Register for your free account! | Forgot your password?

You last visited: Today at 08:29

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



[Guide] About keyloggers

Discussion on [Guide] About keyloggers within the S4 League Hacks, Bots, Cheats & Exploits forum part of the S4 League category.

Reply
 
Old   #1
 
ero-Z's Avatar
 
elite*gold: 0
Join Date: Dec 2009
Posts: 469
Received Thanks: 1,341
[Guide] About keyloggers

Hi, I have recived a lot of private messages about 'basic tips' for remove a keylogger, so I'll try to explain it shortly...

What is a keylogger?

A keylogger is a program that looks for in your computer passwords/accounts, also register the pressed keys!, then the keylogger send the information to his owner.

Symptoms

A slow keyboard
Internet speed slow
Processes generally slow down

What should I do?

If you're infected the first thing you should do is stop the process, search for a strange process launched by your user. (Maybe "svechost.exe" or "bluewind.exe" process), you can use to know where the process was launched.

Then you should delete it, (maybe in "YourHomeDrive\Windows\System32").

Also the RunKey in Windows startup! "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run" (in your "regedit.exe"), this is an example, "KEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\Keylogger"

And check this dir (at Vista/Win7) -> "C:\Users\<YourUsername>\AppData\Local\Temp"

"" is a free tool that will erase all your temporal trash.

And, of course, a good scan! You should close your internet conection while you are scanning your computer! Also an Anti-spyware or software anti-keylogging. works right.

To prevent:

ATM, don't download anything new.

More information -> Here

That's all, I hope that this 'easy tips' will help you. Any question/something to add, feel free to comment.

Greetings.

Thanks to Honeysweet, FichteFoll, _Alastor_, Teiva, Forfirith for add.
@FichteFoll, nice! I'm from the old-school way xD


Add by FichteFoll:

You should try the . Download, unpack and start the .
There you can enable all suspected programs (use the Tab "Logon").
Or just run the msconfig.exe and go to "Systemstart" (<- Dunno how Windows translates it to english).

Many Keyloggers/Trojans try to immitate the svchost themselves.
To give you some orientation:



What I've marked:
1. This is usually started with windows.
2. This is extra-information on which you can identify the serviceHost. As I highlighted, this is a SERVICE-process from windows. So it has to be found inside the services.exe.
3. For more information you can look at the "Company Name" Tab or the "Path" (you can enable them manually). It's selfexplaining I think.
4. These 2 (and the explorer.exe) are also started from windows... and actually the last in the list (sort).
Any process AFTER them with a name like "csrrss.exe", "svchost.exe" or another version is obviously malware!

There also shouldn't be a "svchost.exe" here:



Look at the Tooltip for this example. This is the sidebar in Windows 7, but otherwise there shouldn't be stuff from Windows here, cuz it's lauchned from somewhere else.

If you can't kill them or delete them from autostart (it also starts after you've deleted it), run Windows in "save mode" and delete the file itself, after checking the its path.

Add by Forfirith

What is csrss.exe?

A Microsoft Windows file stored in the c:\windows\system32 or c:\winnt\system32 directory that has the file description: "Client Server Runtime process." This file

Is this file a spyware, trojan, or virus?

The csrss.exe file included with Microsoft Windows is not spyware, a trojan, or a virus. However, like any file on your computer it can become corrupted by a virus, worm, or trojan. antivirus programs can detect and clean this file if it has become infected. Because this file is part of Microsoft Windows users should never delete or remove this file if they think it is infected, let the antivirus program handle it.

Is it safe to remove csrss.exe from the Task Manager processes?

No. The csrss.exe is a critical system process that cannot be removed from the Task Manager without causing issues with Windows. When attempting to End Process the csrss.exe you will receive the Unable to Terminate Process window with the error "This is a critical system process. Task Manager cannot end this process." It is normal to receive this error.

The csrss.exe file is using 99%, 100%, or other high abnormal percentage of CPU.

This issue is caused when your Microsoft Windows profile is corrupt. To resolve this issue requires that you delete and recreate the profile. To do this follow the below steps.

Backup all the files in My Documents as they will be lost. It's also recommended you backup any other important files you may be concerned about loosing.
Log out of the account that is causing the problem and into a different account. If you do not have another account you can create a new account through the User Accounts icon in the Control Panel.
Once in the other account right-click My Computer icon and click Properties.
In the Properties window click the Advanced tab.
In Advanced click the Settings button under User Profiles.
Finally, in the User Profiles window highlight the name of the profile that is encountering this issue and click the Delete button.
Once the profile has been deleted you can recreate it if you wish to use the same profile name.
Attached Images
File Type: jpg OWvoQ.jpg (22.4 KB, 281 views)
File Type: jpg 3Q7BI.jpg (18.7 KB, 338 views)
ero-Z is offline  
Thanks
198 Users
Old 06/07/2010, 17:45   #2
 
elite*gold: 380
Join Date: Aug 2009
Posts: 753
Received Thanks: 5,089
Nice job =D
You got my thanks !

#Vote4Sticky
-I.Paradise- is offline  
Thanks
11 Users
Old 06/07/2010, 17:46   #3
 
kerochan26's Avatar
 
elite*gold: 0
Join Date: Mar 2010
Posts: 73
Received Thanks: 43
Thanks, ero-Z I need it u.u
kerochan26 is offline  
Thanks
5 Users
Old 06/07/2010, 17:48   #4
 
[B]urning[S]tar's Avatar
 
elite*gold: 0
Join Date: Nov 2009
Posts: 670
Received Thanks: 267
Thanks and tnaks again for helping me already
[B]urning[S]tar is offline  
Thanks
6 Users
Old 06/07/2010, 17:48   #5
 
elite*gold: 0
Join Date: Sep 2009
Posts: 140
Received Thanks: 408
bes como es normal que te roben la cuenta por ser confiado, ahora lo que ba a pasar es que nadie confia de nadie, yo almenos ya no me fio de nadie.
s0n1k is offline  
Thanks
2 Users
Old 06/07/2010, 17:49   #6
 
ero-Z's Avatar
 
elite*gold: 0
Join Date: Dec 2009
Posts: 469
Received Thanks: 1,341
Quote:
Originally Posted by s0n1k View Post
bes como es normal que te roben la cuenta por ser confiado, ahora lo que ba a pasar es que nadie confia de nadie, yo almenos ya no me fio de nadie.
Te aseguro que no te volvera a pasar otra ves, nada mejor como la cosecha de una mismo.
ero-Z is offline  
Thanks
10 Users
Old 06/07/2010, 17:50   #7
 
Riotblade's Avatar
 
elite*gold: 0
Join Date: Nov 2009
Posts: 55
Received Thanks: 30
nice guide you got my thanks
Riotblade is offline  
Thanks
3 Users
Old 06/07/2010, 17:55   #8
 
[B]urning[S]tar's Avatar
 
elite*gold: 0
Join Date: Nov 2009
Posts: 670
Received Thanks: 267
I deleted the things in "HKEY_LOCAN_MACHINE" u said and now my internet is faster than befor!

i thing it should be sticked as a warning @ all users
[B]urning[S]tar is offline  
Thanks
4 Users
Old 06/07/2010, 17:58   #9
 
elite*gold: 280
Join Date: Apr 2010
Posts: 998
Received Thanks: 1,501
Nice Thread!
#Vote 4 Sticky dude
[NoctisNexilis] is offline  
Thanks
5 Users
Old 06/07/2010, 18:04   #10
 
elite*gold: 0
Join Date: Jun 2009
Posts: 236
Received Thanks: 30
gj danke
themaster95 is offline  
Thanks
2 Users
Old 06/07/2010, 18:08   #11
 
elite*gold: 0
Join Date: Jan 2010
Posts: 87
Received Thanks: 14
Unnötig.
Falsche Section....
AliYOrulmaz is offline  
Old 06/07/2010, 18:13   #12
 
kerochan26's Avatar
 
elite*gold: 0
Join Date: Mar 2010
Posts: 73
Received Thanks: 43
Quote:
Originally Posted by Honeysweet View Post
And check this dir(at Vista/Win7) -> C:\Users\<YourUsername>\AppData\Local\Temp .
Tnks, I detect 1 thing... an archive appears, desapears O_O the name of archive is ***.*** O_O
kerochan26 is offline  
Old 06/07/2010, 18:19   #13
 
elite*gold: 380
Join Date: Aug 2009
Posts: 753
Received Thanks: 5,089
Quote:
Originally Posted by AliYOrulmaz View Post
Unnötig.
Falsche Section....
It isn't a question so why "falshe section" ?
-I.Paradise- is offline  
Thanks
2 Users
Old 06/07/2010, 18:21   #14
 
ero-Z's Avatar
 
elite*gold: 0
Join Date: Dec 2009
Posts: 469
Received Thanks: 1,341
Quote:
Originally Posted by AliYOrulmaz View Post
Unnötig.
Falsche Section....
It's not a question, it's a guide 'how to help with a problem in this forum', so I think that I am in the correct section.

Quote:
Originally Posted by _Alastor_ View Post
You fail to realize that I do NOT speak german.
I just love this^
ero-Z is offline  
Thanks
10 Users
Old 06/07/2010, 18:25   #15
 
elite*gold: 0
Join Date: Jan 2010
Posts: 87
Received Thanks: 14
Ich weiß nicht ob ihr lesen könnt, aber hier steht ---> S4 League Hacks, Bots, Cheats & Exploits

Hier sollten eig. nur Hacks usw.. rein .. ^^
AliYOrulmaz is offline  
Reply

Tags
ero-z, guide, keylogger, zerotheaprendice


Similar Threads Similar Threads
[Guide] Tools Spyware,keyloggers..delete 'em all - Anti Hacker
05/29/2009 - SRO Guides & Templates - 13 Replies
Hey, I want to open a thread about tools which delete spyware,clean the registry and so on. You can also post tools/programs with a text,downloadlink and eventually a screenshot. And i will update it into the main post -=== Anti - Spyware ===- 1. Ad-Aware 2007 I think most people know Ad-Aware 2007.It's one of the best anti-spyware program. It scans your computer for spywares,tracks etc. This version is for free.You can also download a language pack from the official website.
[GUIDE]How to prevent keyloggers from bots/hacks
05/31/2008 - Cabal Guides & Templates - 17 Replies
Due to the Latest Issue on KeyLoggers on a certain Bots(Im not pointing w/c is w/c),here is a way to prevent them.. Things you needed: 2 PC w/c both have internet access Steps: 1. At the 1st PC,Use the bot of your choice then log-In Your Account 2. After you have Logged into the game,go to the 2nd PC and goto cabal site(e.g. cabalonline.com, ogplanet.com) 3. Immediately Log-In to the site and Change Password(Remember your new passwordNOTE:Be sure that the 2nd PC is clean of keyloggers...



All times are GMT +1. The time now is 08:29.


Powered by vBulletin®
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2025 elitepvpers All Rights Reserved.