|
|
| Welcome to the Mac Forums forums. Please read the FAQ if you have questions. Register to participate. |
|
|||||||
| TouchArcade.com - iPhone Game Reviews and News |
![]() |
|
|
Thread Tools | Search this Thread | Display Modes |
|
|
#1 |
|
macrumors 65816
Join Date: Dec 2005
Location: NYC
|
A Mac trojan??? the image by lasthope?!?!?
This thread and the events are summarized here: The First Mac Virus? (A New OS X Trojan)
If anyone remembers last night, when lasthope spread that picture that opened in terminal. I just turned on my other computer and it said it had an incoming file, from my computer, which was the latest pics file. Any help. I have already secure deleted it off of my harddrive, but how do i know that it will not come back. Any help is appreciated. link to lasthopes thread: http://forums.macrumors.com/showthre...=1#post2142507
__________________
MacBook "Black Edition" 23" ACD Disclaimer: Never take facts I state in a post as totally 100% correct unless otherwise stated. Last edited by arn : Feb 16, 2006 at 02:42 AM. |
|
|
|
| yankeefan24 |
| View Public Profile |
| Find More Posts by yankeefan24 |
|
|
#2 |
|
macrumors 68030
Join Date: Mar 2005
Location: A religiously oppressed state
|
Same thing happened over here (as you see from my post in the other thread) and everything seems to be fine but we have no way of telling because [rant] APPLE DOESN'T INCLUDE ****ING VIRUS PROTECTION IN THE .MAC ANY MORE!!!!!!!!! [/rant]
Last edited by Rower_CPU : Feb 15, 2006 at 11:22 AM. Reason: don't circumvent the profanity filter |
|
|
|
|
|
#3 | |
|
macrumors 601
Join Date: Mar 2004
|
Sounds like a trojan, not a virus.
Quote:
__________________
Nintendo Players - the Ultimate Nintendo Resource MacBook CD/2GHz/2GB/160GB/SD Hackintosh Core 2 Quad/2.4 GHz/4GB/660GB/8800GT 16 GB iPhone Last edited by Rower_CPU : Feb 15, 2006 at 11:22 AM. |
|
|
|
|
|
|
#4 |
|
macrumors 6502a
Join Date: Jan 2004
Location: Maryland
|
I ran it, opened terminal and then closed it. Dont know about sending messages to other computers though because i have the only mac in my house.
__________________
iBook G4 14" 1.42ghz, 1.5gb RAM, 100gb 7200rpm Travelstar, 4G iPod 40gb
|
|
|
|
|
|
#5 | |
|
Banned
Join Date: Jan 2005
|
Quote:
No it can find new ones. Normally covered on a bloodhound like feature (basicly it looks for virus like chars and quantitines the file) now it will not be able to remove the virus and cure it. But it will prevent access to it and protect the rest of the system from it. |
|
|
|
|
|
|
#6 | |
|
macrumors regular
Join Date: Oct 2004
|
Quote:
http://www.clamxav.com/ Last edited by Rower_CPU : Feb 15, 2006 at 11:22 AM. |
|
|
|
|
|
|
#7 |
|
Banned
Join Date: Feb 2006
|
Mac OS X is very specific about making installing viruses a thing that the user has a very large part in. Don't impulsively type your system password when a dialogue box pops up and you should be fine.
|
|
|
|
| Mr. Mister |
| View Public Profile |
| Find More Posts by Mr. Mister |
|
|
#8 | |
|
Thread Starter
macrumors 65816
Join Date: Dec 2005
Location: NYC
|
Quote:
__________________
MacBook "Black Edition" 23" ACD Disclaimer: Never take facts I state in a post as totally 100% correct unless otherwise stated. |
|
|
|
|
| yankeefan24 |
| View Public Profile |
| Find More Posts by yankeefan24 |
|
|
#9 | |
|
macrumors 68030
Join Date: Mar 2005
Location: A religiously oppressed state
|
Quote:
|
|
|
|
|
|
|
#10 | |
|
Thread Starter
macrumors 65816
Join Date: Dec 2005
Location: NYC
|
Quote:
__________________
MacBook "Black Edition" 23" ACD Disclaimer: Never take facts I state in a post as totally 100% correct unless otherwise stated. |
|
|
|
|
| yankeefan24 |
| View Public Profile |
| Find More Posts by yankeefan24 |
|
|
#11 | |
|
macrumors 68040
|
Quote:
__________________
Alumium MacBook 2.0Ghz C2D | 2GB RAM | 320GB HD | Snow Leopard |
|
|
|
|
|
|
#12 | |
|
macrumors 68030
Join Date: Mar 2005
Location: A religiously oppressed state
|
Quote:
|
|
|
|
|
|
|
#13 |
|
Thread Starter
macrumors 65816
Join Date: Dec 2005
Location: NYC
|
The trojan still exists on this computer. Does anyone know where the file would be located on my HDD.
Unlike benjamin, mine somehow got permission to do whatever it had to do. I have the file mirrored (i think thats the right term) on a seperate site, so if anyone wants to reverse engineer it, you can do that. just remember that you are downloading a known trojan (because the downloader knows that it is trojan (you can't get past that on the site), i think i am allowed to give it out, just PM me so i am sure). The virus is still alive on my computer despite secure deleting the script (it tried to get itself to my sisters computer), so any help is appreciated, and i hope this isn't worse than it seems. But it didn't require a password so i believe that it can't do anything very bad, but why would someone make a trojan just to spread it, so he can say he made the first mac virus (i know its not a virus, but that might be what the guy was aiming for). All help is appreciated. I did scan my home library folder with the above linked app. BTW, i think that lasthope should be banned, and tell exactly what it does.
__________________
MacBook "Black Edition" 23" ACD Disclaimer: Never take facts I state in a post as totally 100% correct unless otherwise stated. |
|
|
|
| yankeefan24 |
| View Public Profile |
| Find More Posts by yankeefan24 |
|
|
#14 |
|
macrumors 65816
|
I really hope this guy gets what he deserved. I also hope that this doesn't get worse as we find out more about it. It already has the ability to spread to every mac on the network. Good thing I downloaded the file and then just decided to delete it. What if I opened it at school?? Every Mac in the school would have this "thing" on it!
__________________
[double-click to type your signature] |
|
|
|
|
|
#15 | |
|
Thread Starter
macrumors 65816
Join Date: Dec 2005
Location: NYC
|
Quote:
Again, if anyone thinks that they can isolate it and reverse engineer it or anything like that i will be happy to give you the mirrored link (im not posting it here because i am not sure what the rules are).
__________________
MacBook "Black Edition" 23" ACD Disclaimer: Never take facts I state in a post as totally 100% correct unless otherwise stated. |
|
|
|
|
| yankeefan24 |
| View Public Profile |
| Find More Posts by yankeefan24 |
|
|
#16 | |
|
macrumors 68030
Join Date: Mar 2005
Location: A religiously oppressed state
|
Quote:
|
|
|
|
|
|
|
#17 | |
|
Thread Starter
macrumors 65816
Join Date: Dec 2005
Location: NYC
|
Quote:
__________________
MacBook "Black Edition" 23" ACD Disclaimer: Never take facts I state in a post as totally 100% correct unless otherwise stated. |
|
|
|
|
| yankeefan24 |
| View Public Profile |
| Find More Posts by yankeefan24 |
|
|
#18 | |
|
macrumors 65816
|
Quote:
__________________
[double-click to type your signature] |
|
|
|
|
|
|
#19 |
|
macrumors 68000
|
Even though macs are techincally virus free and all that, you should still be very cautious on what you click and what you do with your computer. I'm not insulting anyone that clicked the link, god knows I've messed up windows boxes, but still - be cautious all the same
.
|
|
|
|
| calebjohnston |
| View Public Profile |
| Find More Posts by calebjohnston |
|
|
#20 | |
|
macrumors 68030
Join Date: Mar 2005
Location: A religiously oppressed state
|
Quote:
|
|
|
|
|
|
|
#21 | |
|
Thread Starter
macrumors 65816
Join Date: Dec 2005
Location: NYC
|
if i try to recreate this on a seperate account on my computer, do you think if would affect other accounts? I want to take a good look at the script and see what apps it is affecting (i quit terminal before i could see anything and would like to see.)
Quote:
EDIT: I have a BAD feeling that this is only going to get worse. I just have to recommend everyone who downloaded this file and uncompressed it to BACKUP RIGHT NOW! if this is going to spread like it seems to be doing (bonjour and aim) i think this is a delayed reaction type thing. I'll get back to you after i reverse engineer it. (im going to create a new account and then download it off of my mirror and then see what apps its affecting. if its something minor i will uninstall and reinstall, but if its an apple app (such as finder or ichat) we might all have a problem.
__________________
MacBook "Black Edition" 23" ACD Disclaimer: Never take facts I state in a post as totally 100% correct unless otherwise stated. Last edited by yankeefan24 : Feb 15, 2006 at 08:04 PM. |
|
|
|
|
| yankeefan24 |
| View Public Profile |
| Find More Posts by yankeefan24 |
|
|
#22 | |
|
macrumors 65816
|
Quote:
__________________
[double-click to type your signature] |
|
|
|
|
|
|
#23 | |
|
Thread Starter
macrumors 65816
Join Date: Dec 2005
Location: NYC
|
Quote:
/Users/virustest/Desktop/latestpics\ 2; exit usage: cp [-R [-H | -L | -P]] [-f | -i | -n] [-pv] src target cp [-R [-H | -L | -P]] [-f | -i | -n] [-pv] src1 ... srcN directory cp: /tmp/latestpics/..namedfork/rsrc: No such file or directory /usr/bin/tar: latestpics: Cannot stat: No such file or directory /usr/bin/tar: Error exit delayed from previous errors cp: /Applications/RealPlayer.app/Contents/MacOS/RealPlayer: Permission denied cp: /Applications/Firefox.app/Contents/MacOS/Firefox: Permission denied cp: /Applications/Rise of Nations Gold/Game/Rise of Nations Gold.app/Contents/MacOS/Rise of Nations Gold: Permission denied cp: /Applications/Skype.app/Contents/MacOS/Skype: Permission denied cp: /Applications/Google Earth.app/Contents/MacOS/Google Earth: Permission denied logout [Process completed] I'll try this on my other account and post what it gives me if different. On my main account, it doesn't seem to be completed but this is it: my user name/Desktop/latestpics; exit override rw-r--r-- virustes/wheel for latestpics.tgz? (y/n [n])
__________________
MacBook "Black Edition" 23" ACD Disclaimer: Never take facts I state in a post as totally 100% correct unless otherwise stated. |
|
|
|
|
| yankeefan24 |
| View Public Profile |
| Find More Posts by yankeefan24 |
|
|
#24 |
|
macrumors 68030
Join Date: Mar 2005
Location: A religiously oppressed state
|
I Think Ive Removed It
I THINK I've removed it off my laptop, it embeds it's self in the UNIX file system of random apps. To find what apps its in download the file again (should be in your history) and it will ask if you want to overwrite (choose no) and it will tell you all the apps its in. When you try to run most of the apps that are effected they wont run. Just trash the apps that it's embedded in. This seems to have worked and my laptop seems fast again. In a few days we will see if it's still around when it tries (or doesn't) to send to other people again.
EDIT: yankeefan24 has already posted what will come up when you run it. You must run it in new account to find out what apps its in. |
|
|
|
|
|
#25 | ||
|
Thread Starter
macrumors 65816
Join Date: Dec 2005
Location: NYC
|
Quote:
/Desktop/latestpics; exit override rw-r--r-- virustes/wheel for latestpics.tgz? (y/n [n]) n not overwritten logout [Process completed] this is from my main account, my post above's first part was from a sub account. Quote:
__________________
MacBook "Black Edition" 23" ACD Disclaimer: Never take facts I state in a post as totally 100% correct unless otherwise stated. |
||
|
|
|
| yankeefan24 |
| View Public Profile |
| Find More Posts by yankeefan24 |
![]() |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|