Follow us on Twitter!
Follow us on Facebook!
 

Go Back   Pixtus - Photography Forum, Photographers, Photo Tips > General Information > Open Talk


Key logger help

This is a discussion on Key logger help within the Open Talk forums, part of the General Information category; My son's computer obviously has a key logger infesting it. He plays WOW and has gotten hacked several times in ...

Reply
 
LinkBack Thread Tools Display Modes
  (#1) Old
Premium Member
 
dbphotos's Avatar
 
Posts: 3,626
Join Date: Mar 2005
Location: Flower Mound (DFW), Texas
Real First Name: David
Camera: Nikon
Can Others Edit My Photos: No
iTrader Rating: 4

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
Key logger help - 04-07-2010, 10:09 PM


My son's computer obviously has a key logger infesting it. He plays WOW and has gotten hacked several times in the last 2 days after chaning his password to a very secure string of characters. I have ran a full scan with Mcafee and it hasn't found it. Is there a program that all of you IT gurus would recommend to isolate and delete a key logger?

Thanks!

---------------------------
| David Bailey Photography | Digital Racing Images | Sports Shooter | flickr | Grafix USA
I have a camera and some other stuff...
"Live your life in such a way that when your feet hit the floor satan shudders and says oh hell he's awake!"
Reply With Quote
Sponsored Links

Premium Members do not see Google advertisements. SIGN UP today and help support our community.
  (#2) Old
Senior Member
 
dryicerx's Avatar
 
Posts: 410
Join Date: Feb 2009
Location: Austin, TX, Texas
Real First Name: J
Camera: Canon
Can Others Edit My Photos: Yes
iTrader Rating: 0

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
04-07-2010, 10:13 PM


Try StartupCPL to see and disable any startup programs that seem suspicious or unwanted, as one of them can be the (goes a bit beyond msconfig)

Another possibility is someone has access to his email, so change the password to those and also the associated security questions.
Reply With Quote
  (#3) Old
Permanently Banned
 
CaptainTom's Avatar
 
Posts: 15,341
Join Date: Apr 2005
Location: Fort Worth, Tx,
Real First Name: Tom
Camera: canon
Can Others Edit My Photos: Yes
iTrader Rating: 24

Likes Received LIKES Received: 5
Likes Given LIKES Given: 0
04-07-2010, 10:14 PM


Can he change his password without using the keyboard? This would eliminate any keystroke hacking.
He'd then have to sign in that way as well.

Windows has an on screen keyboard that would be mouse controlled. I don't know where it is, but I've heard that as a way to get around the key logging.
Reply With Quote
  (#4) Old
Uber Poster
 
Rson's Avatar
 
Posts: 2,742
Join Date: May 2006
Location: Keller, Texas
Real First Name: Rich
Camera: A disposable from CVS
Can Others Edit My Photos: Yes
iTrader Rating: 0

Likes Received LIKES Received: 84
Likes Given LIKES Given: 14
04-07-2010, 10:22 PM


Hijackthis is great for that.....you can post the log here and we can dissect it
Reply With Quote
  (#5) Old
Forum Master
 
Nocturnus's Avatar
 
Posts: 1,620
Join Date: Dec 2004
Location: Austin, Texas
Real First Name: Ed
Camera: Canon 40d
Can Others Edit My Photos: Yes
iTrader Rating: 2

Likes Received LIKES Received: 16
Likes Given LIKES Given: 7
04-08-2010, 09:47 PM


Anytime I ever suspected I had a issue like that, I would just reinstall.

There is a free software out there that is like Norton Ghost. I'm going to start using this on my comptuers. Just install your OS, install all programs you want to have, then you run the software and it will clone your install. Then if you have a issue, you can just reimage your drive.

---------------------------
Ed Fay
http://www.photo-mojo.net
Reply With Quote
  (#6) Old
Premium Member
 
lscottpht's Avatar
 
Posts: 8,981
Join Date: Jan 2005
Location: McKinney, Texas
Real First Name: Leslie
Camera: Canon
Can Others Edit My Photos: Yes
iTrader Rating: 3

Likes Received LIKES Received: 133
Likes Given LIKES Given: 152
04-08-2010, 09:48 PM


ugh, my ex put that on my old laptop. took awhile to get rid of it, and i dont remember exactly how we did it...sorry!
Reply With Quote
  (#7) Old
The Sony Alpha Mod
 
groovyone's Avatar
 
Posts: 8,670
Join Date: Dec 2006
Location: Dickinson, Texas
Real First Name: Keith
Camera: Sony A900/A100/NEX-7
Can Others Edit My Photos: Yes
iTrader Rating: 5

Likes Received LIKES Received: 388
Likes Given LIKES Given: 564
04-08-2010, 09:49 PM


MalwareBytes is my weapon of choice. It found a mess of stuff Norton missed. The scan software is FREE too.

---------------------------
Sony|SonyIR|Sony NEX|Minolta Film|Polaroid
If I could tell the story in words, I wouldn't need to lug around a camera. ~Lewis Hine
"No one cares how hard you worked...but they will notice if you didn't work hard enough." -Ctein
Reply With Quote
  (#8) Old
Uber Poster
 
Dobick's Avatar
 
Posts: 3,712
Join Date: Jun 2005
Location: Slaton, Texas
Real First Name: Kent
Camera: Canon
Can Others Edit My Photos: Yes
iTrader Rating: 0

Likes Received LIKES Received: 33
Likes Given LIKES Given: 11
04-08-2010, 10:19 PM


if you install malwarebytes, get it updated, and then reboot into safemode to run it it is very effective.

not sure if it will find keyloggers or not though.

Lots of keyloggers run very stealth. You may not be able to find it through conventional means.

If you have a large external disk to move important files and pictures over, you might consider very seriously reformatting and doing a reload. Might be the lesser of evils

---------------------------
Nevermind -- I'll take care of it myself!
Reply With Quote
  (#9) Old
Uber Poster
 
ngoduyviet's Avatar
 
Posts: 2,864
Join Date: May 2006
Location: Stafford, Texas
Real First Name: Viet
Camera: Any
Can Others Edit My Photos: Yes
iTrader Rating: 35

Likes Received LIKES Received: 33
Likes Given LIKES Given: 4
Send a message via Skype™ to ngoduyviet
04-08-2010, 10:51 PM


Unfortunately it doesn't matter if you remove it. If your son plays WoW, you gotta tell him to stop downloading questionable / unknown plugins, and also not to buy / sell gold or virtual items online or from farmers. Those are the two main reason WoW players got keylogger on their computer. You can clean it, but it'll come right back.

BTW, McAfee & Norton are the two biggest waste of time. Get Avira, or Kaperski, or AVG and Malwarebyte, as well as what Rich suggested if you know what you are doing.

Best option is wipe it clean and reinstall WoW.

---------------------------
Blog
Reply With Quote
  (#10) Old
Forum Regular
 
TxLerman's Avatar
 
Posts: 582
Join Date: Jun 2005
Location: Houston, Texas
Real First Name: David
Camera: Canon 1D Mk IIII
Can Others Edit My Photos: No
iTrader Rating: 0

Likes Received LIKES Received: 9
Likes Given LIKES Given: 4
Send a message via Skype™ to TxLerman
04-09-2010, 07:54 AM


Quote:
Originally Posted by Nocturnus View Post
Anytime I ever suspected I had a issue like that, I would just reinstall.
+1

This is a difficult situation. They only sure way to remove it, is to reformat the hard drive and then reinstall all of the software from the original disks. This can be a long painstaking process, but it will solve the problem.

Another potential problem is that if your son's computer is on a home network and his computer is connected to other computers on the network, then it is possible that those computers are infected as well. I hate to raise an alarm if un-necessary, but our firm has a digital forensics lab and we have run into this in the past with our clients' computers. I would make sure that your son's computer did not have the other harddrives mapped to it from other computers and/or network storage devices.

After you remove the problem software, remember to the best defense are passwords that are alpa-numeric strings, that use lower and upper case, letters and numbers and are at least 20 characters long. The advantage here is that a brute force attack would require a network of computers and years of time to crack the password.

In the future if you are going to play online games like WOW, I would set-up a dedicated gaming computer that is completley isolated from any other computer and is not used for any other purpose. Think of it as a gaming cut-out. If it is hacked, all they will find are games and no personal information.

---------------------------
1D Mark III
Canon 20D
Nifty Fifty
100-400 L
70-200 2.8L non-IS
17-40L
24-70 f2.8L
Reply With Quote
  (#11) Old
Supa Dupa Poster
 
Murph's Avatar
 
Posts: 4,379
Join Date: Apr 2005
Location: San Antonio, Texas
Real First Name: Murph
Camera: Nikon and Yashica TLR
Can Others Edit My Photos: Yes
iTrader Rating: 3

Likes Received LIKES Received: 43
Likes Given LIKES Given: 11
04-09-2010, 07:58 AM


Two things: AVAST Anti-Virus avast! - Download Free Antivirus Software or Internet Security and Spybot S&D The home of Spybot-S&D!

If not see above to reformat/reinstall.

---------------------------
Texas can exist without the United States, but the United States, cannot, except at great peril, exist without Texas. Sam Houston.
Reply With Quote
  (#12) Old
Senior Member
 
Coogie's Avatar
 
Posts: 280
Join Date: Jun 2008
Location: Houston,
Real First Name: -
Camera: Nikon
Can Others Edit My Photos: No
iTrader Rating: 0

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
04-09-2010, 09:18 AM


+1 for what David said. Only sure fire way is to wipe everything off your computer and reinstall everything again. It's a pain in the ass but if you have a keylogger, who knows what else is on that computer too.
Reply With Quote
  (#13) Old
Senior Member
 
TimmyTheTag's Avatar
 
Posts: 328
Join Date: Feb 2008
Location: N. Ridgeville, Ohio
Real First Name: David
Camera: D300
Can Others Edit My Photos: Yes
iTrader Rating: 0

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
04-09-2010, 10:39 AM


+1 for newest updates/versions of Malwarebytes and Avast.
-1 on SpyBot, Norton and Mcafee

I use them all the time at work and they are the only ones I have found that find more real things than anything else and less false ones also. Norton and Mcafee aren't what they used to be and have to much BS built into them. Plus, the ones mentioned are better programs and free. They will also help stop future problems as well.
Reply With Quote
  (#14) Old
Premium Member
 
dbphotos's Avatar
 
Posts: 3,626
Join Date: Mar 2005
Location: Flower Mound (DFW), Texas
Real First Name: David
Camera: Nikon
Can Others Edit My Photos: No
iTrader Rating: 4

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
04-09-2010, 04:16 PM


Thanks guys I'm going to try the malware program several have recommended just to see if it finds it and then I'm going to reformat anyway. Its my son's computer and there is nothing important on it, so it will just take time.

---------------------------
| David Bailey Photography | Digital Racing Images | Sports Shooter | flickr | Grafix USA
I have a camera and some other stuff...
"Live your life in such a way that when your feet hit the floor satan shudders and says oh hell he's awake!"
Reply With Quote
  (#15) Old
Junior Member
 
kennyt's Avatar
 
Posts: 40
Join Date: Jan 2005
Location: Heartland, Texas
Real First Name: kenny
Camera: canon
Can Others Edit My Photos: No
iTrader Rating: 0

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
04-09-2010, 05:39 PM


Get him a Blizzard Authenticator. Keyloggers wont matter then for the WoW account then. Also tell him after the reformat to not click on any links he receives ingame or by email. The gold farmers love to scam people that way
Reply With Quote
Reply

Tags
key, logger

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Visit Our Sponsors
 

Google Sponsors

Premium Members do not see Google advertisements. SIGN UP today and help support our community.

Copyright ©2004 - 2011, Abel Longoria - www.Pixtus.com
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.