the same, or a few folders back in the tree.

    I hope this helps. I do this for a living. I have detected and removed keyloggers on windows machines before. So I can try my best to help you.

    Once you find any suspect files. Upload them to virustotal.com and see what they rank as, either good or bad.

  6. #6
    Join Date
    Apr 2012
    Location
    Netland
    Posts
    35
    Thanks
    0
    Thanked 1 Time in 1 Post
    Rep Power
    0
    Quote Originally Posted by scotty View Post
    1. I am Assuming windows.
    2. I am assuming the machine is on.
    3. You can do the same in linux, I just don't know the tools.

    Ok Firstly. You wanna stop using your plugged in keyboard. Go to the onscreen keyboard on the screen - this will not be logged by a keylogger.

    Secondly. You wanna find out what ports you have open, and where they are connecting to. Close all web browsers and everything connecting outwards. If you see anything going out, not the ip address.

    Open a process viewer (task manager will do) look for any processes taking up more ram / cpu than the others. Download and install process explorer from sys internals. Use this to "varify" all processes running. Right click process, click properties, click varify.

    If any do not varify. They are suspect.

    Disconnect the machine from the internet. If it is a text keylogger you need to look for several things. Any stange exes, and any strange text files. To find these. I would boot into a linux live cd. Grep for exe. See what you find. Grep for .txt or .log see what you find.

    If you are still unsure. Type in some random characters onto the live running machine using your keyboard. Make it a unique string. so like "hdnsnakaishtbam292834dsa" something you would not have typed before. Boot into linux, and do a grep for that string. If you find it saved in a text file, or find it anywhere on the drive OTHER THAN the pagefile.sys. You have a keylogger on your machine. Once you find out where your string is stored, you have the temp file of the keylogger. Google its name, and check the folder where it is saved. You will likely find the keylogger hidding in the same, or a few folders back in the tree.

    I hope this helps. I do this for a living. I have detected and removed keyloggers on windows machines before. So I can try my best to help you.

    Once you find any suspect files. Upload them to virustotal.com and see what they rank as, either good or bad.

    Great and detailed post. I would do it as Scotty said. Another method you might want to consider assuming it is still in windows is to use safe mode. Just reboot your windows and switch to safe mode then manually delete/uninstall that keylogger. If anyone can teach us how to do it in Linux, it would be a great help.

  7. #7
    Join Date
    Apr 2012
    Posts
    84
    Thanks
    5
    Thanked 1 Time in 1 Post
    Rep Power
    2
    Quote Originally Posted by Godric View Post
    Great and detailed post. I would do it as Scotty said. Another method you might want to consider assuming it is still in windows is to use safe mode. Just reboot your windows and switch to safe mode then manually delete/uninstall that keylogger. If anyone can teach us how to do it in Linux, it would be a great help.
    Yes for linux, I am not so sure. The best thing you can do is unplug from the network, and not restart. That way if anything is transmitting / running now you will get it. If you restart you run the risk that you might not catch it again.

  8. #8
    Join Date
    Apr 2012
    Location
    Manila, Philippines
    Posts
    27
    Thanks
    2
    Thanked 0 Times in 0 Posts
    Rep Power
    0
    I'm just curious... If there is a keylogger running in Linux, would you be able to find it on your running processes by typing "ps x"? If so, maybe you could just kill that process then search and destroy it. I haven't encountered any keylogger yet so I'm not quite sure.
    Acronix | Coders Republic
    "In my weakness, I find strength."

  9. #9
    Join Date
    Apr 2012
    Posts
    30
    Thanks
    0
    Thanked 0 Times in 0 Posts
    Rep Power
    0
    If you're on Windows what anti-virus are you running? Because constantly browsing the web with Windows and no anti-virus, even a free one, is just asking to get infected with something. If you don't want to spend money, then at least download the free versions of Avast and Malwarebytes. If you're willing to put out a couple of bucks, then Kaspersky and Bitdefender are also quite good. The paid version of Kaspersky (3-PC license for 2012) also has a free $50 rebate on Newegg right now (ends 4/18) so you essentially get it for free.

  10. #10
    Join Date
    Apr 2012
    Posts
    84
    Thanks
    5
    Thanked 1 Time in 1 Post
    Rep Power
    2
    Quote Originally Posted by Acronix View Post
    I'm just curious... If there is a keylogger running in Linux, would you be able to find it on your running processes by typing "ps x"? If so, maybe you could just kill that process then search and destroy it. I haven't encountered any keylogger yet so I'm not quite sure.
    Yes you could if you could find the process. A lot of keyloggers hide at the rootkit level, so finding the process is sometimes difficult, as it can either be hooked into something else like the acpi drivers, for example.

 

 

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
           








Check out Linux Central for Linux software and other goodies!





» Stats

Members: 3,541
Threads: 3,912
Posts: 9,423
Top Poster: Fred (1,486)
Welcome to our newest member, permeno34

» Links



Powered by vBadvanced CMPS