Forum Moderators: phranque
Since the weekend I have noticed my PC (win XP) has become veeeeeeeeeeeery slow. In fact, after a few hours running you can see how it is working even if I'm not doing anything. You know, the HDD activity LED blinking continuously.
This is a problem, I have had to restart the PC twice a day the past two days. I was thinking about a keylogger but I ran Ad-Aware and found nothing but tracking cookies.
I have ran SpyBot SD and it found the same.
I have this idea about having a Keylogger for one specific reason.
I was running a 16Bit Windows application. In one text input window. I tried to write:
está
But I got
est´´a
I had noticed that when a Keylogger is running, accents (´)are typed twice because of the way a keylogger works. But this doesn't happen in Win XP.
Last friday my PC was updated with two security patches (I'm beginning to doubt about those files being security patches). And all the problems began this week.
Any idea on how to scan for Keyloggers. This is annpying, I can't get my job done properly if I need to restart.
Thanks.
Last friday my PC was updated with two security patches (I'm beginning to doubt about those files being security patches). And all the problems began this week.
Did you install them, or did someone else? Did you go to the Microsoft website to get them, or did "Microsoft" email them to you? It may be that the security patches were legitimate and that they have simply created problems for some malware that was already present.
At any rate, a key logger should show up in your Task Manager as a running process. Also, if your setup permits, install a packet sniffer on an adjacent machine to see if anything is trying to send out packets.
You should also make sure you have some type of firewall protection that detects attempts made to access the internet. That way if there is in fact a key logger or other trojan, you can prevent it from finishing its job.
Also - I don't think the scanning tools you mentioned are specifically suited to pick up all types of trojan apps. Norton and McGafee AV do look for a lot of different trojans as part of their virus scans. (I reserve the right to be wrong, so if you are sure that those tools do perform in-depth searches for trojans, then never mind this last bit).
Keyloggers are no good unless they can deliver the information to the remote computer, and they do this by e-mail, but not using a client like Outlook, but just the transport protocol which means the mail is sent without you really knowing about it. Keyloggers will also be set to send a mail at set intervals, like every hour, day, week etc.
Having your anti-virus set to scan outgoing mails will display a pop-up when it is scanning a mail - this will alert you to the fact that a mail is going out even if it isn't using your mail client. Some AV programs let you log activity, so you can see if it is happening while you sleep if the 'puter is left on.
Also, check on the websites of keylogger suppliers - many of them come with default keystrokes that will bring up their interface. If the culprit who loads one on your computer is lazy, then they perhaps won't have changed the default keystrokes and you may be able to find them this way.
Good luck.
Oh, and welcome to WW!
Keyloggers just read the last key typed. They generally don't bother getting in the way of what was typed.
Writing accents (like á é í ó ú) in spanish gave an idea of how keylogges work. As long as I know, they 'print' each character twice, once for the Log and once for the screen.
An accent works a little different to other character. Ypu need to type the (´) key first and the letter (a)last, so the (´) holds until the (a) is pressed to appear on scree.
But if you type (´) twice you get (´´).
Win XP solves this (I don't know how) but 16Bit Win apps still have this behaivor.
Thats why I have concerns on this thing being a keylogger.
On the other hand, I did not installed the security patches, and I don't installed them from a hoax e-mail.
It was the 'System Department' people who came around to fix some Worms we had been having problems with.
It seems (now) that I am the only one having this kind of problems here.
[msdn.microsoft.com...]
These are both read-only functions and do not 'write out' anything.
What api were you refering to?
I had used it before.
Now. I have run Anti-Keylogger
It found three files:
MSCTF.dll (From Microsoft)
TrayIt!.dll (I installed this)
Idle.dll <--- disabling this one that weird accent behaivor stops.
I don't have a clue of what Idle.dll does. It doesn't has a manufacturer associated.
Before doing anything I'll look some info.
Any idea at this point?