Trojan + Keylogger - Norton not detecting

Note: Please do not post Personally Identifiable Information like email address, personal phone number, physical home address, product key etc.

Issue abstract: Norton not detecting trojan & keylogger.

Detailed description: Realised I had spyware in laptop and mobiles. Took one laptop to 3 shops, nothing was found as “macbooks are impossible to crack” so I’m “imagining it”. Reset the OS, still had a problem. Finally took it to the 4th shop where it was indeed found hidden in the BIOS (trojan with keylogger and a MASSIVE file of data ready to be “shipped off” to my hacker).

I’ve since realised it was the internet connection that was the origin of the problem and that’s how all my devices became “infected”. Unfortunately only realised that after connecting my expensive new mobile by ethernet cable, after I had already done the same to my “clean” laptop…

I have Norton antivirus installed in everything. I know it all has spyware, yet Norton has detected freaking zilch, nada, zero. I would have expected something to be flagged. Yet, nothing does. Two macbooks, 4 mobiles, everything up to date and I find myself (yet again) in the position of having to pay a professional to clean my laptops and buy new mobiles as your antivirus does squad.

I can’t believe my neighbour (professional stalker and hacker wannabe) is better than you people and manages to beat a product that probably took millions to make. Hang your heads in shame people! And go and sit in the naughty corner with no freaking internet and no gadgets.

Product & version number: MacBook Air M2

OS details: Tahoe 26.5.1

What is the error message you are seeing? N-O-N-E, zero, zilch, nada and herein lies the problem.

If you have any supporting screenshots, please add them:

1 Like

I have a Windows PC not Mac so my comments may not apply to your situation.

Norton does not have the ability to scan the BIOS as far as I know. It only runs after the BIOS is loaded and scans the file system and network connections for weak passwords and compromised connections.

As for the mobile app it only scans apps both user and system and also network connections.

If the source of your infection is the BIOS that is much more sophisticated malware than most antivirus programs will handle.

1 Like

Thanks for your insight and for taking the time to comment. My issue is how did it get to the BIOS in the first place? I can understand the first time it happened: I got Norton after it was already in the BIOS. The second time though Norton should have protected my laptop. Nothing should have got past it.

When I bought Norton, nowhere did it say “only protects half of your laptop”. If that were the case I’d have bought stamps and paper and I would send letters instead of buying expensive laptops.

I’m using a freaking laptop/mobiles that have been hacked and I blame you “Norton”, for lulling me into a false sense of security.

Also, my spyware creates a file (that’s what was found hiding in the BIOS in the other laptop and named macintosh-sth) and then, given the massive amounts of data used when I’m basically reading the news online, sends it over to the hacker. Isn’t Norton supposed to control what gates open, when and by what apps? Norton, is essentially pointless or am I’m reading this wrong?

1 Like

===================

================================

AI sourced content may make mistakes
Caveat: I’m not macOS

1 Like

AI sourced content may make mistakes
Caveat: I’m not macOS

1 Like

AI sourced content may make mistakes
Caveat: I’m not macOS

1 Like

I started having problems almost two years ago. Then, after forever, realised the neighbour was naming their wifi like mine. Then “they?” (not sure what to look this person(s) so I shall refer to them as the weirdo) used something to disable my wifi on and off. Then noticed other wifis named like mine. Change my wifi’s name, then proper saw a wifi pop up with the same name every single time. Started using ethernet, carried on having problems, changed laptop, changed mobile…. Somewhere along the way noticed “weirdo” fiddling in the main comms cupboard in the hall of the building and then “nice neighbour” said something about me being careful with the internet and “heavily implied” “weirdo” was up to something.

This is a seriously short version of this story, there’s lots more to it. I thought that connecting a “clean laptop” to a “new” mobile and using that as a hotspot plus Norton would have been enough.

With my old mobile the only fine thing was the location turning on and off, and static during phone calls. Got a new phone and that was sorted but then realised that 2nd one had been hacked and finally got a third one (actually paid extra to get Norton on everything). How the heck does a hacker “come in”, drop their “shit.e”, open a door and Norton doesn’t flag it?!

I have nothing noticeable anywhere, in neither the mobiles nor the laptop. It was only when I took to the fourth place that they found the massive trojan with keylogger. I was told only Mossad or the KGB would crack a macbook and “why would they come for me?!”.

Thanks for the help but I would add for others reading this: install your OS from a pendrive or from a clean laptop. Do not connect your laptop to the www. Which was what I did. That doesn’t actually work.

The posts by bjm above bring out lots of good points about your situation.

I understand and am sympathetic to your problems because no one should have to go thru what you are experiencing.

I update my BIOS from time to time thru my manufacturers website. I download and run that file to update the current BIOS to the newer version. The only way I know of to infect the BIOS would be if that program I download has been altered by a hacker.

However I do not think that any of the current products on the market like Bitdefender, Kaspersky, Sophos etc. would be able to detect that malware,

Maybe Norton should take note of your issues and improve their antivirus software.

1 Like

Sorry, it wasn’t actually named macintosh-sth! ahah! Sorry! It was Macintosh hd “something” but I don’t remember what it was called, I never saw it. The computer tech found the file and they only noticed it because it was huge. The name was not noticeable at all, hence the fact others missed it before. Though tbh the others had a look before I reset the OS. When it was found I had already reset it so it shouldn’t have had such a massive file stored and that’s what caught their eye.

1 Like

AI sourced content may make mistakes
Caveat: I’m not macOS

Thank you for understanding! It’s hard to put into words what it feels like to be stalked by a bloody pervert and not be able to do zilch.

You can’t “update” an “infected” BIOS no matter what. That’s what made it so hard to get a grasp on what was going on.

In my case, the tech went in, "deleted” the file and then installed a new OS BUT not connected to the web (that is reeeeally important). You can’t be online.

What I did was reset the disk (but not the trojan” as that was hidden) and then installed a new OS but the infected file remained. So, in reality, I didn’t delete the actual spyware.

Never update or install a new OS connected to the web if you think you’ve got a problem.

1 Like

AI sourced content may make mistakes
Caveat: I’m not macOS

AI sourced content may make mistakes
Caveat: I’m not macOS

AI sourced content may make mistakes
Caveat: I’m not macOS

1 Like

@bjm If you ever want a free holiday in Portugal let me know! We can work something out… A free flat in return for tech advice and making my current set up safer because right now it feels like I keep patching holes while somebody’s outside with a bloody drill having fun.

Free dinner (in a proper restaurant) if you can find the ip where the data’s going to!

1 Like

Sorry guys, I was offline for a bit and didn’t realise that what I’d written wasn’t posted so it wasn’t clear.

To clarify: my wifi was not right and I noticed wifi connections named after mine, so moved to ethernet, then neighbour had to fiddle with the internet cable outside my flat as I stopped using wifi. When I was told that I started using my mobile as a hotspot and stopped using that internet connection. I started using data from my SIM card. The first hack was via a physical device and the second one I forgot to turn off my laptop’s wifi and it connected to the neighbour’s one which he had named after mine obviously.

I will “wipe the data raw” and try to then install a new OS using a pendrive (I had previously downloaded it with a clean laptop). Meanwhile I’ll carry on using an old laptop for important stuff, having fun with this one and hoping my “nice neighbour” will have the guts to do the right thing.

Thank you all for the help, it was much much appreciated!

1 Like

Please keep in mind going forward that Mac isn’t bulletproof as many would like us to believe. Here is some relevant information about patches just this year for your OS version.

SA