Click here to get back home

How to detect keylogging / screen captuer software

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
How to detect keylogging / screen captuer software Mark Siler 09-06-2007
Posted by Mark Siler on September 6, 2007, 9:51 pm
Please log in for more thread options
I believe one or more of our computers in our corporate network have
keylogger/screen capture software installed. What software can detect these?
I contacted http://www.spectorsoft.com and they claim there is nothing that
can detect their software. This is very troubling if not?



Does anyone know if the hard drive is re-formatted will that remove these
applications or are they put someplace harder to get rid of?



Thanks!



Posted by Steve Riley [MSFT] on September 6, 2007, 10:11 pm
Please log in for more thread options
Some anti-spyware products can detect certain loggers, if they've been
updated to look for the particular signatures of them.

Certainly if you format the drive and reinstall Windows, then the malware
will be gone. Then it's important to think about how to lessen the
likelihood of another infection occurring. The best thing you can do is run
as standard user, not administrator. Loggers typically need admin privileges
to install and function correctly. By running as standard user, these things
won't work.

--
Steve Riley
steve.riley@microsoft.com
http://blogs.technet.com/steriley
http://www.protectyourwindowsnetwork.com


>I believe one or more of our computers in our corporate network have
>keylogger/screen capture software installed. What software can detect
>these? I contacted http://www.spectorsoft.com and they claim there is
>nothing that can detect their software. This is very troubling if not?
>
>
>
> Does anyone know if the hard drive is re-formatted will that remove these
> applications or are they put someplace harder to get rid of?
>
>
>
> Thanks!
>
>

Posted by Mark Siler on September 6, 2007, 10:50 pm
Please log in for more thread options
The person who did this was the network admin. not a "standard" user.

> Some anti-spyware products can detect certain loggers, if they've been
> updated to look for the particular signatures of them.
>
> Certainly if you format the drive and reinstall Windows, then the malware
> will be gone. Then it's important to think about how to lessen the
> likelihood of another infection occurring. The best thing you can do is
> run as standard user, not administrator. Loggers typically need admin
> privileges to install and function correctly. By running as standard user,
> these things won't work.
>
> --
> Steve Riley
> steve.riley@microsoft.com
> http://blogs.technet.com/steriley
> http://www.protectyourwindowsnetwork.com
>
>
>>I believe one or more of our computers in our corporate network have
>>keylogger/screen capture software installed. What software can detect
>>these? I contacted http://www.spectorsoft.com and they claim there is
>>nothing that can detect their software. This is very troubling if not?
>>
>>
>>
>> Does anyone know if the hard drive is re-formatted will that remove these
>> applications or are they put someplace harder to get rid of?
>>
>>
>>
>> Thanks!
>>
>>



Posted by Steve Riley [MSFT] on September 6, 2007, 11:53 pm
Please log in for more thread options
Uh oh. Alas, you no longer have a technical problem. I think you know what
needs to happen next.

http://www.microsoft.com/technet/community/columns/secmgmt/sm0705.mspx
http://blogs.technet.com/steriley/archive/2007/05/31/when-you-say-goodbye-to-an-employee.aspx


--
Steve Riley
steve.riley@microsoft.com
http://blogs.technet.com/steriley
http://www.protectyourwindowsnetwork.com


> The person who did this was the network admin. not a "standard" user.
>
>> Some anti-spyware products can detect certain loggers, if they've been
>> updated to look for the particular signatures of them.
>>
>> Certainly if you format the drive and reinstall Windows, then the malware
>> will be gone. Then it's important to think about how to lessen the
>> likelihood of another infection occurring. The best thing you can do is
>> run as standard user, not administrator. Loggers typically need admin
>> privileges to install and function correctly. By running as standard
>> user, these things won't work.
>>
>> --
>> Steve Riley
>> steve.riley@microsoft.com
>> http://blogs.technet.com/steriley
>> http://www.protectyourwindowsnetwork.com
>>
>>
>>>I believe one or more of our computers in our corporate network have
>>>keylogger/screen capture software installed. What software can detect
>>>these? I contacted http://www.spectorsoft.com and they claim there is
>>>nothing that can detect their software. This is very troubling if not?
>>>
>>>
>>>
>>> Does anyone know if the hard drive is re-formatted will that remove
>>> these applications or are they put someplace harder to get rid of?
>>>
>>>
>>>
>>> Thanks!
>>>
>>>
>
>

Posted by Mathieu CHATEAU on September 7, 2007, 6:39 am
Please log in for more thread options
Since it's a "commercial" product, he may have been asked to do so ?


--
Cordialement,
Mathieu CHATEAU
http://lordoftheping.blogspot.com


> The person who did this was the network admin. not a "standard" user.
>
>> Some anti-spyware products can detect certain loggers, if they've been
>> updated to look for the particular signatures of them.
>>
>> Certainly if you format the drive and reinstall Windows, then the malware
>> will be gone. Then it's important to think about how to lessen the
>> likelihood of another infection occurring. The best thing you can do is
>> run as standard user, not administrator. Loggers typically need admin
>> privileges to install and function correctly. By running as standard
>> user, these things won't work.
>>
>> --
>> Steve Riley
>> steve.riley@microsoft.com
>> http://blogs.technet.com/steriley
>> http://www.protectyourwindowsnetwork.com
>>
>>
>>>I believe one or more of our computers in our corporate network have
>>>keylogger/screen capture software installed. What software can detect
>>>these? I contacted http://www.spectorsoft.com and they claim there is
>>>nothing that can detect their software. This is very troubling if not?
>>>
>>>
>>>
>>> Does anyone know if the hard drive is re-formatted will that remove
>>> these applications or are they put someplace harder to get rid of?
>>>
>>>
>>>
>>> Thanks!
>>>
>>>
>
>


Similar ThreadsPosted
How to Detect All Connections? October 19, 2005, 2:34 pm
CTRL-ALT-DEL SCREEN VANISHES February 22, 2006, 5:50 pm
Turning off auto-screen-lock? March 10, 2006, 11:02 am
File Screen only send out email once September 6, 2007, 4:32 am
Enable Automatic Screen Lock Group Policy May 30, 2006, 1:41 pm
Firewall Software and ASP .NET February 14, 2006, 3:10 pm
cannot install software January 10, 2007, 6:44 pm
restricting software installation July 27, 2005, 10:41 am
Windows software inventory? Is there a way? February 28, 2006, 3:47 pm
Quick Software Audit March 1, 2006, 6:02 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap