Transcriptionist Getting a Lot of Firewall Messages about a Keylogger

Discussion in 'Malware Help (A Specialist Will Reply)' started by AngelsWilliam, Sep 8, 2009.

  1. AngelsWilliam

    AngelsWilliam Private First Class

    Hi, there. Ever since I installed (and uninstalled after it didn't do jack for me) iTunes Agent on my desktop computer, I have been getting a lot of firewall messages asking permission for this mysterious "M" to perform various things on my computer. I obviously can't find anything on it in Google because--well, you can't look up the letter M and get any meaningful results.

    At the same time, I started getting warnings from my firewall about a keylogger. I got this warning also whenever I ran iTunes Agent and it went to open iTunes. At the time, I figured, "Oh, it's just one of those false positive thingies," and clicked "allow" without clicking "remember my decision" or "trust this program." You know, playing it as safe as I could. When I uninstalled iTunes Agent, my computer went nuts with all kinds of alarms and warnings about malware. I didn't write them down (dammit) because the only thing on my mind was getting that software off my computer. But, now, I've got this keylogger on my computer and this mysterious "M" that gives me the willies.

    The keylogger is obviously my greatest concern as a transcriptionist. That is not a cool thing when one is working with people's private medical records. That M thing could very well be nothing, but I figure now that I'm getting this keylogger warning more and more that it's about time to turn in logs. Hope they can tell you something!
     

    Attached Files:

  2. AngelsWilliam

    AngelsWilliam Private First Class

    Here's my MGTools log. I'm sorry I didn't say thank you in my last post. It used to say that in my signature!

    Thanks for any and all help, folks. :grouphug
     

    Attached Files:

  3. AngelsWilliam

    AngelsWilliam Private First Class

    Not trying to bump my thread, but there have been new developments that I think are extremely relevant and are why I now only check for replies from my laptop:

    1. After I posted my logs for my desktop to your forum, I went to your list of firewalls and downloaded the one labeled "pick" (i.e., PC Tools Plus). I then downloaded it and uninstalled Online Armor. When I went to install PC Tools, it said I had another firewall, AVG Firewall, running on my computer. Thing is, I uninstalled AVG Pro back in May when my license expired. But, I opened RegSeeker and searched the registry for occurrences of AVG Firewall. It found 3, so I deleted them. Then, I ran CCleaner and its registry cleaner and tried to install PC Tools again. It said the same thing. I decided, chuck it, I was going to install it anyway because it had said at the beginning of the installation that it would shut down all other firewalls on my system when I installed it.

    2. Yesterday (Wednesday), I booted my computer up because I knew there had been a major Microsoft security update and I thought it couldn't hurt to put that on after everything that happened. As per usual (something I forgot to mention in my original post), the automatic update shield didn't come up with a notice that there were updates available. (It used to only come up to say updates were ready to install after I'd gone to the update site and gone through the on-site update process and begun to install the high-priority updates.) So, as usual, I went to the start menu and clicked on Microsoft Update. One small difference: I got taken to the "Welcome to Microsoft Update! Click here to start using Microsoft Update" page. I remember this happening to me once before, but I know it's not supposed to because I had been using automatic updates and Windows Genuine Advantage all along.

    3. I tried to access the web to check for a response from my team leader to my e-mail regarding my computer situation. I got nothing but a blank white page when I opened Firefox.

    4. I decided, just for kicks, to take a gander at my Combofix log, worried that I'd get told again I was being obnoxious sending in clean logs. I saw that it had 3 AVG components on it, even though I had uninstalled AVG back in May.

    Folks, something is definitely wrong. I am NOT imagining this. Please...help me.

    And, I should also mention, as long as I am without these computers, I am out of work and my company is VERY unhappy with me...and they already were.

    Thanks muchly!:wave
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The effect is still the same.

    If this current thread is for your Desktop PC then please only talk about your Desktop PC in this thread to avoid confusion. And only talk about your laptop in your other thread.

    You did not have Online Armor installed so I'm not sure what you are talking about.

    Please post questions about software problems in the Software Forum. Or post them on the website for the software you are having problems with. We don't have time for non-malware issues in this forum.

    Also possibly a topic for the Software Forum if you still have any update issues.

    Your logs are basically clean, so you may not be having malware problems. Try Internet Explorer and see what happens. I do have some minor things for you to do I will post at the end of this message. However MGtools did not run properly. The logs appear to indicate you may be having Error Message Type 1 mentioned in the Using MGtools link so perhaps you should run the suggested fix right now so that what we do down below will possibly work properly.

    ComboFix has some bugs and often complains about things that are not installed or that used to be installed and are not cleaned up properly. No software uninstall 100% completely. They all have very poor uninstall processes.

    But they may not all be malware based on your logs. We will fix what I see and then see what happens.

    Sorry but all threads get treated the same. Everyone thinks their problems are more important. ;)


    If you are going to keep WinPatrol installed I strongly suggest that you uninstall Windows Defender.


    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    R3 - URLSearchHook: (no name) - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - (no file)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)


    Also if the below is not valid or something you recognize then fix it too.
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = ichart.com


    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. AngelsWilliam

    AngelsWilliam Private First Class

    Done!


    The company techs are going to kill me because they have to reinsert the voice servers, etc. back into my host file again....
    :duck

    It's legit. It's part of the Dictaphone/Word Client/EXText Client software I use for my job. Not sure why that part's called iChart, but it is. That software has so many different names for it it's pathetic. (Oh, and...I didn't just say that because I'm not supposed to say anything to do with anything about anything within the company. But, you know, they are only responsible for problems with their own software. If we have problems with our "equipment," we have to get it fixed somewhere else. But, nobody can know anything about anything to do with anything about the company unless he or she is an employee. Uh-huh.)
    rolleyes

    Success!

    Well, I was able to do all this, update Firefox, and update NoScript. I wasn't able to do MS update before we did this, but let me try it now. That Worm thingie we removed with HJT kinda makes me wonder if that was what was preventing me from getting the updates. If so, I just wasted MS support's time.... (I just sent them a diagnostic and support request via their web site because of my inability to get updates either way.)

    I'm sorry I can't seem to tell the difference between software and malware problems. Maybe someone can explain the difference to me privately so I cause you all less irritation in the future? I'm not stupid; I just have an innate aptitude in some things and a need for repeated hands-on experience in others.

    Thanks,
     

    Attached Files:

    Last edited: Sep 15, 2009
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you implying the below were valid?
    O1 - Hosts: 204.61.236.164 ahdcttxt01 ahdcttxt01.ah.org
    O1 - Hosts: 204.61.236.165 ahdctvoc01 ahdctvoc01.ah.org

    Then it was probably from emptying the hosts file since nothing else we did would affect this.

    That was just left over junk from Symantec which did not completely uninstall itself.

    Sometimes it is not so easy for people other than us to distinguish between the two. Clearly anything related to general questions about any software that has nothing to do with protection will belong in the Software Forum. When it is a program used for protection, it gets a little harder. Any specialty tool problems like ComboFix, Avenger, RootRepeal, and MGtools always belong in the malware forum. For other tools like antivirus, SUPERAntiSpyware, Malwarebytes, and similar the questions belong in the malware forum if it is a direct question about malware removal. If it is a question like, how do I get AVG to uninstall, or how do I diable AVG linkscanner, or how do stop SUPERAntiSpyware from loading at startup..... you know general questions anyone can answer. Then post in the Software Forum. You will probably get an answer much sooner since we are so busy removing malware.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  7. AngelsWilliam

    AngelsWilliam Private First Class

    They're in my laptop's host file, too, so I'm guessing you're correct. I don't know much about what goes in the host files. All I know is these are the EXText servers settings:

    General Tab
    Server Connection Settings:
    Server name = xxx.xxx.xxx.xxx
    Protocol = ncacn_ip_tcp

    Voice Server Settings Tab
    Use local settings is selected:
    Protocol = ncacn_ip_tcp
    Address = xxx.xxx.xxx.xxx

    Does that help? It's all Greek to me! :confused

    I just realized: I/We have a piece of software called "Host Selector" that changes the host settings for each client in Word Client as needed if we switch from our primary to our secondary accounts depending on workload. So, the above servers probably aren't always the same. I don't know. Again, it's all Greek to me. You probably know how these things work better than I. There's a guy at your site who told me he works in hospitals...can't think of his name...OH! BJGarrick! He probably knows how this kind of setup works if you don't. I hope that didn't sound insulting. It's not meant to be.

    Thanks still more,
     
    Last edited by a moderator: Sep 21, 2009
  8. AngelsWilliam

    AngelsWilliam Private First Class

    Oh, and tried Java update, it didn't work, so clicked on link to see "possible solutions." The recommended deleting entire Java folder in programs folder and then restarting my computer and downloading the new version of Java afresh.

    We-he-helll...

    My little Windows Update shield came right up as soon as my wireless connection did! And, once that was done, I tried downloading the new version of Java and running it and...you'll never guess!

    IT INSTALLED SUCCESSFULLY!!!

    So, I think we're good to go, here. Let me know what you think after you read my last reply. I gotta go nightie-night.
    :wave
    Thank you SOOOOO MUCH!

    Oh, and let me know when it's safe to run the registry part of CCleaner, now that I've uninstalled and installed some programs. :)
     
    Last edited: Sep 15, 2009
  9. AngelsWilliam

    AngelsWilliam Private First Class

    Okay, about the hosts thing, yeah. everything works except logging into Word Client. Host selector works, VPN works, but Word Client tells me EXT Server's not available. So, is fixing the host file something I have to go to them for, I take it? You can't tell me how to put those 2 entries back in there?

    Thanks,
     
  10. AngelsWilliam

    AngelsWilliam Private First Class

    URGENT! NEED TO DELETE (INFO IN) 1 OF MY REPLIES Re: Transcriptionist Getting....

    Also, I need to delete at least one of my posts (the one with the server addresses), so the info isn't visible to others' eyes. I didn't think of that when I posted that reply. Baaad, bad idea. The forum was letting me edit my posts, but all of the sudden I couldn't edit my most recent 2.
    :confused
    I haven't gotten anymore replies from you, and I've really got to deal with this. Did I offend you in some way? I didn't mean to. I'm sorry if I did.
    :-o
    Thanks,
    C
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are just talking about the below lines, just edit your hosts file with notepad and add them back in.
    204.61.236.164 ahdcttxt01 ahdcttxt01.ah.org
    204.61.236.165 ahdctvoc01 ahdctvoc01.ah.org

    I delete the IP addresses you previously post for your server.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: URGENT! NEED TO DELETE (INFO IN) 1 OF MY REPLIES Re: Transcriptionist Getting....

    Everytime you make additional posts, you are bumping yourself to the bottom of the work queue. If you kept posting, you would never get an answer. Didn't you read the sticky threads???? Like: Don't Bump! It Only Hurts You!!!
     
  13. AngelsWilliam

    AngelsWilliam Private First Class

    This computer has died Re: Transcriptionist Getting...

    I believe it was some variation of vundo, since the following symptoms occurred in rapid succession immediately after reconnecting the Internet after closing Avast!antivirus when I walked in and saw that it had come up with "0 infected files" other than those it couldn't scan because they were locked or whatever other reasons it gave:

    1. The Internet connection showed as "Very Good," when it always comes up as "Excellent," so I moved the antenna around, whereupon it went down to "Good," so I decided to attempt to repair it because that had been helping a lot on my laptop lately. When I did it on this computer, it took it down to "Low."

    2. Thinking the problem might be an aging wireless card, I restarted the computer to see whether or not that would make a difference, figuring if it didn't it was indeed the wireless card. Well...when I restarted it, I didn't get ANYthing. Nothing onscreen at ALL. Not even the pre-Windows info. I tried once more, hoping I could go into Safe Mode, but it didn't even give me the opportunity to do that. Worse yet, the orange light indicating hard drive activity stopped soon after I gave up tapping the F8 button.

    I'm thinking EEK.

    I've called my local guy. I'm hoping if we use my Windows disk, we can keep it alive long enough to recover my data. Otherwise, we'll have to go back to all that I had back when I had an 80GB drive. I have some stuff on DVD, but not the major stuff. *sigh*
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: This computer has died Re: Transcriptionist Getting...

    Not according to the logs you attached in this thread which were all clean.

    Good luck.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds