Getting Rid of a Keylogger


  1. Posts : 381
    Windows 10
       #1

    Getting Rid of a Keylogger


    Whilst roaming about the net, I seem to have picked up a keylogger. I know this because I got an email today with my user name and a valid password for a site I frequent in the subject line. The email is threatening me with embarrassing details being broadcast to everyone in my address book unless I provide a bitcoin, yadda yadda yadda.

    I have seen these phishing emails before, but they have never had my password before, so I know I've been keylogged. My question is, how do I find the logger and how do I get rid of it? I am running Malwarebytes and it didn't find it. I also used SuperAntiSpyware and Windows Defender, but nothing showed up there either. I have changed my passwords using another PC, but I want to clean my machine from this. I'm using 1909, fully updated.

    Anyone have any ideas?
      My Computer


  2. Posts : 920
    Windows 10 Pro
       #2

    Have you considered that the reason the email had your password is because the email account was hacked rather than the information being sent from your PC by a key logger?
    Changing your passwords is a good idea if in any doubt, and doing it from a second PC is good as long as you have never shared files/ drives/ network between the PC's.
    If you are really convinced you have a key logger but anti virus/ anti malware scans reveal nothing (and by all means try several, what one misses another might find) then the best course of action is a clean install, removing all existing partitions in the process and using a Windows setup media created on a known clean machine.
    That is my best thought on the matter, hope it helps.
      My Computer


  3. Posts : 1,345
    Windows 10 Pro 64-bit
       #3

    I've seen what you describe 3 times this past year. Hurry up and save your data.

    Then follow Pejole2165 advice in post #2 "best course of action is a clean install, removing all existing partitions in the process and using a Windows setup media created on a known clean machine."
      My Computer


  4. Posts : 194
    Windows 10
       #4

    Its a scam, they got your password from a site you use which was breached, this happens to many sites. Same thing happened to me, got my password from the Avast forum which was breached a few years ago. If you use the same password for any other sites just change it, otherwise just delete email and do not worry.
      My Computer


  5. Posts : 8,114
    windows 10
       #5

    I get one every week claiming to have activated my web cam and videoed me not having a webcam I know its a con
      My Computer


  6. Posts : 381
    Windows 10
    Thread Starter
       #6

    Oh I definitely know it is a con, but I use this PC for development work and VPN into work. I also do my banking on it...

    I've done full scans on the entire 5 drives I have and found nothing with three different AVs, so I don't think I have a keylogger. Unless it's so sophisticated it doesn't show up. I'm not too worried about the email itself as I haven't done anything embarrassing with my machine and I don't have the webcam that they said they activated. I have deleted both emails.

    I guess I have to assume that my Hotmail account was hacked. I have changed all the passwords that I can, so I guess I might be OK. I am taking my image drive offline for a while though. Better safe than sorry.

    Thanks for all of your help, everyone.
      My Computer


  7. Posts : 1,345
    Windows 10 Pro 64-bit
       #7

    Gurn Blanston said:
    Oh I definitely know it is a con, but I use this PC for development work and VPN into work. I also do my banking on it...

    I've done full scans on the entire 5 drives I have and found nothing with three different AVs, so I don't think I have a keylogger. Unless it's so sophisticated it doesn't show up. I'm not too worried about the email itself as I haven't done anything embarrassing with my machine and I don't have the webcam that they said they activated. I have deleted both emails.

    I guess I have to assume that my Hotmail account was hacked. I have changed all the passwords that I can, so I guess I might be OK. I am taking my image drive offline for a while though. Better safe than sorry.

    Thanks for all of your help, everyone.
    It looks like you are keeping up with what you need to do.
    I've seen 3 incidences over this past year very similar to yours.
    --- One of those users let it go on too long before dealing with: to make a long story short, a clean install was the solution.
    I'm not aware of an AV finding anything relating to what was going on similar to your case.
    --- See if AdwCleaner finds anything. I use Downloads - AdwCleaner - ToolsLib
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 17:22.
Find Us




Windows 10 Forums