Spyware/malware/keylogger? HELP!!!

Hi. I was looking for free dialup servce as a backup. I came across a link in a forum I frequent, and went to the site. Registration was just username and password. I registered, but was suspicious.

So I ran a search and came across complaints that the site (Metconnect.com) was infiltrated by hackers, and they'd installed "urchin.js" trackers. Out of curiosity, I did a find on my computer (my Pismo laptop) and found two instances of this "urchin.js," which apparently comes with Google Analytics? But what was really suspicious was their location: both were found in a folder where I keep copies of credit reports and my financial information, titled "Credit Reports/Money."

I immediately deleted them both, disconnected from the internet and started a spyware/keylogger check that comes with Internet Cleanup/Net Blockade, which I keep running at all times and use the feature which lets me know when anyone tries to connect to my computer (like Little Snitch). I also have my firewall settings turned up to the max/stealth.

However, I am still freaking out and wondering just what information these folks might already have grabbed in those few minutes. The spyware check takes a few hours and isn't close to finished.

Does anyone have any experience with this, and know what I might be up against?

Thanks so much!!

Pismo G4 550; Pismo G3 500; Mac 700; iMac DV500 Graphite; dead iBook SE Graphite, Mac OS X (10.4.11), iPhone 3G; Nano 4G/8GB; Nano 1G/2GB; Shuffle 1G/512MB; Airport Express

Posted on Sep 28, 2009 12:37 PM

Reply
38 replies

Sep 30, 2009 9:06 AM in response to WZZZ

I registered and posted in the "Security" section. Only one person responded to me, and wasn't able to shed much light on the subject. He basically thinks that since all the complaints about that site are a few years old, I probably have nothing to worry about. So I guess all I can really do is hope

Here you can see the nature of the complaints, just FYI:

http://www.freedomlist.com/forum/viewtopic.php?p=169753
http://www.epinions.com/review/cmsw-ISP ... C3AD-prod3
http://www.freedomlist.com/forum/viewtopic.php?p=169421
http://www.freedomlist.com/forum/viewto ... 0&p=173297

thanks everyone for all your help. 🙂

Sep 30, 2009 9:36 AM in response to LaurieNY

Hi,

Did you post in the Support forum? The general seems to be far less populated. If not, I'd re-post and see if you get some more replies, maybe Giorgio.

I only looked at one of those links, but seems to have to do with re-directs from metconnect. You had that file urchin.js download to a very sensitive folder. Any of those links mention that?

Also a general security tip: use these numbers from OpenDNS for your DNS servers in Sys Preferences/ Network. Safer (prevent re-directs) and faster than those from your isp. Highly recommended. Very simple Instructions here:

https://www.opendns.com/start/

Sep 30, 2009 9:49 AM in response to WZZZ

I didn't understand most of the stuff in those links. I just knew it didn't sound good.

I posted in "Security" because it seemed to be the right section for my question ("Talk about internet security, computer security, personal security, your social security number..."). As a forum moderator myself, I've always hated when people deliberately post in the wrong section simply because there's more traffic there. 😉 Especially as my question wasn't about either of the products that the forum is dedicated to!!

I really appreciate all the time and effort you've put into my problem. 🙂

Sep 30, 2009 10:14 AM in response to LaurieNY

Well, I learned something from you. I never saw that security forum before. Never knew it existed. That's why I was suggesting you post over in support. Maybe someone else will chime in over there.

BTW, not to get crazy posting all over, but there's also a Firefox forum--definitely no registration required. Maybe someone over there. I'd just copy your first post from NoScript. Don't be afraid to bump it. It's a very busy forum and your post can get snowed over quite quickly. A lot of PCs there; mention that you're on a Mac in the subject/topic line. There's one guy over there who I know is really into security and Macs. Maybe it was "Robert," with a golfing avatar.
http://forums.mozillazine.org/viewforum.php?f=38

I'd be completely nuts if this had happened to me.

Oct 1, 2009 5:27 AM in response to WZZZ

Hi,
I hope you're still checking in on this thread. I really wanted to get to the bottom of this, and summarized your question in another forum with some very knowledgeable Mac people--I'm certainly not one--which BDAqua introduced me to some time ago. Here is a short excerpt of the reply and a direct link to the thread for the full reply. I think you may find some comfort here.
My guess, if I had to guess, is that she saved a page from Firefox in "Webpage, complete" format at some point from a page that was using Google Analytics, like one of the credit reporting agencies, then later went back and found the urchin.js file which had been saved with the complete web page.
...It's nice that's she's being cautious, but in all likelihood it was just plain old Google Analytics urchin.js file.

http://x704.net/bbs/viewtopic.php?f=17&t=3688&p=43335&#p43335
There are some very helpful people (as there are here) over there. (You would get a nice welcome if you decide to join at any time.)

Oct 1, 2009 6:50 AM in response to WZZZ

Hey W

You're an absolute doll. Thanks for doing that. I read through all that and feel much better. I'm sure I did probably did save a webpage or two in there before I started saving as pdfs instead. I feel much better now. Although I did find a whole folder in Application Support for something called "Esellerate," which apparently appeared the same day, and which I'd never heard of. Yikes. 🙂

But I'm going to give you a "Solved" here anyway, because you went above and beyond and I think your diligence hit upon the probable answer. Thank you!!

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Spyware/malware/keylogger? HELP!!!

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.