How can i check that?

Wannsong

Regular Member
Joined
Jun 11, 2017
Messages
276
Reaction score
124
Hello guys! Today i woke up and i found out that 2 payments have been made with my paypal account, now before few minutes i saw that someone is trying to change my password in one site. I am starting to think that i might have downloaded a keylogger or something.. Any idea how can i check, if i did so? Also will appreciate any tips on how to save my accounts!

Thanks in advance!
 
Enable two step verification on your paypal account. In addition to that, if you want to be 100% sure that you don't have a keylogger on your PC, make a format and clean installation of your windows (if desktop)
 
Scan your Computer with https://www.malwarebytes.com/

check what is running in task manager, maybe you'll find some weird program running etc...

Thanks downloading it now!
Enable two step verification on your paypal account. In addition to that, if you want to be 100% sure that you don't have a keylogger on your PC, format it.

I don't know why i thought that i have it, may be because i created new account lately, i did so immediately after i saw payments. Thanks!
 
As above, scan your computer with antivirus program, enable MFA on your account to keep it safe, change your password to something really secure - don't use a dictionary word and don't use any password you have used previously.

If you have any type of remote access on your computer - Teamviewer for example - make sure its locked down and that you also have MFA on it as well.

Lastly, something you can also do if you are paranoid - on command prompt, run this command -

netstat -no

Then copy all of the remote IP addresses, remove local addresses and duplicates and then check that list on an IP service such as maxmind.

If you do that a few times throughout the day you will know if anyone has a persistent connection to your computer - its normally easy to spot suspicious connections that you are not expecting.
 
As above, scan your computer with antivirus program, enable MFA on your account to keep it safe, change your password to something really secure - don't use a dictionary word and don't use any password you have used previously.

If you have any type of remote access on your computer - Teamviewer for example - make sure its locked down and that you also have MFA on it as well.

Lastly, something you can also do if you are paranoid - on command prompt, run this command -

netstat -no

Then copy all of the remote IP addresses, remove local addresses and duplicates and then check that list on an IP service such as maxmind.

If you do that a few times throughout the day you will know if anyone has a persistent connection to your computer - its normally easy to spot suspicious connections that you are not expecting.

Thank you very much i have both Teamviewer and Anydesk without any MFA on them, working on this now!
I am not that paranoid, wouldn't like to use any valuable accounts that's the only thing, but i'll try that as i didn't know it! :D

Thank you a lot for your detailed answer!
 
Thank you very much i have both Teamviewer and Anydesk without any MFA on them, working on this now!
I am not that paranoid, wouldn't like to use any valuable accounts that's the only thing, but i'll try that as i didn't know it! :D

Thank you a lot for your detailed answer!

I have heard in the past there are some vulnerabilities with Teamviewer in particular. So what I would do is set up MFA on the teamviewer account itself and then also, go into teamviewer settings on the computer, and restrict access only to your account - that way nobody can log in to your PC via teamviewer, unless they are also logged in to your teamviewer account (Which will have MFA on it).

You can do the same for anydesk as well. It also has a whitelist feature and I assume it has MFA as well.
 
Is it needed guys to do clean install of my windows or I can clear everything with Malwarebytes?
 
Back
Top