Spyware/malware/keylogger? HELP!!!

Hi. I was looking for free dialup servce as a backup. I came across a link in a forum I frequent, and went to the site. Registration was just username and password. I registered, but was suspicious.

So I ran a search and came across complaints that the site (Metconnect.com) was infiltrated by hackers, and they'd installed "urchin.js" trackers. Out of curiosity, I did a find on my computer (my Pismo laptop) and found two instances of this "urchin.js," which apparently comes with Google Analytics? But what was really suspicious was their location: both were found in a folder where I keep copies of credit reports and my financial information, titled "Credit Reports/Money."

I immediately deleted them both, disconnected from the internet and started a spyware/keylogger check that comes with Internet Cleanup/Net Blockade, which I keep running at all times and use the feature which lets me know when anyone tries to connect to my computer (like Little Snitch). I also have my firewall settings turned up to the max/stealth.

However, I am still freaking out and wondering just what information these folks might already have grabbed in those few minutes. The spyware check takes a few hours and isn't close to finished.

Does anyone have any experience with this, and know what I might be up against?

Thanks so much!!

Pismo G4 550; Pismo G3 500; Mac 700; iMac DV500 Graphite; dead iBook SE Graphite, Mac OS X (10.4.11), iPhone 3G; Nano 4G/8GB; Nano 1G/2GB; Shuffle 1G/512MB; Airport Express

Posted on Sep 28, 2009 12:37 PM

Reply
38 replies

Sep 28, 2009 7:38 PM in response to BDAqua

Still following this. Yeah, I thought if they were still in the trash, could do a "get info," or open it, and maybe learn a little more.

BD's the best, but really, bring this up on the NoScript forum. You can be a "guest;" I don't think you need to register Maybe Giorgio has heard something about it, or can figure out how this might have happened. He deals with this evil stuff all the time. He's like a kind of exorcist. NoScript is all about Javascript exorcism. But wait 'till the AM; he's in Italy and probably sleeping now. He, or someone else on the forum, might try replicating it to figure it out. I'd be freaked out too, but a lot of this stuff is aimed at Windows, and might, if it's a genuine exploit, be completely harmless on a Mac.

Sep 28, 2009 9:08 PM in response to WZZZ

BD's the best...


Granted, but what else has BD ever done for us?

PS. Not really, thousands here better than I, I;m just prolifific, but Niel, the #1 i the world has been clicking off a good 100 points a day since I mentioned months ago that my goal was to catch him... now he's going to lap me! (121,125 points!!!)

Sep 29, 2009 6:36 AM in response to WZZZ

Hey W

I tried to register over there a couple of hours ago, still waiting for activation email, even had it re-sent. Yes I checked spam.

Anyway, I was looking at malware info there and it said malware "Will Search “Documents and Settings” for SSNs, credit cards, and saved IE passwords"

Yeah. Which is probably why those files ended up in my financial folder. I've put fraud alerts on my credit reports, but who knows where else this may lead and when. These types don't always use your information right away.

Sep 29, 2009 9:39 AM in response to LaurieNY

I know when someone out there is trying to connect to me, but not when anything leaves my computer when it shouldn't be.

I run istat menu with the network traffic indicator going. Not the same as Little Snitch but if I were to see a lot of constant outgoing network activity when all I was doing was typing a letter it would probably indicate something was going on when it shouldn't.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Spyware/malware/keylogger? HELP!!!

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.