How to detect keylogging / screen captuer software

How to detect keylogging / screen captuer software

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
How to detect keylogging / screen captuer software Mark Siler 09-06-2007
Posted by Mark Siler on September 6, 2007, 9:51 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I believe one or more of our computers in our corporate network have
keylogger/screen capture software installed. What software can detect these?
I contacted http://www.spectorsoft.com and they claim there is nothing that
can detect their software. This is very troubling if not?



Does anyone know if the hard drive is re-formatted will that remove these
applications or are they put someplace harder to get rid of?



Thanks!



Posted by Steve Riley [MSFT] on September 6, 2007, 10:11 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Some anti-spyware products can detect certain loggers, if they've been
updated to look for the particular signatures of them.

Certainly if you format the drive and reinstall Windows, then the malware
will be gone. Then it's important to think about how to lessen the
likelihood of another infection occurring. The best thing you can do is run
as standard user, not administrator. Loggers typically need admin privileges
to install and function correctly. By running as standard user, these things
won't work.

--
Steve Riley
steve.riley@microsoft.com
http://blogs.technet.com/steriley
http://www.protectyourwindowsnetwork.com


>I believe one or more of our computers in our corporate network have
>keylogger/screen capture software installed. What software can detect
>these? I contacted http://www.spectorsoft.com and they claim there is
>nothing that can detect their software. This is very troubling if not?
>
>
>
> Does anyone know if the hard drive is re-formatted will that remove these
> applications or are they put someplace harder to get rid of?
>
>
>
> Thanks!
>
>

Posted by Mark Siler on September 6, 2007, 10:50 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
The person who did this was the network admin. not a "standard" user.

> Some anti-spyware products can detect certain loggers, if they've been
> updated to look for the particular signatures of them.
>
> Certainly if you format the drive and reinstall Windows, then the malware
> will be gone. Then it's important to think about how to lessen the
> likelihood of another infection occurring. The best thing you can do is
> run as standard user, not administrator. Loggers typically need admin
> privileges to install and function correctly. By running as standard user,
> these things won't work.
>
> --
> Steve Riley
> steve.riley@microsoft.com
> http://blogs.technet.com/steriley
> http://www.protectyourwindowsnetwork.com
>
>
>>I believe one or more of our computers in our corporate network have
>>keylogger/screen capture software installed. What software can detect
>>these? I contacted http://www.spectorsoft.com and they claim there is
>>nothing that can detect their software. This is very troubling if not?
>>
>>
>>
>> Does anyone know if the hard drive is re-formatted will that remove these
>> applications or are they put someplace harder to get rid of?
>>
>>
>>
>> Thanks!
>>
>>



Posted by Aaron on September 6, 2007, 11:24 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Mark Siler wrote:
> The person who did this was the network admin. not a "standard" user.
>
>> Some anti-spyware products can detect certain loggers, if they've been
>> updated to look for the particular signatures of them.
>>
>> Certainly if you format the drive and reinstall Windows, then the malware
>> will be gone. Then it's important to think about how to lessen the
>> likelihood of another infection occurring. The best thing you can do is
>> run as standard user, not administrator. Loggers typically need admin
>> privileges to install and function correctly. By running as standard user,
>> these things won't work.
>>
>> --
>> Steve Riley
>> steve.riley@microsoft.com
>> http://blogs.technet.com/steriley
>> http://www.protectyourwindowsnetwork.com
>>
>>> I believe one or more of our computers in our corporate network have
>>> keylogger/screen capture software installed. What software can detect
>>> these? I contacted http://www.spectorsoft.com and they claim there is
>>> nothing that can detect their software. This is very troubling if not?
>>>
>>> Does anyone know if the hard drive is re-formatted will that remove these
>>> applications or are they put someplace harder to get rid of?
>>>
>>> Thanks!

From your posts here it sounds as though the owner, or authorized
representative of the owner, has installed the possible keylogger(s).

If you did manage to remove it, would they take punitive action against
you for doing so?

If they are not responsible for its presence, are they responsible for
its removal?

Remember, if they own it, they may be legally allowed to take actions to
monitor its use. It is their resource; they can be held responsible in a
legal proceeding for actions performed using their computer: libelous
email, surfing to bad websites, inappropriate pictures found on the
computer, etc.

In short: IF it is the corporation's property, and the corporation is
responsible for the presence of monitoring software, they can probably
legally monitor what you do with their property. Where I work, when I
log into the company network there is a large splash screen saying, in
about ten sentences, "Big Brother IS watching YOU".

--
I'm glad my Mom named me Aaron,
That's what everybody calls me.

Posted by Steve Riley [MSFT] on September 6, 2007, 11:53 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Uh oh. Alas, you no longer have a technical problem. I think you know what
needs to happen next.

http://www.microsoft.com/technet/community/columns/secmgmt/sm0705.mspx
http://blogs.technet.com/steriley/archive/2007/05/31/when-you-say-goodbye-to-an-employee.aspx


--
Steve Riley
steve.riley@microsoft.com
http://blogs.technet.com/steriley
http://www.protectyourwindowsnetwork.com


> The person who did this was the network admin. not a "standard" user.
>
>> Some anti-spyware products can detect certain loggers, if they've been
>> updated to look for the particular signatures of them.
>>
>> Certainly if you format the drive and reinstall Windows, then the malware
>> will be gone. Then it's important to think about how to lessen the
>> likelihood of another infection occurring. The best thing you can do is
>> run as standard user, not administrator. Loggers typically need admin
>> privileges to install and function correctly. By running as standard
>> user, these things won't work.
>>
>> --
>> Steve Riley
>> steve.riley@microsoft.com
>> http://blogs.technet.com/steriley
>> http://www.protectyourwindowsnetwork.com
>>
>>
>>>I believe one or more of our computers in our corporate network have
>>>keylogger/screen capture software installed. What software can detect
>>>these? I contacted http://www.spectorsoft.com and they claim there is
>>>nothing that can detect their software. This is very troubling if not?
>>>
>>>
>>>
>>> Does anyone know if the hard drive is re-formatted will that remove
>>> these applications or are they put someplace harder to get rid of?
>>>
>>>
>>>
>>> Thanks!
>>>
>>>
>
>

Similar ThreadsPosted
Detect what software is blocking connections January 26, 2006, 11:49 am
How to detect antivirus software on a system December 20, 2007, 4:34 am
How to detect malware? December 21, 2008, 5:47 pm
detect account type October 5, 2006, 11:07 am
Keyloggers - does antivirus detect them December 4, 2006, 7:59 pm
How to detect the signature of a file September 2, 2008, 8:29 am
Detect cookie additions immediately - How to? February 22, 2006, 9:31 am
detect when a computer joins the network January 13, 2007, 8:24 am
Reliable way to detect presence of macros August 24, 2007, 4:52 pm
how does a website detect a visitor's PC/Router MAC address? is it possible? May 3, 2006, 8:29 am

The site map in XML format XML site map

Contact Us | Privacy Policy