Page 2 of 2 FirstFirst 12
Results 11 to 20 of 48

Thread: How can I tell if a keylogger got added to my PC while I was in Beijing?

Hybrid View

  1. #1
    David H. Lipman Guest

    Re: How can I tell if a keylogger got added to my PC while I was in Beijing?

    From: "Steve Riley [MSFT]" <steve.riley@microsoft.com>

    | I've heard these rumors before, too, and I'm not convinced they're true.
    | I've traveled to China several times, it isn't the monolithic evil empire
    | that bulletins like this would seem to indicate. Any laptop left anyplace
    | unattended has risk; drive encryption like BitLocker is really the only way
    | to mitigate such attacks (other than keeping the laptop with you at all
    | times).

    This is *not* a rumour!

    A warning was issued about Blackberries as well.

    You said "I'm not convinced they're true".
    Then you are naive.

    You obviously have not read any Chinese threat assesments.


    --
    Dave
    http://www.claymania.com/removal-trojan-adware.html
    Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



  2. #2
    Dustin Cook Guest

    Re: How can I tell if a keylogger got added to my PC while I was in Beijing?

    "Steve Riley [MSFT]" <steve.riley@microsoft.com> wrote in
    news:E3C4B9CE-9821-4AB1-A7B4-F523991E1416@microsoft.com:

    > I've heard these rumors before, too, and I'm not convinced they're
    > true. I've traveled to China several times, it isn't the monolithic
    > evil empire that bulletins like this would seem to indicate. Any
    > laptop left anyplace unattended has risk; drive encryption like
    > BitLocker is really the only way to mitigate such attacks (other than
    > keeping the laptop with you at all times).
    >


    Depending on where you go in China, if you leave a laptop behind, yes,
    someone might come along and install something and not take your laptop.
    Why would they do this? Having remote access is more valuable, let you
    decrypt the data for them.

    If you suspect your computer has been compromised, I wouldn't even bother
    scanning it unless your a pro; and are willing and know how to go low level
    on your own. If you don't have the skills, secure wipe the drive, and
    reload the system from known clean backups. In the future, keep all
    important data safe and encrypted. Using a proprierty encryption system for
    the entire HD isn't a bad idea in this case. That way, no password, no
    access, no dropping/installing anything.


    --
    Regards,
    Dustin Cook, Author of BugHunter
    BugHunter - http://bughunter.it-mate.co.uk
    MalwareBytes - http://www.malwarebytes.org



  3. #3
    Juan I. Cahis Guest

    Re: How can I tell if a keylogger got added to my PC while I was in Beijing?

    Dear Dustin & friends:

    Dustin Cook <bughunter.dustin@gmail.com> wrote:

    >"Steve Riley [MSFT]" <steve.riley@microsoft.com> wrote in
    >news:E3C4B9CE-9821-4AB1-A7B4-F523991E1416@microsoft.com:
    >
    >> I've heard these rumors before, too, and I'm not convinced they're
    >> true. I've traveled to China several times, it isn't the monolithic
    >> evil empire that bulletins like this would seem to indicate. Any
    >> laptop left anyplace unattended has risk; drive encryption like
    >> BitLocker is really the only way to mitigate such attacks (other than
    >> keeping the laptop with you at all times).
    >>

    >
    >Depending on where you go in China, if you leave a laptop behind, yes,
    >someone might come along and install something and not take your laptop.
    >Why would they do this? Having remote access is more valuable, let you
    >decrypt the data for them.
    >
    >If you suspect your computer has been compromised, I wouldn't even bother
    >scanning it unless your a pro; and are willing and know how to go low level
    >on your own. If you don't have the skills, secure wipe the drive, and
    >reload the system from known clean backups. In the future, keep all
    >important data safe and encrypted. Using a proprierty encryption system for
    >the entire HD isn't a bad idea in this case. That way, no password, no
    >access, no dropping/installing anything.


    To encrypt the hard disk is a very good security measure if the laptop
    is stolen, but it is useless to avoid a keylogger install.

    To be able to install a keylogger, the user should be logged in with
    Administrator features, and I supposed that the user didn't leave the
    computer unattended *and* powered on *and* logged in, did you?


    Thanks
    Juan I. Cahis
    Santiago de Chile (South America)
    Note: Please forgive me for my bad English, I am trying to improve it!

  4. #4
    Mark McIntyre Guest

    Re: How can I tell if a keylogger got added to my PC while I wasin Beijing?

    Juan I. Cahis wrote:
    >
    > To be able to install a keylogger, the user should be logged in with
    > Administrator features, and I supposed that the user didn't leave the
    > computer unattended *and* powered on *and* logged in, did you?


    If the hacker has physical access to the computer, all bets are off. He
    can boot from a CD or pendrive and install whatever the heck he likes on
    the laptop.

  5. #5
    Juan I. Cahis Guest

    Re: How can I tell if a keylogger got added to my PC while I was in Beijing?

    Mark McIntyre <markmcintyre@TROUSERSspamcop.net> wrote:

    >Juan I. Cahis wrote:
    >>
    >> To be able to install a keylogger, the user should be logged in with
    >> Administrator features, and I supposed that the user didn't leave the
    >> computer unattended *and* powered on *and* logged in, did you?

    >
    >If the hacker has physical access to the computer, all bets are off. He
    >can boot from a CD or pendrive and install whatever the heck he likes on
    >the laptop.


    Unless you have set the BIOS password, which any respectable SysAdmin
    of any respectable business corporation doing international business
    should always have set.


    Thanks
    Juan I. Cahis
    Santiago de Chile (South America)
    Note: Please forgive me for my bad English, I am trying to improve it!

  6. #6
    Kerry Brown Guest

    Re: How can I tell if a keylogger got added to my PC while I was in Beijing?

    "Mark McIntyre" <markmcintyre@TROUSERSspamcop.net> wrote in message
    news:09jOk.252876$5p1.56150@en-nntp-06.dc1.easynews.com...
    > Juan I. Cahis wrote:
    >>
    >> To be able to install a keylogger, the user should be logged in with
    >> Administrator features, and I supposed that the user didn't leave the
    >> computer unattended *and* powered on *and* logged in, did you?

    >
    > If the hacker has physical access to the computer, all bets are off. He
    > can boot from a CD or pendrive and install whatever the heck he likes on
    > the laptop.



    If the laptop fully supports bitlocker and bitlocker is used, physical
    access won't help you gain access to the contents of the hard drive.

    --
    Kerry Brown
    MS-MVP - Windows Desktop Experience: Systems Administration
    http://www.vistahelp.ca/phpBB2/
    http://vistahelpca.blogspot.com/





  7. #7
    Dustin Cook Guest

    Re: How can I tell if a keylogger got added to my PC while I was in Beijing?

    Mark McIntyre <markmcintyre@TROUSERSspamcop.net> wrote in news:09jOk.252876
    $5p1.56150@en-nntp-06.dc1.easynews.com:

    > Juan I. Cahis wrote:
    >>
    >> To be able to install a keylogger, the user should be logged in with
    >> Administrator features, and I supposed that the user didn't leave the
    >> computer unattended *and* powered on *and* logged in, did you?

    >
    > If the hacker has physical access to the computer, all bets are off. He
    > can boot from a CD or pendrive and install whatever the heck he likes on
    > the laptop.
    >


    Not if the HD is entirely encrypted he can't. It would do him no good
    whatsoever to boot from cd, no data to read. No drive to load anything
    onto.


    --
    Regards,
    Dustin Cook, Author of BugHunter
    BugHunter - http://bughunter.it-mate.co.uk
    MalwareBytes - http://www.malwarebytes.org



  8. #8
    Dennis Guest

    Re: How can I tell if a keylogger got added to my PC while I wasin Beijing?

    In article <09jOk.252876$5p1.56150@en-nntp-06.dc1.easynews.com>, Mark McIntyre <markmcintyre@TROUSERSspamcop.net> wrote:
    >Juan I. Cahis wrote:
    >>
    >> To be able to install a keylogger, the user should be logged in with
    >> Administrator features, and I supposed that the user didn't leave the
    >> computer unattended *and* powered on *and* logged in, did you?

    >
    >If the hacker has physical access to the computer, all bets are off. He
    >can boot from a CD or pendrive and install whatever the heck he likes on
    >the laptop.


    Pop the hard drive out, lock it up, hide it, take it with you. It's very
    simple.

    Dennis
    =================

    Posted Via Usenet.com Premium Usenet Newsgroup Services
    ----------------------------------------------------------
    http://www.usenet.com

  9. #9
    Anne & Lynn Wheeler Guest

    Re: How can I tell if a keylogger got added to my PC while I was in Beijing?


    Donna Ohl <donna.ohl@sbcglobal.net> writes:
    > I was in Beijing, and I used my Windows PC there with a freeware firewall
    > and freeware anti virus and freeware malware scanners.
    >
    > Recently a friend said nearly all American travelers were to be warned by
    > the State Department that their laptops, if left in the hotel, were almost
    > certainly compromised.
    >
    > How could I tell if a keylogger or other spyware was inserted onto my
    > laptop by the Chinese?


    recent news with more sophisticated flavor ... which mentions having
    lots of countermeasures against detection:

    Three Year Old Trojan Compromised Half Million Banking Details - The
    exact origins of the Trojan have not been determined yet
    http://news.softpedia.com/news/Three...ls-96953.shtml
    Trojan steals 500,000+ bank and card details
    http://www.finextra.com/fullstory.asp?id=19217
    'Ruthless' Trojan horse steals 500k bank, credit card log-ons
    http://www.computerworld.com/action/...icleId=9118718
    Advanced Trojan Virus Compromises Bank Info
    http://www.redorbit.com/news/technol...nfo/index.html
    Sinowal data-stealing trojan has infected half million PCs
    http://www.scmagazineus.com/Sinowal-...rticle/120243/

    part of archived (linkedin) thread (regarding article from Kansas City
    FED: Can Smart Cards Reduce Payments Fraud and Identity Theft?) that
    includes discussion of countermeasures for compromised PCs
    http://www.garlic.com/~lynn/2008p.html#28
    http://www.garlic.com/~lynn/2008p.html#32

    --
    40+yrs virtualization experience (since Jan68), online at home since Mar70

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •