keylogging devices

Discussion in 'Software' started by paperclipper2, Apr 16, 2011.

  1. paperclipper2

    paperclipper2 Private E-2

    Does a keylogging device leave any detectable presence in my computer after the keylogging device has been removed? Are there any traces of the keylogging device on my computer? If so, what do I need to do to find it?
     
  2. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    I classify key loggers the same as rootkits. You are never sure you are clean.

    If it were my computer, I'd format and do a clean install.
     
  3. paperclipper2

    paperclipper2 Private E-2

    Thanks for the reply. But I would like to know if I can prove the keylogging device was installed on my computer even though it has been removed?
     
  4. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    What Windows version and Service Pack you using and what was the keylogger app if you personally installed it?

    If a keylogger was installed without your knowledge then its very hard to know what has been done and as plodr mentions a full reinstall of Windows is likey best option as you will need to know if all the keylogger application is gone if not.


    Full malware scanning is likey other option


     
  5. paperclipper2

    paperclipper2 Private E-2

    Thank you for the reply. Here are my responses to your questions:

    1. My PC has Windows Ultimate Vista for home with Service Pak 2.

    2. The keylogger was installed and subsequently removed without my knowledge. It may have been on my computer for 30-60 days. So I would like to prove its existence. Can this be done?
     
  6. theefool

    theefool Geekified

    Perhaps.

    Try, bring up the device manager and looking at storage volumes, or something. It will be hard. I'll post a few pics.
     

    Attached Files:

    • 1st.png
      1st.png
      File size:
      10.6 KB
      Views:
      8
    • 2nd.png
      2nd.png
      File size:
      12.2 KB
      Views:
      13
    • 3rd.png
      3rd.png
      File size:
      39.3 KB
      Views:
      11
    • 4th.png
      4th.png
      File size:
      16 KB
      Views:
      12
  7. Novice

    Novice MajorGeek

    Just something to think about. There are hardware key loggers as well.:)
     
  8. paperclipper2

    paperclipper2 Private E-2

    Yes. This was a hardware device attached to my computer without my knowledge. But I saw it, although at the time I did not recognize it. Since its removal I have done the research to know what it was. Now I need to prove its existence on my PC. Any additional thoughts on how to do this? Thank you.
     
  9. paperclipper2

    paperclipper2 Private E-2

    How do I get from Thumbnail 1 to 2?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should have a tab that says previous and next. Just click next. Of just put your pointer over the next thumbnail you want to view.
     
  11. Novice

    Novice MajorGeek

    The hardware key loggers are self contained devices and only require physical access to your computer to install or remove. No software installation is necessary, so a photograph of it installed would be the best way to prove that it was there.:)
     
  12. paperclipper2

    paperclipper2 Private E-2

    Too late for that. Any other suggestions?
     
  13. theefool

    theefool Geekified

    Well, it typically would show up in the device manager, only with my post. But, even then, it would be hard for proof.
     
  14. paperclipper2

    paperclipper2 Private E-2

    Tim W....it's not the thumbnails. How do I get from Thumbnail 1 to 2 on my PC? Is it a left or right click on the circular Windows icon in the lower left corner? And then what?
     
  15. theefool

    theefool Geekified

    If you are referring to my pics, I'd just use the old fashion mouse and middle click each pic. If you are using ie7/8/9 or chrome/firefox/etc
     
  16. paperclipper2

    paperclipper2 Private E-2

    Thanks. But you are misunderstanding my question. I see the thumbnails and have enlarged them and see the images. I don't know how to get to the screen represented in Thumbnail #2. How do I get from the Windows circular icon to what is represented in Thumbnail #2?
     
  17. theefool

    theefool Geekified

    Ah, sorry, the first pic points to the windows "orb" click that, then at the very bottom, you can see that I type in cmd, to bring up cmd prompt. Right click cmd, to bring up menu.

    More pics.
     

    Attached Files:

  18. theefool

    theefool Geekified

    Note #112001.2: This is only a way to see if there are devices that were once put into your computer. If you were to use a usb device (hdd/thumb) it would leave hidden entries here.
     
  19. paperclipper2

    paperclipper2 Private E-2

    Thank you for your assistance with the step by step instructions. I think I was able to capture all of the information I can for now. In the "run as administrator" mode there is an indication of a hidden keyboard device. I copied and printed all of the Values from the Details tab onto another document. And I plan to get some additional expertise on this so that the significance can be translated into understandable terms.

    Again, thank you for your help.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds