Skip to main content
Bug sweeps & TSCM · Blog

A spied-on computer: how to detect keyloggers and spyware on your PC.

The signs of a keylogger or spyware on PCs and notebooks, the mistakes that destroy the evidence and how a forensic IT sweep works. The guide from Arcadia Company's specialists for the North Milan area.

Your computer is the device everything passes through: home banking, email, work documents, private conversations. That is precisely why it has become the favorite target of anyone who wants to control someone - an ex-partner who knows details they should not know, a business partner who anticipates every move, a competitor who always gets there first on quotes and clients. When that happens, the suspicion often has a precise technical name: a keylogger or spyware installed on the PC.

Contrary to popular belief, a spied-on computer is not a rare occurrence reserved for executives and politicians: spy software can be found online for a few euros, installed in a few minutes of physical access to the machine - or with a well-crafted attachment - and can remain invisible for months. This guide explains how to recognize the signs, which mistakes to avoid so as not to destroy the evidence and how a professional IT sweep works.

Keyloggers and spyware: how spy software operates on a computer

The family of spy software for PCs is broad and constantly evolving. The most widespread categories:

  • Software keyloggers: they record every keystroke - passwords, messages, searches - and send the logs to whoever installed them. There are also hardware keyloggers: small adapters inserted between the keyboard and the computer, or modules concealed inside the keyboard itself.
  • Spyware and RATs (Remote Access Trojans): they hand a stranger remote control of the machine: watching the screen in real time, activating the webcam and microphone, copying files and browsing history.
  • Infostealers: malware designed to loot, in a matter of seconds, the credentials saved in the browser, session cookies and home-banking login details, to be resold or reused.

The most common way in is not a sophisticated attack: it is the physical access of someone close who knows (or guesses) the PC's password, followed by targeted phishing and the «useful» programs downloaded from unofficial sources.

The signs that your PC or notebook is being spied on

No symptom, on its own, is proof. But the combination of several signs justifies a serious technical check:

  • Slowdowns and fans constantly running even when the computer is idle: the capture and transmission processes consume resources.
  • Antivirus disabled without your intervention, or impossible to re-enable: many spyware programs neutralize it in order to survive.
  • Abnormal sessions and logins: emails marked as read that you don't remember opening, logins to your accounts from unknown devices or places, passwords that «stop working».
  • The webcam LED turning on by itself, windows appearing and disappearing at startup, unknown programs set to run automatically.
  • Abnormal network traffic toward unknown destinations, even when the computer is not in use.
  • Those around you know too much: the most important sign is not technical - details of private conversations, movements or negotiations known only to you that «leak» outside.

What not to do: the mistakes that destroy the evidence

The instinctive reaction - formatting everything and changing your passwords - is also the most damaging, for two reasons. First: formatting wipes out the digital evidence; without the logs, files and installation artifacts of the spy software, a criminal complaint loses much of its weight. Second: it often does not solve the problem, because if the credentials have already been copied, or the access runs through a cloud account, the surveillance resumes within hours.

Other frequent mistakes: changing your passwords from the same compromised computer (a keylogger records the new ones too), installing one «cleaner» downloaded from the internet after another, overwriting the traces, and talking about your suspicions near the devices or on the accounts that may be monitored.

How a professional IT sweep works

An IT sweep for malware and spyware is not a simple antivirus scan: it is a digital forensics operation that proceeds through documented phases.

  • Forensic acquisition: before any action is taken, a bit-by-bit copy of the storage media is created, with an integrity hash, following the best practices introduced with the ratification of the Budapest Convention (L. 48/2008): this is what makes the evidence usable in court.
  • Analysis: running processes, persistence mechanisms, browser extensions, scheduled tasks, network connections and system artifacts are examined in search of keyloggers, RATs and spyware, including the variants that commercial antivirus products fail to detect.
  • Removal and securing: controlled removal of the spy software, checks for any hardware keyloggers, credential rotation from a clean device and hardening of the machine and accounts.
  • Technical report: a dated and signed report documenting what was found, where and how - the foundation on which your lawyer can build the criminal complaint.

If the suspicion also involves your smartphone - and it often does: whoever controls the PC frequently controls everything - the operation extends to phone spyware removal. For the signs on your phone and covert listening devices, also read the guide on how to find hidden bugs and tell if your phone is tapped.

Spying on a computer is a crime: the legal framework

Installing spy software on another person's computer is not a «lapse in judgement»: it is a criminal offence, even between spouses and cohabiting partners. The main provisions:

  • Unauthorized access to a computer system (art. 615-ter c.p.): it punishes anyone who enters a protected system against the owner's will - even if they know the password.
  • Unlawful interception of computer communications (art. 617-quater c.p.) and installation of equipment designed to intercept them (art. 617-quinquies c.p.): they cover the capture of emails, chats and data traffic.

Law 90/2024 on cybersecurity has toughened the penalties for most computer crimes. Anyone who discovers they are being spied on is a victim: with the sweep's technical report, their lawyer can file a detailed criminal complaint, typically with the Postal Police. A point of method that is also a legal boundary: an investigative agency authorized pursuant to art. 134 TULPS acts exclusively on devices lawfully at the client's disposal and operates in compliance with EU Regulation 2016/679; identifying the perpetrator of the unauthorized access is a matter for the Judicial Authority, to which the report provides the technical elements needed to proceed.

Company computers: when the target is the business

For a company, a compromised computer is not just a privacy issue: it is the channel through which quotes, negotiations, intellectual property and ERP credentials pass. An infostealer on a single notebook can open the way to payment fraud and industrial espionage. In these cases the sweep is combined with corporate cyber security and digital forensics analysis: a perimeter extended to servers and email, and checks carried out in compliance with art. 4 of the Workers' Statute (L. 300/1970) and the GDPR when workstations used by employees are involved.

IT sweeps in Sesto San Giovanni, Milan and Brianza

Arcadia Company operates from its headquarters in Sesto San Giovanni (Piazza Don Mapelli 60), right on the northern belt of Milan and the province of Monza and Brianza: a laboratory for the forensic analysis of devices and on-site operations for businesses, planned with discretion and with costs defined before we begin. The method is ISO 9001 certified and authorized by the Prefecture.

If your computer «knows too much» about you and you fear someone else is reading it, do not format it: have it checked. A confidential preliminary consultation, protected by professional secrecy, comes with no commitment.

1,000+cases

Cases closed since 2017

9years

of uninterrupted activity

42cities

Operational cities in Italy

100% confidentiality

Zero confidentiality breaches

Let’s talk

Do you have a question?

The first consultation is always free and without obligation. We reply within 24 hours.

Fields marked with * are required.