03-06-2009 04:19 AM
I have a keylogger on my computer and Norton 2009 cannot detect/find it.
I know I have a keylogger because my World of Warcraft account had been hacked via it. Yet I can do a full system scan for the 5th time -- with updated detection library ofc -- and Norton still cannot find the keylogger.
This was the first year I decided to replace AVG with Norton. And within 2.5 months I have a serious security breech that Norton still can't even detect after the fact.
03-06-2009 04:20 AM
Please send the file to Symantec so they can have a look.
03-06-2009 04:23 AM
Send what file? I cannot find the file -- Norton cannot detect it.
So I guess I should buy some better security programs to detect it, then send the info to Norton? That's idiotic.
03-06-2009 04:45 AM
Tsujigiri00 wrote:
I know I have a keylogger because my World of Warcraft account had been hacked via it.
Send what file? I cannot find the file
hmm !? ;)
show us a Hijackthis Log or so.
You can also try manually Settings on Intelligent Firewall -> extented Control , than NIS find a legal or illegal Key Logging Program
03-06-2009 05:10 AM
03-06-2009 05:48 AM
I know it's a keylogger because: I logged into WoW 3hrs ago and my password no longer worked, I changed the password out of game and logged in to see my characters had been pillaged, then I got kicked off b/c the hacker was logging in with my new password.
This = definitive proof of a keylogger.
But Norton cannot detect the keylogger so I still haven't been able to remove it from my computer.
So I guess the only solution now is to purchase a different security system and don't trust Norton?
03-06-2009 05:57 AM
03-06-2009 09:37 AM - edited 03-06-2009 09:38 AM
Tsujigiri00 wrote:I know it's a keylogger because: I logged into WoW 3hrs ago and my password no longer worked, I changed the password out of game and logged in to see my characters had been pillaged, then I got kicked off b/c the hacker was logging in with my new password.
This = definitive proof of a keylogger.
...
Actually, no, this is not definitive proof of keylogger.
Passwords can be hacked. I don't know how secure their site it, but it does happen.
If you do have a keylogger on your machine, it has probably taken a lot more than one password to one site. What else have you checked?
Also, vendors can have database errors on their servers. If a particular user's files get corrupted, everything can change: password and game status. I know this for a personal fact because I just had something like that happen to one of my utility accounts. It took me four weeks to get customer service to believe I knew what I was talking about and refer me to their webmaster. Once we actually talked, he checked things out and found out I was right. Took four or five days to fix because they had to rebuild my data file.
03-06-2009 11:33 AM
Do a full scan with http://www.malwarebytes.org/mbam.php
Clean anything it finds and DO NOT GIVE YOUR PASSWORD TO ANYBODY. Even your parents/friends/girlfriend etc.
You can trust them AS MUCH AS YOU WANT, but who says they wont login on some infected computer?
First thing is to do a full scan with Malwarebytes http://www.malwarebytes.org/mbam.php and with Superantispyware http://www.superantispyware.com/.
Afterwards clean anything you find and post the log from a Hijackthis scan ( http://www.trendsecure.com/portal/en-US/tools/secu
Post any logs that appear when running these scans (Malwarebytes, superantispyware (if any) and Hijackthis). Then we will review them and see if you were infected and if you are clean now.
Regards, Salihb
03-06-2009 01:55 PM
Salihb wrote:Do a full scan with http://www.malwarebytes.org/mbam.php
Clean anything it finds and DO NOT GIVE YOUR PASSWORD TO ANYBODY. Even your parents/friends/girlfriend etc.
You can trust them AS MUCH AS YOU WANT, but who says they wont login on some infected computer?
First thing is to do a full scan with Malwarebytes http://www.malwarebytes.org/mbam.php and with Superantispyware http://www.superantispyware.com/.
Afterwards clean anything you find and post the log from a Hijackthis scan ( http://www.trendsecure.com/portal/en-US/tools/secu
rity_tools/hijackthis ).
Post any logs that appear when running these scans (Malwarebytes, superantispyware (if any) and Hijackthis). Then we will review them and see if you were infected and if you are clean now.
Regards, Salihb
Thank you very much for the advice. I'm currently doing full scans with both programs and will post results.
I've also run Spybot, AVG, and CCCleaner. Nothing serious was detected, however the two latter did find the following, something I didn't recognize:
C:\Users\Adam\AppData\Roaming\Mozilla\Firefox\Pro
There were about 10 of these:
C:\Users\Adam\AppData\Local\Microsoft\Windows\Exp
I wasn't particularly concerned with those though since I only use Firefox (modded with NoScript ofc) and never touch IE.
