View Single Post
Old 29-08-2006, 21:40   #1
Tezcatlipoca
Inactive
 
Tezcatlipoca's Avatar
 
Join Date: Jun 2003
Location: Cambridge
Posts: 16,760
Tezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny stars
Tezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny stars
Unhappy tspy - Trojan keylogger

I like to think (...or used to like to think) that my XP SP2 PC was pretty well protected from all the nasties out there.


It sits behind a Netgear ADSL wireless router gateway, connected via wireless G using WPA & MAC filtering, with NAT & SPI.

It has Kaspersky AntiVirus, with all the different "Protections" running, including the "Proactive Defense".

It has Spywareblaster.

It has Spybot S&D.

It has Adaware.

It has MS Windows Defender.

Though for a software firewall it currently only has the XP SP2 firewall. I used to use Zone Alarm, but had problems with it conflicting with Kaspersky, so ditched ZA a couple of months ago.

I use Firefox rather than IE (unless IE is needed, e.g. for Windows Updates).


Everything is updated regularly.


I scan with Spybot & Adaware & Windows Defender every day.

I scan with Kaspersky's "Critical Areas" & "Startup Objects" scans every day.

I scan with Kaspersky's full "My Computer" scan every few days.



and yet.....

It seems to have picked something up yesterday.

Some variant of the "tspy" trojan keylogger, according to Trend Micro's online "HouseCall" antivirus scan.

Housecall removed said infection, & in a fit of paranoia I've since changed my passwords (& also inadvertently locked myself out of my online banking due to entering the wrong password when going back into it later on).


What really worries me, as well as the whole obvious risk of having an apparent keylogger, is exactly when the hell did this infection occur & how?

Maybe it was very recent, & would have been picked up by something else if I hadn't happened to have thought to do a "HouseCall" scan when I did.

But maybe it was there for longer, & *only* Housecall is capable of detecting it?!

In which case...

Is that possible or likely?



I've tried to find info on exactly what Spybot, Adaware, & Kaspersky can actually detect, but not had much luck.


I've since bought CounterSpy, another anti-spy/ad/malware etc. prog, plus I'm thinking of going back to using something other than the SP2 firewall.
Tezcatlipoca is offline   Reply With Quote