PDA

View Full Version : Keyloggers



DrRusty
2008-08-02, 04:15 AM
I was wondering if there is a way to tell if there's a keylogger on someones computer, and this is the reason i'd like to know.

I let my friend play on my bandit for a little while, and he went to check my shop. In my shop there was one of those messages "hey i saw you in a video at (insert website here), and wow you were awesome!. Was that really you? It was a sweet video" well something like that. Anyways, my friend asked me the next day, "Rusty you were in a video ??" I asked him wtf he was talking about. He then told me about the message in my shop. I asked him if he went to the website, and he said why? I then told him that it was a hacking website and if you download anything that pops up from it, then you probably just got a keylogger on your computer. He swore to me up and down that he didn't go. Well I kicked him off my bandit just to be safe.

Well, last week, another friend that let that guy on his account got hacked. He lost a 66 atk craven and 40 luk katinas. I was wondering if there is a way to know for sure if there is a keylogger on a computer. I know my friend would never hack anyone else, because he's my RL friend and he doesn't even play MS anymore unless someone lets him play on their char.

bored4ever86
2008-08-02, 04:26 AM
there are many ways to "tell" if there is/eliminate a keylogger on your computer

1.Antivirus scanners can find them about 50-60% of the time
2.Strange processes mixed with outgoing tcp connections are 90% viruses
3.Many programs can show hidden processes that are running in your memory and can eliminate said processes

DrRusty
2008-08-02, 04:35 AM
there are many ways to "tell" if there is/eliminate a keylogger on your computer

1.Antivirus scanners can find them about 50-60% of the time
2.Strange processes mixed with outgoing tcp connections are 90% viruses
3.Many programs can show hidden processes that are running in your memory and can eliminate said processes

are there any links or examples I can use for him?

bored4ever86
2008-08-02, 05:01 AM
best way to get rid of it, if in fact there is one, is to use trendmicro's housecall

takes a while esp on a slow connection but its the best, most up to date, and most sure fire way i know of

loddlaen
2008-08-02, 05:44 AM
Also try a virus forum and post a hijack this log. They should be able to tell you if something isnt right.
Worst case scenario, you back up your harddrive and reformat =(

Tamekii
2008-08-02, 08:03 AM
I dont think keyloggers will get you hacked on MapleStory =)
The chance of getting is like,hmm...lemme see =)

95% of the things with keylogger,will never hack you in MS...
and if they will hack you in MS, Pin Crack was patched my son =)

Patched,and patched....do you know,how do a PinCracker feel after getting banned after five pins?:D!

But hey,i forgot about hacking email,maybe maybe..but still confusing.

So,maybe he gave the PW to someone?Thats what i believe in... =)

Acim
2008-08-02, 08:11 AM
95% of the things with keylogger,will never hack you in MS...
and if they will hack you in MS, Pin Crack was patched my son =)




Unfortunately, pin crackers aren't patched for people more experienced with programming than script kiddies. My cousin cracked his account when I was over his house a few days ago. =\ And, more complicated keyloggers take a screenshot of every mouse event you cause (i.e., clicking, scrolling, whatever). So they could tell your PIN too, if they were smart enough.

I wouldn't bother trying to find out if you have a keylogger, I would immediately scan my computer if anything suspicious like your story ever happened.

Tamekii
2008-08-02, 08:37 AM
KK,back =)
Was SP off or just meh?o.o

@ On Topic

What "people more experienced with programming than script kiddies." do to Bypass Nexon's Ban?=)

I dont think they can do something :O!

Unpack the Client and change it would take ages =)

Shinryuji
2008-08-02, 09:58 AM
as long as you didn't download anything you should be fine

never download something related to flash (fake upgrades or some crap from sites) unless you know the source/trust it

Lyssa
2008-08-02, 10:13 AM
as long as you didn't download anything you should be fine

never download something related to flash (fake upgrades or some crap from sites) unless you know the source/trust it

Even if you think you trust the source, the safest way to deal with an upgrade/update is to visit the official site and download it there.
The folks manning the scam mentioned by the OP did a decent job of making their fake download LOOK official, but simply reading the address bar puts up a big red flag.

As for keylogger detectors, I used this a few months back when a few friends of mine were worried about the safety of their accounts:
http://dewasoft.com/privacy/kldetector.htm

It didn't find anything on my computer but I already knew my machine was clean. I'd say the best way to test it would be to download a keylogger and see if that program catches it. Of course, you'd want to make sure your personal stuff was safe =p

~Lyssa

DrRusty
2008-08-02, 10:15 AM
as long as you didn't download anything you should be fine

never download something related to flash (fake upgrades or some crap from sites) unless you know the source/trust it

thats the thing; he said he didn't download anything, but I'm not sure if I should believe that or not since he had no clue it was a scam in the first place.

Bacon
2008-08-02, 01:13 PM
Keyloggers are extremely hard to detect. Most of the good ones have been programmed to stay hidden and show up as Windows Processes so as to not arouse suspicion. As others have suggested, the best way to keep yourself safe is to get a good virus scanner. However, since many viruses tend to disable your virus scanner, you might not discover anything. I'll also suggest using a good online Virus scanner. Here are just a few great free online virus scanners. Find one that you like and use it. Note that some of these only work until IE. I know, sounds odd, but they do work better.

Free Online Scanners

Kaspersky Online Scanner (http://www.kaspersky.com/kos/eng/partner/default/languages/english/check.html)

ESET's NOD32 Online Scanner (http://www.eset.com/onlinescan/index.php)

Trend Micro's Housecall Scanner (http://prerelease.trendmicro-europe.com/hc66/launch/)

BitDefender Scanner (http://www.bitdefender.com/scan8/ie.html)

Panda's Active Scan (http://www.pandasecurity.com/homeusers/solutions/activescan/)

Those should just get rid of the Keylogger. The next thing you should get you and your friend to do is to stay safe when browsing the internet. Download WinPatrol to make sure you don't get any unwanted start programs, and make sure you are running Firefox 3 with add-ons such as NoScript, SiteAdvisor, and WOT. Doing those things will ensure that you're as safe as possible.

NoScript is the main thing I'd want your friend to download. A lot of times, you might think you're not downloading anything because you don't accept to download stuff. However, if you allow certain script to run, those scripts might contain 'bad stuff'. Having NoScript will give you full control of what sites you allow to run scripts, and which sites you forbid.

@Lyssa: Are you sure that Dewasoft program is safe? It shows up in the Malware Domain List. (http://www.malwaredomainlist.com/mdl.php?search=dewasoft&colsearch=All&quantity=50)

Derimed
2008-08-02, 02:13 PM
DrRusty:

Before doing anything further, go to a reliable computer OTHER than the computer you suspect is infected, go to the Nexon website and CHANGE ALL YOUR INFO. All of it. Your pass, your secret questions, anything that comes to mind. Do this immediately. Once that is done, do not log onto your account from the computer that you are concerned may be infected with a keylogger. Along with changing your Maple info, change all other passwords that you may have typed, and which lead to valuable resources, such as your email account. Once you have done that, you have effectively rendered the hacker, (if he is there,) from accessing your Maple account. After you've done this, use software to detect and eliminate the keylogger, or prove to yourself that it is not around.

I personally wouldn't trust free internet scanners to detect a keylogger. Go to your electronics store, and buy a well-reputed security package, (if you haven't already.) I understand some people may have issues with McAffee or Norton, but I would be willing to bet that their stuff will do more for you than a free online scanner. A business dealing in online security protection stands more to lose if it fails, and they will have much more of a professional staff working for them. If you're paying NX to play Maple, paying some money for reliable security software should be a given; especially since that software will protect things much more important than Maple, such as your PayPal account. It's one thing to get your inventory cleaned out, but if some guy gets access to your PayPal or credit card info you're in deep shit.

Lyssa
2008-08-02, 08:47 PM
@Lyssa: Are you sure that Dewasoft program is safe? It shows up in the Malware Domain List. (http://www.malwaredomainlist.com/mdl.php?search=dewasoft&colsearch=All&quantity=50)

Like I said, I personally had no issues with it. It was recommended to me by chafalcar on sleepywood.

http://www.sleepywood.net/forum/showthread.php?t=1374407

~Lyssa

Rain
2008-08-02, 08:50 PM
The best way is to use an Anti-virus.

I cant believe scams like these are still out there!