Why I'll be sticking with Kaspersky as my Virus checker

znaps

Senior member
Jan 15, 2004
414
0
0
So I get a call from BofA today telling me about some possible fraudulent activity in my account online. Sure enough, some asshole has transferred $10,000 out of my account over the weekend. I had an issue with Paypal last week also, so it was pretty clear to me that someone had gotten my account info somehow for both sites.

Anyway, BofA and Paypal have things under control and I've changed all my passwords etc, so I started to check my machine for Trojans. I've always had Norton Antivirus installed (came free with my Thinkpad) and it never reported anything, so I tried Trend Micro's online scanner, and it reported nothing either. Just in case, I tried Kaspersky because I've always liked it, and lo and behold it found a Trojan which was probably the culprit.


Summary:

Kaspersky > (Norton | Trend Micro)
 

znaps

Senior member
Jan 15, 2004
414
0
0
Some trojan keylogger/backdoor program. Thanks for the first non-idiot response.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
If you have a router that allows it, you may want to set up rules that arbitrarily block TCP and UDP traffic on ranges of ports that you don't have a specific reason to have open. example using cheap good Netgear RP614 showing how I can cherry-pick the ports I have an actual use for, and block the rest. This would thwart some types of backdoor proggies from getting out.
 

Raincity

Diamond Member
Feb 17, 2000
4,477
12
81
I would nuke everything and start over again. Follow Mech's advice on running a limited user account. Mech's advice on buttoning down the RP614 sounds good also. I use a PIX 501 for my firewall. You cant be too safe these days.
 

znaps

Senior member
Jan 15, 2004
414
0
0
Thanks for the suggestions - I'll definitely lock down as many ports as I can. What I really want to do is find the IP address of the person who was collecting the info. I'd love to meet him face to face.
 

Raincity

Diamond Member
Feb 17, 2000
4,477
12
81
Originally posted by: znaps
Thanks for the suggestions - I'll definitely lock down as many ports as I can. What I really want to do is find the IP address of the person who was collecting the info. I'd love to meet him face to face.

Knowing the IP wont do you any good. These folks will use somebodys server that been exploited to collect the keylogger packets. Start over, tighten up security and live and learn.