shadowmoses said:Wasnt there something simular to this with the release of 10.4, I remember a virus/trojan spreading through a widget??
Yeah, but the proof-of-concept has been around for ages.
I remember seeing a similar trojan back during 10.2
shadowmoses said:Wasnt there something simular to this with the release of 10.4, I remember a virus/trojan spreading through a widget??
yankeefan24 said:The First Mac Virus? (A New OS X Trojan)
3fingersalute said:So if mac's are not immune to viruses anymore, that leaves zero reasons to own a mac.![]()
moki said:Folks... the file "latestpics.tgz" is definitely up to no good, or at least wants to appear that it is up to no good. When unarchived, the file appears to be a JPEG file because someone pasted the image of a JPEG file onto the file.
The file is actually a Unix executable, with routines such as:
_infect:
_infectApps:
_installHooks:
_copySelf:
I have not looked at it in complete detail yet, but it does indeed appear to be opening files, changing file attributes, and potentially doing damage.
DO NOT DOWNLOAD OR RUN THIS FILE
I will be looking into it further; if you are a programmer, attached is the disassembly of the executable (it's just a plain text file) for your reading pleasure.
It XOR's the static string data stored in it, which is why it doesn't appear to have any string constants. It's definitely trying to mask what it is doing. More later.
I will post updates here:
http://www.ambrosiasw.com/forums/index.php?showtopic=102379
tag said:Well I'm using Netscape and didn't recieve a warning, but would you really expect to? It wasn't a direct download to an application, it was an app that was compressed (tar), so your browser wouldn't know an app is inside, for all a browser knows a picture was inside.
Mr. Mister said:Seeing as it requires user authentication, it's just as much of a virus as somebody formatting their own damned hard drive.
generik said:I think you noobs should just display file extensions in finder.
Been there done that on Windows, pfft, old trick.
Well, that's no good then.WildCowboy said:It doesn't require any sort of authentication if the user has admin privileges...it just goes.
Patch what?easy4lif said:i have to agree with this. th last thing apple needs right now is for all this wild fire about viruses coming out during the intel transition. Tomorrow Steve jobs is going to yell at a lot of engineers to get this fixed fast cause thier jobs depend on. I see mac patch in 5 days
and check Prefs > Accounts > Start up items for "hidden" start up apps when you trash apps. iTunes uses a similar one to sit in background watching out for a connected iPod.WildCowboy said:iChat Agent is the app that stays running when iChat is closed to monitor things like incoming chat requests, etc. You should be able to open Activity Monitor, find iChat Agent, and quit the process. You should then be able to get rid of the files.
I don't think there's any evidence for this. It seems to copy (something) into whatever apps it can find. The iChat Agent is not a creation of the trojan, just a hidden support app that wasn't deleted as part of trashing the main iChat app.MrMacMan said:P.S:
GITANAJAVA -- Check your active processes and kill any process that has iChat in it. Clearly the program installs it own stripped down version of iChat to try to propagate itself to others.
GITANAJAVA said:I've read most of the posts here today and yesterday (and at Macnn.com) and I still need an FYI, if anyone's available.
I'd already deleted the iChat app 2 weeks ago when doing an archive and install and general cleanup; I've never used it and don't expect to. After the "latestpics"/Trojan news, I decided to make sure I'd trashed all the iChat files. Found these (see attachment) and when I attempted to empty the trash I received a message saying "iChat Agent is in use" and cannot be trashed.
I'm Panther, BTW, not Tiger: why can't I empty trash of the remaining iChat files? Should I be concerned? And no, I only read the "latestpics" posts, haven't dl'd anything in 4-5 days that wasn't from Apple. Thanks NE1 for feedback ;-)
GITANAJAVA said:Huh?
Hey, Frankb, I'm blonde, remember?
GITANAJAVA said:Huh?
Hey, Frankb, I'm blonde, remember?