AAPL stock: $427.00 ( -4.77 ) *Cached every 60 seconds. For live updating, Click Here |
| Tips and Deals ---- 'Friendly' Political Ranting |
| I actually had a Mac infected with a Trojan yesterday! Really! Posted by: Paul F.
Date: March 29, 2012 01:18PM
|

| Re: I actually had a Mac infected with a Trojan yesterday! Really! Posted by: cbelt3
Date: March 29, 2012 01:22PM
|
| Re: I actually had a Mac infected with a Trojan yesterday! Really! Posted by: samintx
Date: March 29, 2012 01:24PM
|
| Re: I actually had a Mac infected with a Trojan yesterday! Really! Posted by: billb
Date: March 29, 2012 01:33PM
|
| Re: I actually had a Mac infected with a Trojan yesterday! Really! Posted by: LaserKun
Date: March 29, 2012 01:40PM
|
| Re: I actually had a Mac infected with a Trojan yesterday! Really! Posted by: Paul F.
Date: March 29, 2012 01:43PM
|

| Re: I actually had a Mac infected with a Trojan yesterday! Really! Posted by: lost in space
Date: March 29, 2012 01:44PM
|
| Re: I actually had a Mac infected with a Trojan yesterday! Really! Posted by: N-OS X-tasy!
Date: March 29, 2012 01:57PM
|
| Re: I actually had a Mac infected with a Trojan yesterday! Really! Posted by: decay
Date: March 29, 2012 02:10PM
|

| Re: I actually had a Mac infected with a Trojan yesterday! Really! Posted by: mattkime
Date: March 29, 2012 02:13PM
|
| Re: I actually had a Mac infected with a Trojan yesterday! Really! Posted by: haikuman
Date: March 29, 2012 02:24PM
|

| Re: I actually had a Mac infected with a Trojan yesterday! Really! Posted by: GGD
Date: March 29, 2012 02:35PM
|
Quote
F-Secure's analysis offers a detailed method for detecting and ultimately removing the malware from your system, though you can easily detect the malware in its known variants by running the following three commands sequentially in the OS X Terminal utility (found in the /Applications/Utilities/ folder):
defaults read ~/.MacOSX/environment DYLD_INSERT_LIBRARIES
defaults read /Applications/Safari.app/Contents/Info DYLD_INSERT_LIBRARIES
defaults read /Applications/Firefox.app/Contents/Info DYLD_INSERT_LIBRARIES
If your system is not infected then the output of these commands will state in part that the domain/default pair "does not exist"; however, if it is infected then Terminal will output a path that points to the malware, and you can follow the instructions provided in F-Secure's analysis to remove the malware from your system.
| Re: I actually had a Mac infected with a Trojan yesterday! Really! Posted by: michaelb
Date: March 29, 2012 03:12PM
|
Quote
decay
There is no request for a password, and the user does not need to be an administrator for this malware to install.
| Re: I actually had a Mac infected with a Trojan yesterday! Really! Posted by: TheCaber
Date: March 29, 2012 05:34PM
|
| Re: I actually had a Mac infected with a Trojan yesterday! Really! Posted by: TheCaber
Date: March 29, 2012 05:44PM
|
% defaults read ~/.MacOSX/environment DYLD_INSERT_LIBRARIES 2012-03-29 19:25:01.919 defaults[55530:903] The domain/default pair of (/Users/daasawyer/.MacOSX/environment, DYLD_INSERT_LIBRARIES) does not exist % defaults read /Applications/Safari.app/Contents/Info DYLD_INSERT_LIBRARIES 2012-03-29 19:25:14.615 defaults[55531:903] The domain/default pair of (/Applications/Safari.app/Contents/Info, DYLD_INSERT_LIBRARIES) does not exist % defaults read /Applications/Firefox.app/Contents/Info DYLD_INSERT_LIBRARIES 2012-03-29 19:25:24.839 defaults[55532:903] The domain/default pair of (/Applications/Firefox.app/Contents/Info, DYLD_INSERT_LIBRARIES) does not exist %and I conclude that I don't suffer that particular form of malware (yet).
| Re: I actually had a Mac infected with a Trojan yesterday! Really! Posted by: Black
Date: March 29, 2012 06:14PM
|
Quote
TheCaber
For example, I started Applications->Utilities->Terminal.app and 'copy-and-paste'd each of the command lines in GGD's quote. Here's what it looked like, and the results returned:% defaults read ~/.MacOSX/environment DYLD_INSERT_LIBRARIES 2012-03-29 19:25:01.919 defaults[55530:903] The domain/default pair of (/Users/daasawyer/.MacOSX/environment, DYLD_INSERT_LIBRARIES) does not exist % defaults read /Applications/Safari.app/Contents/Info DYLD_INSERT_LIBRARIES 2012-03-29 19:25:14.615 defaults[55531:903] The domain/default pair of (/Applications/Safari.app/Contents/Info, DYLD_INSERT_LIBRARIES) does not exist % defaults read /Applications/Firefox.app/Contents/Info DYLD_INSERT_LIBRARIES 2012-03-29 19:25:24.839 defaults[55532:903] The domain/default pair of (/Applications/Firefox.app/Contents/Info, DYLD_INSERT_LIBRARIES) does not exist %and I conclude that I don't suffer that particular form of malware (yet).
This is a bit of nasty social engineering (that tricks you into opening an infected document which uses the Microsoft non-secure execution environment), not a true worm or virus which would not require human intervention to propagate.
| Re: I actually had a Mac infected with a Trojan yesterday! Really! Posted by: Ammo
Date: March 29, 2012 07:40PM
|
| Re: I actually had a Mac infected with a Trojan yesterday! Really! Posted by: decay
Date: March 29, 2012 08:46PM
|


