ITunes trojan horse small.bog

Today I finally decided to update to iTunes 8.2.1 after I found out Palm had fixed the syncing for the Palm Pre. After downloading iTunes 8.2.1 I got a iTunes trojan horse small.bog message on my AVG. I thought it was a virus at first, but after doing some searching I found out it was a false alert. If you see this message, just ignore it. There is no virus or torjan in iTunes.
Post relates to: Palm IIIc

I agree with you 'C_Sannell'. I've just spent the last three hours trying to unistall the latest version of iTunes and go back to a previous version but because the 8.2.1.6 vesion of iTunes created a later library my iTunes now doesn't work at all. I say it doesn't work at all because there is no way I'm going to use the iTunes 8.2.1.6 until the trojans are removed. My AVG anti virus system has identified 99 infections just in the setup file alone. These were identified as "Trojan horse Small.BOG"
I couldn't belive that Apple (iTunes) would allow this to be included in the downloaded software, and immediately assumed the fault was with the source that I had downloaded the software from (PC Mag or the like) so I went direct to the Apple Mac site to download the iTunes and there was the same problem.
Fortunately for me I can keep my iPod charged without connecting to iTunes but if the trogan's are in this software then Apple need to lookinto why this has been alowed to happen to their customers.
HELP please !! we need a newer version without the trogans.

Similar Messages

  • Trojan horse small.BOG

    My AVG antivirus scan found a number of iTunes files that supposedly found the trojan horse small.BOG (whatever the heck that is) infection. Based on the postings, lots of people have found it. Can anyone tell me their thoughts?

    Hey guys someone did this, good luck, I'll try.
    Here's how I did it (Microsoft Vista OS and AVG Free)---------
    1. Open AVG Free
    2.Click "Tools" at the top, scroll down to "Advanced Settings"
    3. Under the "Resident Shield" directory, (expand it if not already), click "Exceptions".
    4. When the menu pops up, click "Add Path" at the upper right.
    5. When the window pops up, click these folders in this order-
    COMPUTER>HARD DRIVE or C folder>PROGRAM FILES(x86)>ITUNES
    When you click on the iTunes folder, make sure you don't click the arrow, but click on the folder itself.
    6. Hit okay and save your settings, click apply and exit AVG. When you look at the exceptions on AVG, the itunes directory should look like this C:\Program Files\iTunes\
    7. Restart your computer.
    8. When you turn it back on, open iTunes, it should go through a little setup process, then iTunes should work.
    -------------------IF ITUNES STILL DOESN'T WORK, TRY MAKING ANOTHER DIRECTORY UNDER PROGRAM FILES(NOT X86). KEEP THE OLD (X86) EXCEPTION.---------------------------
    This worked for me, good luck.
    Source(s):
    personal experience

  • Trojan Horse small.bog itune

    Can someone help me. I'm very confussed. Yesterday my itunes were working just fine and today I'm getting this trojan message from AVG and it will not allow me to open I itunes. I'm wondering if I should just uninstall itunes for a while. I have never dealt with this before.

    It appears AVG has updated their definitions to prevent the itunes and ipod files from being tagged as trojans.
    I had put mine in exceptions earlier. But just received my second AVG update of the day. I took the itunes/ipod exceptions out of Resident shield and rescanned the program files and voila - no trojans in the the itunes folder now. (Even though I had it earlier and never cleaned it up).
    So If you did not uninstall itunes already, just updated your AVG again and you should be ok.

  • Possible Solution to Itunes Trojan Horse issue

    I simply updated my AVG and Itunes opened with no problems. Good Luck!

    just update AVG, there was a programming or communication problem between the two, AVG was just detecting iTunes as a virus, it has been fixed, just download the update from AVG and rerun it. I happened to have uninstalled iTunes too but I don't think it is necessary. You can if you want. There was no virus in iTunes, I have friends who have another antivirus program and they had no problems. I would still keep AVG if you have it, it is a good program, just a glitch.

  • Hey, im experiencing problems with itunes. i downloaded the recent itunes update yesterday and today i plugged my iphone in and my computer said there was a trojan horse and now itunes wont open. Help please??

    Hey guys, Im expierencing problems with itunes after the latest update yesterday(1/22) and the problem im having is when i plugged my iphone into my PC today a virus detection came up and said a trojan horse was present. I also cant open itunes at all. Im confused and dont know what to do. thanks in advance

    Place the device in DFU mode (google it) and restore.

  • SPY script/ Trojan Horse active on my MAC BOOK PRO

    Hello, Since two days I have noticed a small pop up every other minute when I am connected to the internet (which I do wireless) in the left top corner. It is a small window that pops and disappears very fast, impossible to read what it says. Does anyone can help me with this? How do I find out what it is and even more important how can I delete/ remove it

    Just in case we actually are confronted by a Trojan, read this:
    From MacWorld, January 10, 2008:
    SecureMac has introduced a free Trojan Detection Tool for Mac OS X. It's available here:
    http://www.securemac.com/
    The DNSChanger Removal Tool detects and removes spyware targeting Mac OS X. Called DNSChanger Trojan and also known as OSX.RSPlug.A Trojan Horse the software attacks users attempting to play a fake video file.
    Upon attempting to play the video, the victim receives the following message:
    “Quicktime Player is unable to play movie file.
Please click here to download new version of codec.”
    Upon running the installer, the user's DNS records are modified, redirecting incoming internet traffic through the attacker's servers, where it can be hijacked and injected with malicious websites and pornographic advertisements. The trojan also installs a watchdog process that ensures the victim's DNS records stay modified on a minute-by-minute basis.
    SecureMac's DNSChanger Removal Tool allows users to check to see if the trojan has been installed on their computer; if it has, the software helps to identify and remove the offending file. After a system reboot, the users' DNS records will be repaired.

  • Trojan Horse pakes?

    I have some sort of Trojan horse on my iMAC (running Mavericks 10.9.5). When I check the console, there are 1000s of processes going on per second and they repetitively say:
    "10/13/14 7:51:53.579 AM proxyhost[22202]: 67.198.140.250:2122 - - [13/Oct/2014:07:51:53 -0700] "GET http://us-u.openx.net/w/1.0/sd?id=537073142&val=RUIDdzr1pcqq7bm659gajgpbbd5mgaxr 8t4yzbrfwht3uyidafrw9hqy==== HTTP/1.1" 302 401 895"
    10/13/14 7:51:53.505 AM proxyhost[22200]: Made direct (non-proxy) connection to syndication.exoclick.com:80
    10/13/14 7:51:53.000 AM kernel[0]: proc: table is full
    for example. The websites keep changing.
    I've scanned for malware with ClamXV and MacScan and found nothing. I have been blocked from my network. They said I have a trojan horse "pakes".
    Here is the etrecheck report (I'm no longer connected to the ethernet so the processes have stopped. I'm not sure if this matters for what people want to see):
    EtreCheck version: 1.9.15 (52)
    Report generated October 13, 2014 at 7:52:18 AM PDT
    Hardware Information: ?
      iMac (27-inch, Mid 2011) (Verified)
      iMac - model: iMac12,2
      1 3.4 GHz Intel Core i7 CPU: 4 cores
      8 GB RAM
    Video Information: ?
      AMD Radeon HD 6970M - VRAM: 1024 MB
      iMac 2560 x 1440
    System Software: ?
      OS X 10.9.5 (13F34) - Uptime: 2 days 19:28:14
    Disk Information: ?
      Hitachi HDS722020ALA330 disk0 : (2 TB)
      S.M.A.R.T. Status: Verified
      EFI (disk0s1) <not mounted>: 209.7 MB
      Macintosh HD (disk0s2) / [Startup]: 2 TB (1.19 TB free)
      Recovery HD (disk0s3) <not mounted>: 650 MB
      OPTIARC DVD RW AD-5680H
    USB Information: ?
      Apple Computer, Inc. IR Receiver
      Apple Internal Memory Card Reader
      Apple Inc. BRCM2046 Hub
      Apple Inc. Bluetooth USB Host Controller
      Apple Inc. FaceTime HD Camera (Built-in)
    Thunderbolt Information: ?
      Apple Inc. thunderbolt_bus
    Gatekeeper: ?
      Anywhere
    Problem System Launch Daemons: ?
      [failed] com.apple.security.syspolicy.plist
    Launch Daemons: ?
      [loaded] com.adobe.fpsaud.plist Support
      [loaded] com.adobe.SwitchBoard.plist Support
      [loaded] com.barebones.authd.plist Support
      [loaded] com.bombich.ccc.plist Support
      [running] com.bombich.ccc.scheduledtask.4CD02F29-DEED-4CEF-AB0E-270D9AAA53AB.plist Support
      [invalid] com.landesk.broker.plist
      [invalid] com.landesk.cba8.plist
      [invalid] com.landesk.ldwatch.plist
      [invalid] com.landesk.msgsys.plist
      [invalid] com.landesk.pds.plist
      [invalid] com.landesk.pds1.plist
      [loaded] com.landesk.pds2.plist Support
      [invalid] com.landesk.remote.plist
      [loaded] com.microsoft.office.licensing.helper.plist Support
      [loaded] com.oracle.java.JavaUpdateHelper.plist Support
    Launch Agents: ?
      [not loaded] com.adobe.AAM.Updater-1.0.plist Support
    User Launch Agents: ?
      [loaded] com.adobe.AAM.Updater-1.0.plist Support
      [loaded] com.adobe.ARM.[...].plist Support
      [loaded] com.adobe.ARM.[...].plist Support
      [running] com.bombich.ccc-user-agent.plist Support
      [loaded] com.google.keystone.agent.plist Support
      [not loaded] com.spotify.webhelper.plist Support
    User Login Items: ?
      Dropbox
    Internet Plug-ins: ?
      FlashPlayer-10.6: Version: 15.0.0.152 - SDK 10.6 Support
      Default Browser: Version: 537 - SDK 10.9
      AdobePDFViewerNPAPI: Version: 10.1.3 Support
      CouponPrinter-FireFox_v2: Version: Version 1.1.6 Support
      AdobePDFViewer: Version: 9.5.5 Support
      Flash Player: Version: 15.0.0.152 - SDK 10.6 Support
      QuickTime Plugin: Version: 7.7.3
      SharePointBrowserPlugin: Version: 14.1.4 - SDK 10.6 Support
      JavaAppletPlugin: Version: Java 7 Update 55 Check version
    Audio Plug-ins: ?
      BluetoothAudioPlugIn: Version: 1.0 - SDK 10.9
      AirPlay: Version: 2.0 - SDK 10.9
      AppleAVBAudio: Version: 203.2 - SDK 10.9
      iSightAudio: Version: 7.7.3 - SDK 10.9
    iTunes Plug-ins: ?
      Quartz Composer Visualizer: Version: 1.4 - SDK 10.9
    User Internet Plug-ins ?
      WebEx64: Version: 1.0 - SDK 10.6 Support
      Aspera Web 3.3.3.81344: Version: (null) - SDK 10.6 Support
      npBcsMcTcIO: Version: (null) Support
      Picasa: Version: 1.0 - SDK 10.6 Support
    3rd Party Preference Panes: ?
      Flash Player  Support
      Growl  Support
      LANDesk Agent  Support
      TeXDistPrefPane  Support
    Time Machine: ?
      Time Machine not configured!
    Top Processes by CPU: ?
          4% WindowServer
          1% hidd
          1% Console
          1% notifyd
          0% Microsoft Word
    Top Processes by Memory: ?
      311 MB com.apple.IconServicesAgent
      205 MB mds_stores
      180 MB Finder
      172 MB Microsoft Word
      156 MB softwareupdated
    Virtual Memory Information: ?
      1.49 GB Free RAM
      3.57 GB Active RAM
      1.67 GB Inactive RAM
      1.25 GB Wired RAM
      2.74 GB Page-ins
      400 KB Page-outs
    Message was edited by: biomed2014

    1. This procedure is a diagnostic test. It changes nothing, for better or worse, and therefore will not, in itself, solve the problem. But with the aid of the test results, the solution may take a few minutes, instead of hours or days.
    Don't be put off by the complexity of these instructions. The process is much less complicated than the description. You do harder tasks with the computer all the time.
    2. If you don't already have a current backup, back up all data before doing anything else. The backup is necessary on general principle, not because of anything in the test procedure. Backup is always a must, and when you're having any kind of trouble with the computer, you may be at higher than usual risk of losing data, whether you follow these instructions or not.
    There are ways to back up a computer that isn't fully functional. Ask if you need guidance.
    3. Below are instructions to run a UNIX shell script, a type of program. As I wrote above, it changes nothing. It doesn't send or receive any data on the network. All it does is to generate a human-readable report on the state of the computer. That report goes nowhere unless you choose to share it. If you prefer, you can act on it yourself without disclosing the contents to me or anyone else.
    You should be wondering whether you can believe me, and whether it's safe to run a program at the behest of a stranger. In general, no, it's not safe and I don't encourage it.
    In this case, however, there are a couple of ways for you to decide whether the program is safe without having to trust me. First, you can read it. Unlike an application that you download and click to run, it's transparent, so anyone with the necessary skill can verify what it does.
    You may not be able to understand the script yourself. But variations of the script have been posted on this website thousands of times over a period of years. The site is hosted by Apple, which does not allow it to be used to distribute harmful software. Any one of the millions of registered users could have read the script and raised the alarm if it was harmful. Then I would not be here now and you would not be reading this message.
    Nevertheless, if you can't satisfy yourself that these instructions are safe, don't follow them. Ask for other options.
    4. Here's a summary of what you need to do, if you choose to proceed:
    ☞ Copy a line of text in this window to the Clipboard.
    ☞ Paste into the window of another application.
    ☞ Wait for the test to run. It usually takes a few minutes.
    ☞ Paste the results, which will have been copied automatically, back into a reply on this page.
    The sequence is: copy, paste, wait, paste again. You don't need to copy a second time. Details follow.
    5. You may have started the computer in "safe" mode. Preferably, these steps should be taken in “normal” mode, under the conditions in which the problem is reproduced. If the system is now in safe mode and works well enough in normal mode to run the test, restart as usual. If you can only test in safe mode, do that.
    6. If you have more than one user, and the one affected by the problem is not an administrator, then please run the test twice: once while logged in as the affected user, and once as an administrator. The results may be different. The user that is created automatically on a new computer when you start it for the first time is an administrator. If you can't log in as an administrator, test as the affected user. Most personal Macs have only one user, and in that case this section doesn’t apply. Don't log in as root.
    7. The script is a single long line, all of which must be selected. You can accomplish this easily by triple-clicking anywhere in the line. The whole line will highlight, though you may not see all of it in the browser window, and you can then copy it. If you try to select the line by dragging across the part you can see, you won't get all of it.
    Triple-click anywhere in the line of text below on this page to select it:
    PATH=/usr/bin:/bin:/usr/sbin:/sbin:/usr/libexec;clear;cd;p=(Software Hardware Memory Diagnostics Power FireWire Thunderbolt USB Fonts SerialATA 4 1000 25 5120 KiB/s 1024 85 \\b%% 20480 1 MB/s 25000 ports ' com.clark.\* \*dropbox \*genieo\* \*GoogleDr\* \*k.AutoCAD\* \*k.Maya\* vidinst\* ' DYLD_INSERT_LIBRARIES\ DYLD_LIBRARY_PATH -86 "` route -n get default|awk '/e:/{print $2}' `" 25 N\\/A down up 102400 25600 recvfrom sendto CFBundleIdentifier 25 25 25 1000 MB com.apple.AirPortBaseStationAgent 464843899 51 5120 files );N5=${#p[@]};p[N5]=` networksetup -listnetworkserviceorder|awk ' NR>1 { sub(/^\([0-9]+\) /,"");n=$0;getline;} $NF=="'${p[26]}')" { sub(/.$/,"",$NF);print n;exit;} ' `;f=('\n%s: %s\n' '\n%s\n\n%s\n' '\nRAM details\n%s\n' %s\ %s '%s\n-\t%s\n' );S0() { echo ' { q=$NF+0;$NF="";u=$(NF-1);$(NF-1)="";gsub(/^ +| +$/,"");if(q>='${p[$1]}') printf("%s (UID %s) is using %s '${p[$2]}'",$0,u,q);} ';};s=(' s/[0-9A-Za-z._]+@[0-9A-Za-z.]+\.[0-9A-Za-z]{2,4}/EMAIL/g;/\/Shared/!s/(\/Users\/)[^ /]+/\1USER/g;s/[-0-9A-Fa-f]{22,}/UUID/g;' ' s/^ +//;/de: S|[nst]:/p;' ' {sub(/^ +/,"")};/er:/;/y:/&&$2<'${p[10]} ' 1s/://;3,6d;/[my].+:/d;s/^ {4}//;H;${ g;s/\n$//;/s: [^EO]|x([^08]|02[^F]|8[^0])/p;} ' ' 5h;6{ H;g;/P/!p;} ' ' ($1~/^Cy/&&$3>'${p[11]}')||($1~/^Cond/&&$2!~/^N/) ' ' /:$/{ N;/:.+:/d;s/ *://;b0'$'\n'' };/^ *(V.+ [0N]|Man).+ /{ s/ 0x.... //;s/[()]//g;s/(.+: )(.+)/ (\2)/;H;};$b0'$'\n'' d;:0'$'\n'' x;s/\n\n//;/Apple[ ,]|Genesy|Intel|SMSC/d;s/\n.*//;/\)$/p;' ' s/^.*C/C/;H;${ g;/No th|pms/!p;} ' '/= [^GO]/p' '{$1=""};1' ' /Of/!{ s/^.+is |\.//g;p;} ' ' $0&&!/ / { n++;print;} END { if(n<200) print "com.apple.";} ' ' $3~/[0-9]:[0-9]{2}$/ { gsub(/:[0-9:a-f]{14}/,"");} { print|"tail -n'${p[12]}'";} ' ' NR==2&&$4<='${p[13]}' { print $4;} ' ' END { $2/=256;if($2>='${p[15]}') print int($2) } ' ' NR!=13{next};{sub(/[+-]$/,"",$NF)};'"`S0 21 22`" 'NR!=2{next}'"`S0 37 17`" ' NR!=5||$8!~/[RW]/{next};{ $(NF-1)=$1;$NF=int($NF/10000000);for(i=1;i<=3;i++){$i="";$(NF-1-i)="";};};'"`S0 19 20`" 's:^:/:p' '/\.kext\/(Contents\/)?Info\.plist$/p' 's/^.{52}(.+) <.+/\1/p' ' /Launch[AD].+\.plist$/ { n++;print;} END { print "'${p[41]}'";if(n<200) print "/System/";} ' '/\.xpc\/(Contents\/)?Info\.plist$/p' ' NR>1&&!/0x|\.[0-9]+$|com\.apple\.launchctl\.(Aqua|Background|System)$|'${p[41]}'/ { print $3;} ' ' /\.(framew|lproj)|\):/d;/plist:|:.+(Mach|scrip)/s/:[^:]+//p ' '/^root$/p' ' !/\/Contents\/.+\/Contents|Applic|Autom|Frameworks/&&/Lib.+\/Info.plist$/ { n++;print;} END { if(n<1100) print "/System/";} ' '/^\/usr\/lib\/.+dylib$/p' ' /Temp|emac/{next};/(etc|Preferences|Launch[AD].+)\// { sub(".(/private)?","");n++;print;} END { print "'${p[41]}'.plist\t'${p[42]}'";if(n<500) print "Launch";} ' ' /\/(Contents\/.+\/Contents|Frameworks)\/|\.wdgt\/.+\.([bw]|plu)/d;p;' 's/\/(Contents\/)?Info.plist$//;p' ' { gsub("^| |\n","\\|\\|kMDItem'${p[35]}'=");sub("^...."," ") };1 ' p '{print $3"\t"$1}' 's/\'$'\t''.+//p' 's/1/On/p' '/Prox.+: [^0]/p' '$2>'${p[43]}'{$2=$2-1;print}' ' BEGIN { i="'${p[26]}'";M1='${p[16]}';M2='${p[18]}';M3='${p[31]}';M4='${p[32]}';} !/^A/{next};/%/ { getline;if($5<M1) a="user "$2"%, system "$4"%";} /disk0/&&$4>M2 { b=$3" ops/s, "$4" blocks/s";} $2==i { if(c) { d=$3+$4+$5+$6;next;};if($4>M3||$6>M4) c=int($4/1024)" in, "int($6/1024)" out";} END { if(a) print "CPU: "a;if(b) print "I/O: "b;if(c) print "Net: "c" (KiB/s)";if(d) print "Net errors: "d" packets/s";} ' ' /r\[0\] /&&$NF!~/^1(0|72\.(1[6-9]|2[0-9]|3[0-1])|92\.168)\./ { print $NF;exit;} ' ' !/^T/ { printf "(static)";exit;} ' '/apsd|BKAg|OpenD/!s/:.+//p' ' (/k:/&&$3!~/(255\.){3}0/ )||(/v6:/&&$2!~/A/ ) ' ' $1~"lR"&&$2<='${p[25]}';$1~"li"&&$3!~"wpa2";' ' BEGIN { FS=":";p="uniq -c|sed -E '"'s/ +\\([0-9]+\\)\\(.+\\)/\\\2 x\\\1/;s/x1$//'"'";} { n=split($3,a,".");sub(/_2[01].+/,"",$3);print $2" "$3" "a[n]$1|p;b=b$1;} END { close(p);if(b) print("\n\t* Code injection");} ' ' NR!=4{next} {$NF/=10240} '"`S0 27 14`" ' END { if($3~/[0-9]/)print$3;} ' ' BEGIN { L='${p[36]}';} !/^[[:space:]]*(#.*)?$/ { l++;if(l<=L) f=f"\n   "$0;} END { F=FILENAME;if(!F) exit;if(!f) f="\n   [N/A]";"file -b "F|getline T;if(T!~/^(AS.+ (En.+ )?text$|(Bo|PO).+ sh.+ text ex)/) F=F" ("T")";printf("\nContents of %s\n%s\n",F,f);if(l>L) printf("\n   ...and %s more line(s)\n",l-L);} ' ' s/^ ?n...://p;s/^ ?p...:/-'$'\t''/p;' 's/0/Off/p' ' END{print NR} ' ' /id: N|te: Y/{i++} END{print i} ' ' / / { print "'"${p[28]}"'";exit;};1;' '/ en/!s/\.//p' ' NR!=13{next};{sub(/[+-M]$/,"",$NF)};'"`S0 39 40`" ' $10~/\(L/&&$9!~"localhost" { sub(/.+:/,"",$9);print $1": "$9;} ' '/^ +r/s/.+"(.+)".+/\1/p' 's/(.+\.wdgt)\/(Contents\/)?Info\.plist$/\1/p' 's/^.+\/(.+)\.wdgt$/\1/p' ' /l: /{ /DVD/d;s/.+: //;b0'$'\n'' };/s: /{ /V/d;s/^ */- /;H;};$b0'$'\n'' d;:0'$'\n'' x;/APPLE [^:]+$/d;p;' ' /^find: /d;p;' "`S0 44 45`" ' BEGIN{FS="= "} /Path/{print $2} ' ' /^ *$/d;s/^ */   /;' );c1=(system_profiler pmset\ -g nvram fdesetup find syslog df vm_stat sar ps sudo\ crontab sudo\ iotop top pkgutil 'PlistBuddy 2>&1 -c "Print' whoami cksum kextstat launchctl sudo\ launchctl crontab 'sudo defaults read' stat lsbom mdfind ' for i in ${p[24]};do ${c1[18]} ${c2[27]} $i;done;' defaults\ read scutil sudo\ dtrace sudo\ profiles sed\ -En awk /S*/*/P*/*/*/C*/*/airport networksetup mdutil sudo\ lsof test osascript\ -e );c2=(com.apple.loginwindow\ LoginHook '" /L*/P*/loginw*' "'tell app \"System Events\" to get properties of login items'|tr , \\\n" 'L*/Ca*/com.ap*.Saf*/E*/* -d 1 -name In*t -exec '"${c1[14]}"' :CFBundleDisplayName" {} \;|sort|uniq' '~ $TMPDIR.. \( -flags +sappnd,schg,uappnd,uchg -o ! -user $UID -o ! -perm -600 \)' '.??* -path .Trash -prune -o -type d -name *.app -print -prune' :${p[35]}\" :Label\" '{/,}L*/{Con,Pref}* -type f ! -size 0 -name *.plist -exec plutil -s {} \;' "-f'%N: %l' Desktop L*/Keyc*" therm sysload boot-args status " -F '\$Time \$Message' -k Sender kernel -k Message Req 'bad |Beac|caug|corru|dead[^bl]|FAIL|fail|GPU |hfs: Ru|inval|jnl:|last value [1-9]|n Cause: -|NVDA\(|pagin|proc: t|Roamed|rror|ssert|Thrott|tim(ed? ?|ing )o|WARN' -k Message Rne 'Goog|ksadm|SMC:| VALI|xpma' -o -k Sender fseventsd -k Message Req 'SL' " '-du -n DEV -n EDEV 1 10' 'acrx -o comm,ruid,%cpu' '-t1 10 1' '-f -pfc /var/db/r*/com.apple.*.{BS,Bas,Es,J,OSXU,Rem,up}*.bom' '{/,}L*/Lo*/Diag* -type f -regex .\*[cgh] ! -name *ag \( -exec grep -lq "^Thread c" {} \; -exec printf \* \; -o -true \) -execdir stat -f:%Sc:%N -t%F {} \;|sort -t: -k2 |tail -n'${p[38]} '/S*/*/Ca*/*xpc* >&- ||echo No' '-L /{S*/,}L*/StartupItems -type f -exec file {} +' '-L /S*/L*/{C*/Sec*A,E}* {/,}L*/{A*d,Ca*/*/Ex,Co{mpon,reM},Ex,In{p,ter},iTu*/*P,Keyb,Mail/B,Pr*P,Qu*T,Scripti,Sec,Servi,Spo,Widg}* -path \\*s/Resources -prune -o -type f -name Info.plist' '/usr/lib -type f -name *.dylib' `awk "${s[31]}"<<<${p[23]}` "/e*/{auto,{cron,fs}tab,hosts,{[lp],sy}*.conf,pam.d/*,ssh{,d}_config,*.local} {,/usr/local}/etc/periodic/*/* /L*/P*{,/*}/com.a*.{Bo,sec*.ap}*t {/S*/,/,}L*/Lau*/*t .launchd.conf" list getenv /Library/Preferences/com.apple.alf\ globalstate --proxy '-n get default' -I --dns -getdnsservers\ "${p[N5]}" -getinfo\ "${p[N5]}" -P -m\ / '' -n1 '-R -l1 -n1 -o prt -stats command,uid,prt' '--regexp --only-files --files com.apple.pkg.*|sort|uniq' -kl -l -s\ / '-R -l1 -n1 -o mem -stats command,uid,mem' '+c0 -i4TCP:0-1023' com.apple.dashboard\ layer-gadgets '-d /L*/Mana*/$USER&&echo On' '-app Safari WebKitDNSPrefetchingEnabled' "+c0 -l|awk '{print(\$1,\$3)}'|sort|uniq -c|sort -n|tail -1|awk '{print(\$2,\$3,\$1)}'" );N1=${#c2[@]};for j in {0..9};do c2[N1+j]=SP${p[j]}DataType;done;N2=${#c2[@]};for j in 0 1;do c2[N2+j]="-n ' syscall::'${p[33+j]}':return { @out[execname,uid]=sum(arg0) } tick-10sec { trunc(@out,1);exit(0);} '";done;l=(Restricted\ files Hidden\ apps 'Elapsed time (s)' POST Battery Safari\ extensions Bad\ plists 'High file counts' User Heat System\ load boot\ args FileVault Diagnostic\ reports Log 'Free space (MiB)' 'Swap (MiB)' Activity 'CPU per process' Login\ hook 'I/O per process' Mach\ ports kexts Daemons Agents XPC\ cache Startup\ items Admin\ access Root\ access Bundles dylibs Apps Font\ issues Inserted\ dylibs Firewall Proxies DNS TCP/IP Wi-Fi Profiles Root\ crontab User\ crontab 'Global login items' 'User login items' Spotlight Memory Listeners Widgets Parental\ Controls Prefetching SATA Descriptors );N3=${#l[@]};for i in 0 1 2;do l[N3+i]=${p[5+i]};done;N4=${#l[@]};for j in 0 1;do l[N4+j]="Current ${p[29+j]}stream data";done;A0() { id -G|grep -qw 80;v[1]=$?;((v[1]==0))&&sudo true;v[2]=$?;v[3]=`date +%s`;clear >&-;date '+Start time: %T %D%n';};for i in 0 1;do eval ' A'$((1+i))'() { v=` eval "${c1[$1]} ${c2[$2]}"|'${c1[30+i]}' "${s[$3]}" `;[[ "$v" ]];};A'$((3+i))'() { v=` while read i;do [[ "$i" ]]&&eval "${c1[$1]} ${c2[$2]}" \"$i\"|'${c1[30+i]}' "${s[$3]}";done<<<"${v[$4]}" `;[[ "$v" ]];};A'$((5+i))'() { v=` while read i;do '${c1[30+i]}' "${s[$1]}" "$i";done<<<"${v[$2]}" `;[[ "$v" ]];};';done;A7(){ v=$((`date +%s`-v[3]));};B2(){ v[$1]="$v";};for i in 0 1;do eval ' B'$i'() { v=;((v['$((i+1))']==0))||{ v=No;false;};};B'$((3+i))'() { v[$2]=`'${c1[30+i]}' "${s[$3]}"<<<"${v[$1]}"`;} ';done;B5(){ v[$1]="${v[$1]}"$'\n'"${v[$2]}";};B6() { v=` paste -d: <(printf "${v[$1]}") <(printf "${v[$2]}")|awk -F: ' {printf("'"${f[$3]}"'",$1,$2)} ' `;};B7(){ v=`grep -Fv "${v[$1]}"<<<"$v"`;};C0() { [[ "$v" ]]&&sed -E "$s"<<<"$v";};C1() { [[ "$v" ]]&&printf "${f[$1]}" "${l[$2]}" "$v";};C2() { v=`echo $v`;[[ "$v" != 0 ]]&&C1 0 $1;};C3() { v=`sed -E "${s[63]}"<<<"$v"`&&C1 1 $1;};for i in 1 2;do for j in 0 2 3;do eval D$i$j'(){ A'$i' $1 $2 $3; C'$j' $4;};';done;done;{ A0;D20 0 $((N1+1)) 2;D10 0 $N1 1;B0;C2 27;B0&&! B1&&C2 28;D12 15 37 25 8;A1 0 $((N1+2)) 3;C0;D13 0 $((N1+3)) 4 3;D23 0 $((N1+4)) 5 4;D13 0 $((N1+9)) 59 50;for i in 0 1 2;do D13 0 $((N1+5+i)) 6 $((N3+i));done;D13 1 10 7 9;D13 1 11 8 10;D22 2 12 9 11;D12 3 13 10 12;D23 4 19 44 13;D23 5 14 12 14;D22 6 36 13 15;D22 7 37 14 16;D23 8 15 38 17;D22 9 16 16 18;B1&&{ D22 35 49 61 51;D22 11 17 17 20;for i in 0 1;do D22 28 $((N2+i)) 45 $((N4+i));done;};D22 12 44 54 45;D22 12 39 15 21;A1 13 40 18;B2 4;B3 4 0 19;A3 14 6 32 0;B4 0 5 11;A1 17 41 20;B7 5;C3 22;B4 4 6 21;A3 14 7 32 6;B4 0 7 11;B3 4 0 22;A3 14 6 32 0;B4 0 8 11;B5 7 8;B1&&{ A2 19 26 23;B7 7;C3 23;};A2 18 26 23;B7 7;C3 24;D13 4 21 24 26;B4 4 12 26;B3 4 13 27;A1 4 22 29;B7 12;B2 14;A4 14 6 52 14;B2 15;B6 14 15 4;B3 0 0 30;C3 29;A1 4 23 27;B7 13;C3 30;D13 24 24 32 31;D13 25 37 32 33;A2 23 18 28;B2 16;A2 16 25 33;B7 16;B3 0 0 34;B2 21;A6 47 21&&C0;B1&&{ D13 21 0 32 19;D13 10 42 32 40;D22 29 35 46 39;};D23 14 1 62 42;D12 34 43 53 44;D12 22 20 32 25;D22 0 $((N1+8)) 51 32;D13 4 8 41 6;D12 26 28 35 34;D13 27 29 36 35;A2 27 32 39&&{ B2 19;A2 33 33 40;B2 20;B6 19 20 3;};C2 36;D23 33 34 42 37;B1&&D23 35 45 55 46;D23 32 31 43 38;D12 36 47 32 48;D13 20 42 32 41;D13 37 2 48 43;D13 4 5 32 1;D13 4 3 60 5;D12 26 48 49 49;B3 4 22 57;A1 26 46 56;B7 22;B3 0 0 58;C3 47;D22 4 4 50 0;D23 22 9 37 7;A7;C2 2;} 2>/dev/null|pbcopy;exit 2>&-
    Copy the selected text to the Clipboard by pressing the key combination command-C.
    8. Launch the built-in Terminal application in any of the following ways:
    ☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)
    ☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.
    ☞ Open LaunchPad. Click Utilities, then Terminal in the icon grid.
    Click anywhere in the Terminal window and paste by pressing command-V. The text you pasted should vanish immediately. If it doesn't, press the return key.
    9. If you see an error message in the Terminal window such as "Syntax error" or "Event not found," enter
    exec bash
    and press return. Then paste the script again.
    10. If you're logged in as an administrator, you'll be prompted for your login password. Nothing will be displayed when you type it. You will not see the usual dots in place of typed characters. Make sure caps lock is off. Type carefully and then press return. You may get a one-time warning to be careful. If you make three failed attempts to enter the password, the test will run anyway, but it will produce less information. In most cases, the difference is not important. If you don't know the password, or if you prefer not to enter it, press the key combination control-C or just press return  three times at the password prompt. Again, the script will still run.
    If you're not logged in as an administrator, you won't be prompted for a password. The test will still run. It just won't do anything that requires administrator privileges.
    11. The test may take a few minutes to run, depending on how many files you have and the speed of the computer. A computer that's abnormally slow may take longer to run the test. While it's running, there will be nothing in the Terminal window and no indication of progress. Wait for the line
    [Process completed]
    to appear. If you don't see it within half an hour or so, the test probably won't complete in a reasonable time. In that case, close the Terminal window and report what happened. No harm will be done.
    12. When the test is complete, quit Terminal. The results will have been copied to the Clipboard automatically. They are not shown in the Terminal window. Please don't copy anything from there. All you have to do is start a reply to this comment and then paste by pressing command-V again.
    At the top of the results, there will be a line that begins with the words "Start time." If you don't see that, but instead see a mass of gibberish, you didn't wait for the "Process completed" message to appear in the Terminal window. Please wait for it and try again.
    If any private information, such as your name or email address, appears in the results, anonymize it before posting. Usually that won't be necessary.
    13. When you post the results, you might see an error message on the web page: "You have included content in your post that is not permitted," or "You are not authorized to post." That's a bug in the forum software. Please post the test results on Pastebin, then post a link here to the page you created.
    14. This is a public forum, and others may give you advice based on the results of the test. They speak only for themselves, and I don't necessarily agree with them.
    Copyright © 2014 by Linc Davis. As the sole author of this work, I reserve all rights to it except as provided in the Use Agreement for the Apple Support Communities website ("ASC"). Readers of ASC may copy it for their own personal use. Neither the whole nor any part may be redistributed.

  • New Trojan Horses

    Last night, I made the mistake of downloading an app called "Wine" and "Winebottler". These are apps that allow Windows programs to be played on Macintosh without installing Windows. I ended up with 13 new OSX Trojan Horses on my Macintosh. These apps kept on installing add ons to the iTunes Store. I knew I was in trouble immediately, I guess, by instinct.I had also installed Wineskin for the same purpose, but I don't think that was the problem as I found no Trojan Horses associated with this app. I had my security set to download from App Store and Trusted Developers only. I am now going to upgrade my security to download from App Store only now, but I don't know for sure if that will help.
    Luckily, I had Kaspersky on my Mac, and it kept on finding Trojan Horses on a full scan. I had firevault on and iCloud on. I am wondering now if my iCloud account is infected. I am currently erasing my whole hard drive and reinstalling. I will not turn on iCloud until I get some advice. For those that are unaware, I know we are in a cyberwar. I don't know where these apps originated, but I wanted the community to know this. I've used Macintosh since the first day it was available in 1984. I've never had troubles with viruses and Trojan Horses like this, except for two that were found by Kaspersky a couple of months ago and were easily found, isolated and disinfected. Not these. Most were easily disinfected: all but two. I had to restart the computer and Kaspersky got rid of them. Kaspersky is a great program, but I wasn't sure if it got rid of everything, which led me to erase and reinstall.
    Please inform my about how secure iCloud is against attached viruses or should I delete my account.

    etresoft wrote:
    straycat23 wrote:
    I downloaded from WineHQ.org.
    I doubt that because WineHQ doesn't have any Mac versions of Wine available. They distribute Linux binaries and source. If you downloaded a Mac version, it must have come from somewhere else.
    As soon as I downloaded it and the Winebottler, I knew I had problems.
    Why?
    I took your earlier advice: left OS10.9.1 in place and turned iCloud back on. I hope I made the right decision. I did not delete Kaspersky because OSX did not delete the Trojan or prevent it from being downloaded. Kaspersky did.
    But you are in a catch-22 situation here. These forums are full of people reporting problems with computers and antivirus is a very common cause. By comparison, there are far fewer people reporting problems with trojans. Are these programs really trojans? And even if they are, would they cause as much trouble and be as difficult to remove as antivirus? I doubt it
    As far as I can tell WineHQ must be a trusted developer, because that is how my computer is set as I previously stated.
    I would definitely consider WineHQ to be trustworthy (more so than antivirus vendors) but they definitely do not have an Apple Developer ID that would enable them to distribute software past Gatekeeper. Someone malicious may have repackaged Wine, added trojans, and signed it with a Developer ID. The only way to address that problem is to identify where you got the software so that the illicit Developer ID can be revoked.
    I did not download these programs to play games. That's for Millenials. I downloaded these because Windows is a disaster, and I didn't want to load Windows on my computer. There are Windows programs that there is no equivalent in Mac.
    It doesn't matter why you downloaded them. If they are Windows programs, you are going to have to run Windows. Wine is a cool project, but very little software actually works on it.
    I also deleted Adobe Flash Player as was advised in another thread. Now I can't see instructions in YouTube. Does the App Store have a recommended flash player to see You Tube?
    Download Adobe Flash directly from Adobe and installer. Then download the Click2Flash Safari extension: http://hoyois.github.io/safariextensions/clicktoplugin/ so you can avoid Flash, if possible. If you ever get any Flash popup asking for an update, always close it - always. Then go to the Adobe Flash site yourself and see if there is an update and download it.
    I downloaded the program from WineHQ. It's in my history. I went back and looked today. I don't think Linux has an iTunes version. I downloaded a program I didn't request that attached itself to iTunes. This is how I knew I had problems.
    I appreciate all the advice: dismissive or not. It did give me confidence there's nothing wrong with my computer. I just don't have faith in Mac like I used to. I'm guessing that the trojans were not real, but I'm glad I had a device to delete the false positives, if for no other reason than it made me feel better. Any website can be attacked by hackers. Maybe that's what happened to WineHQ.

  • Trojan horse Dropper.Generic2.CKPW

    AVG found Trojan horse Dropper.Generic2.CKPW when I downloaded the update to QuickTime. AVG can't delete or vault it.

    Yeah, I think so. I ran AVG free AV/AS and it quarantined the Dropper2 trojan and the registry entry from the SysWoW folder and everything still works. I rebooted, ran iTunes, synced, rebooted again and everything still works with no sign of the virus. I called Apple yesterday wanting to know why I had to keep entering my account info and they wanted me to log in, change my password, then change it back. This might have been an honest attempt to solve my problem, but I wasn't born yesterday and I really see no reason for me to change my password and then change it back again. If I've hurt someone at Apple's feelings, well... boo hoo!!

  • Trojan horse on iPod installation disk?

    I just installed iTunes a couple of days ago for my new iPod Nano. This morning, we discovered a trojan horse on the PC - the only software we've installed since the last scan of the PC is iTunes.
    Has anyone else run into this?

    hmmmm. what is the name of the trojan? (exact spelling please.)
    which security software package picked it up?

  • Trojan Horse Virus

    A little while ago, my macbook was very slow and I went into the Apple store and they recommended that I turn Norton Antivirus off. I did.
    A few months later (now) I ran it just for the heck of it to see if it found anything - and it did. Two or three Trojan Horse malware files. Looking at Nortons descriptions, I think that they were (I located and deleted them) all PC based virus BUT, I am wondering:
    1. I have Microsoft Office for Mac on my Macbook and I am wondering if those files might have been compromised by a PC virus?
    2. I am assuming that if these files have been compromised there is nothing that I can do about retrieving that information as it could be anywhere.
    3. If I have other PC based drives hooked up to my macbook wirelessly - were they vulnerable while I had these Trojan Horses on my Macbook?
    Thanks.
    A.

    Don't always believe what Norton tells you. It is incompatible with OS X.
    Norton Antivirus has a very long and illustrious reputation for mangling Mac OS X systems, sometimes to the point where a complete reinstall is necessary. Among other things, it installs kernel extensions which are known to cause kernel panics and system freezes; it contains known and documented bugs which can silently corrupt Adobe Photoshop and Adobe InDesign files, destroy a user's ability to authenticate as an administrator, and (on PPC systems) can cause Classic to stop functioning; and Symantec has on at least two occasions now released flawed .dat file updates which erroneously report certain critical Mac OS X files as "viruses." (Deleting these "viruses" causes damage to the system that in some cases renders it unbootable.)
    1. No
    2. Need more details about what you call 'compromised'
    3. Yes.
    No viruses that can attack OS X have so far been detected 'in the wild', i.e. in anything other than laboratory conditions.
    It is possible, however, to pass on a Windows virus to another Windows user, for example through an email attachment. To prevent this all you need is the free anti-virus utility ClamXav, which you can download for Tiger and Leopard from (on no account install Norton Anti-Virus on a Mac running OS X):
    http://www.clamxav.com/
    The new version for Snow Leopard is available here:
    http://www.clamxav.com/index.php?page=v2beta
    (Note: ClamAV adds a new user group to your Mac. That makes it a little more difficult to remove than some apps. You’ll find an uninstaller link in ClamXav’s FAQ page online.)
    If you are already using ClamXav: please ensure that you have installed Apple Security Update 2010-005 and that your version of ClamXav is the latest available.
    However, the appearance of Trojans and other malware that can possibly infect a Mac seems to be growing, but is a completely different issue to viruses.
    If you allow a Trojan to be installed, the user's DNS records can be modified, redirecting incoming internet traffic through the attacker's servers, where it can be hijacked and injected with malicious websites and pornographic advertisements. The trojan also installs a watchdog process that ensures the victim's (that's you!) DNS records stay modified on a minute-by-minute basis.
    You can read more about how, for example, the OSX/DNSChanger Trojan works here:
    http://www.f-secure.com/v-descs/trojanosxdnschanger.shtml
    SecureMac has introduced a free Trojan Detection Tool for Mac OS X. It's available here:
    http://macscan.securemac.com/
    The DNSChanger Removal Tool detects and removes spyware targeting Mac OS X and allows users to check to see if the trojan has been installed on their computer; if it has, the software helps to identify and remove the offending file. After a system reboot, the users' DNS records will be repaired.
    (Note that a 30 day trial version of MacScan can be downloaded free of charge from:
    http://macscan.securemac.com/buy/
    and this can perform a complete scan of your entire hard disk. After 30 days free trial the cost is $29.99. The full version permits you to scan selected files and folders only, as well as the entire hard disk. It will detect (and delete if you ask it to) all 'tracker cookies' that switch you to web sites you did not want to go to.)
    A white paper has recently been published on the subject of Trojans by SubRosaSoft, available here:
    http://www.macforensicslab.com/ProductsAndServices/index.php?mainpage=document_general_info&cPath=11&productsid=174
    Also, beware of MacSweeper:
    MacSweeper is malware that misleads users by exaggerating reports about spyware, adware or viruses on their computer. It is the first known "rogue" application for the Mac OS X operating system. The software was discovered by F-Secure, a Finland based computer security software company on January 17, 2008
    http://en.wikipedia.org/wiki/MacSweeper
    On June 23, 2008 this news reached Mac users:
    http://www.theregister.co.uk/2008/06/23/mac_trojan/
    More on Trojans on the Mac here:
    http://www.technewsworld.com/story/63574.html?welcome=1214487119
    This was published on July 25, 2008:
    Attack code that exploits flaws in the net's addressing system are starting to circulate online, say security experts.
    The code could be a boon to phishing gangs who redirect web users to fake bank sites and steal login details.
    In light of the news net firms are being urged to apply a fix for the loop-hole before attacks by hi-tech criminals become widespread.
    Net security groups say there is anecdotal evidence that small scale attacks are already happening.
    Further details here: http://news.bbc.co.uk/2/hi/technology/7525206.stm
    A further development was the Koobface malware that can be picked up from Facebook (already a notorious site for malware, like many other 'social networking' sites like Twitter etc), as reported here on December 9, 2008:
    http://news.bbc.co.uk/newsbeat/hi/technology/newsid_7773000/7773340.stm
    You can keep up to date, particularly about malware present in some downloadable pirated software, at the Securemac site:
    http://www.securemac.com/
    There may be other ways of guarding against Trojans, viruses and general malware affecting the Mac, and alternatives will probably appear in the future. In the meantime the advice is: be careful where you go on the web and what you download!
    If you think you may have acquired a Trojan, and you know its name, you can also locate it via the Terminal:
    http://theappleblog.com/2009/04/24/mac-botnet-how-to-ensure-you-are-not-part-of- the-problem/
    As to the recent 'Conficker furore' affecting Intel-powered computers, MacWorld recently had this to say:
    http://www.macworld.co.uk/news/index.cfm?email&NewsID=25613
    Although any content that you download has the possibility of containing malicious software, practising a bit of care will generally keep you free from the consequences of anything like the DNSChanger trojan.
    1. Avoid going to suspect and untrusted Web sites, especially p'orn'ography sites.
    2. Check out what you are downloading. Mac OS X asks you for you administrator password to install applications for a reason! Only download media and applications from well-known and trusted Web sites. If you think you may have downloaded suspicious files, read the installer packages and make sure they are legit. If you cannot determine if the program you downloaded is infected, do a quick Internet search and see if any other users reported issues after installing a particular program. A recent example is of malware distributed through innocent looking free screensavers: http://www.zdnet.com/blog/security/malware-watch-free-mac-os-x-screensavers-bund led-with-spyware/6560?tag=nl.e589
    3. Use an antivirus program like ClamXav. If you are in the habit of downloading a lot of media and other files, it may be well worth your while to run those files through an AV application.
    4. Use Mac OS X's built-in Firewalls and other security features.
    5. Stop using LimeWire. LimeWire (and other peer-to-peer sharing applications and download torrents) are hotbeds of potential software issues waiting to happen to your Mac. Everything from changing permissions to downloading trojans and other malicious software can be acquired from using these applications. Similar risks apply to using Facebook, Twitter, MySpace, YouTube and similar sites which are prone to malicious hacking: http://news.bbc.co.uk/1/hi/technology/8420233.stm
    6. Resist the temptation to download pirated software. After the release of iWork '09 earlier this year, a Trojan was discovered circulating in pirated copies of Apple's productivity suite of applications (as well as pirated copies of Adobe's Photoshop CS4). Security professionals now believe that the botnet (from iServices) has become active. Although the potential damage range is projected to be minimal, an estimated 20,000 copies of the Trojan have been downloaded. SecureMac offer a simple and free tool for the removal of the iBotNet Trojan available here:
    http://macscan.securemac.com/files/iServicesTrojanRemovalTool.dmg
    Also, there is the potential for having your entire email contact list stolen for use for spamming:
    http://www.nytimes.com/2009/06/20/technology/internet/20shortcuts.html?_r=1
    NOTE: Snow Leopard, OS 10.6.x, offers additional security to that of previous versions of OS X, but not to the extent that you should ignore the foregoing:
    http://www.apple.com/macosx/security/
    Apple's 10.6.4 operating system upgrade silently updated the malware protection built into Mac OS X to protect against a backdoor Trojan horse that can allow hackers to gain remote control over your treasured iMac or MacBook.
    http://www.sophos.com/blogs/gc/g/2010/06/18/apple-secretly-updates
    Finally, do not install Norton Anti-Virus on a Mac as it can seriously damage your operating system. Norton Anti-Virus is not compatible with Apple OS X.
    And if you are using iPhone Apps you are also at risk of losing all privacy:
    http://www.engadget.com/2010/10/03/hacker-claims-third-party-iphone-apps-can-tra nsmit-udid-pose-se/

  • Possible worm or trojan horse?

    I got my powerbookg4 (panther) back from apple repair today and now when I open up Safari I get a message from my isp "Spam Alert: Your PC may be infected with a virus that sends out large amounts of spam. As such, your outbound email service has been temporarily suspended." Click below for more information" When you click you get another message that explains that a large volume of outgoing mail has been detected and that it is indicative of a virus or trojan horse. I can click on a button to go to a free location to check out my system. That sounds suspicious in and of itself, but if you go directly to my providers website, they also link to the same place. Additionally, that site doesn't check safari browser, mac osx.
    So this is perplexing. How do I know if this is possible on my machine? I rarely use my provider email, and all my email accounts go through apple mail. I logged on to my son's mac to see if he got the same thing, hoping the provider was just sending out random messages but it didn't occur on his machine.
    Advice? Thoughts? I do not have a virus protection program on my mac, but I do not visit suspicious sites, do not download from unknown sites, all my music is from itunes, etc. Is the a reputable site I can use to check out my mac?
    Thanks

    Hi Carole,
    I would ignore the on-line warning, especially clicking on the links. No telling what type of spam they'll produce. If you have concerns, call your ISP directly.
    While you can certainly pass on a virus/trojan horse, etc. through an e-mail, these type of items do not affect the Mac.
    To date, no virus has been written for the Mac (there was a suedo virus written earlier this year - much ado about nothing). From your description, it seems your surfing habits are quite conservative. If true, then Virus software would be unnecessary.

  • Defualt Black Bla Trojan Horse from Norton

    Norton antivirus says a worm was detected and blocked every time i open itunes and comcast at the same time, thats not exactly at the same time, for thats physically impossible, but a close periods. Whats this all about.
    By the way Defalt Black Bla Trojan Horse is the worm suppodsly tryn to get in.

    yeah, figures

  • Recent Trojan Horse Stories

    I've been a Mac User for more than 5 years and I've never bought an Antivirus, however I've been seeing articles of Mac's getting something called a Trojan Horse now I'm kind of nervous that I will get it. Can anyone recomend a antivirus?

    jnjaquez wrote:
    I've been seeing articles of Mac's getting something called a Trojan Horse now I'm kind of nervous that I will get it. Can anyone recomend a antivirus?
    (1) Debates about the distinction (if any) between Trojan Horses and viruses are, IMHO, best left to the specialists, who have the time to engage in them and the training to understand the arguments. For us, as average users, they don't matter that much. After all, if my bank account password was stolen, I couldn't care less if it was stolen by a virus, a Trojan Horse, or the frumious bandersnatch.
    (2) The latest versions of Flashback installed themselves without any user interaction. They were not "invited" in any way; the user did not have to "download and execute something". Whether this means that Flashback is "no longer entirely a trojan", as Thomas A Reed puts in the page linked by shldr2thewheel, or that it's a backdoor (or whatever), leave the fun of arguing over it to others. We can just call it malware and be done with it.
    (3) There are two problems with A/V software.
    (a) Macs are a very small market compared to Win; moreover, (for whatever reason) Macs have been much less affected by malware. Consequently, it doesn't make business sense for any commercial A/V developer to put his A Team on developing Mac A/V software. And the products on offer show the signs of being developed by the B Team—by and large, they are intrusive, not very well programmed, and not very well tested.
    (b) A/V software is only as good as the latest upate, and protects only against known threats. In the past five or six weeks, Flashback evolved constantly and fairly rapidly, while A/V updates in general didn't match the pace.
    So, for A/V software, I'd go with BGreg's suggestion of ClamXav (which is not commercial, but a free Mac port of an open-source A/V engine). However, don't assume that, once it is installed, you are fully protected.
    (4) A common thread in the last weeks of the Flashback soap opera has been the reverse firewall. Mac OS X has a built-in firewall (one that controls in-coming connections); but it doesn't have a reverse firewall (which controls outgoing connections). Some versions of Flashback self-immolated when they detected Little Snitch, a popular reverse firewall (Hands Off! is another); others were caught and blocked by Little Snitch. I'd say, this day and age, a reverse firewall is essential.
    In short, what should you do?
    Use your common sense (best and most useful tool).
    Keep yourself informed. (The danger posed by Java vulnerabilities was fairly well known.)
    Get a reverse firewall (Little Snitch or Hands Off!).
    Install ClamXav.
    Adopt good working habits, including using a standard (rather than admin) account for most of your work.
    Back up, back up, and back up some more (eg, Time Machine). And always have an emergency boot device at hand.

  • Trojan Horse alert!

    If you get an e-mail from "iTunes Online Products" with the title "Thank You For Buying iTunes Gift Certificate" containing an attachment that claims to be a $50 gift card from iTunes, don't open it -- it's a Trojan Horse.

    Apple has been alerted. But as the others have said, there's probably little or nothing they can do. The scam is probably coming either from some foreign country with lax enforcement of from a botnet of hacked Windows systems.

Maybe you are looking for

  • Mail Duplicates IMAP account Snow Leopard

    Hey everyone- I'm getting duplicate emails on an IMAP account- I know there is another post about this issue, but it seems to mostly pertain to POP emails, but nothing I've read or seen on this forum or any other has yet helped me. Also I don't know

  • RverseDep Amount Posted

    Hello, How to reverse the Dep Amount already posted.I know that changing the Dep ket as 0000 Asset Master Record and Rerun will solve this.But how to setup this ? Ststem is not allowing to select the 0000 Dep Key in Assets ? Plz help me it is very ur

  • Howto manage object-livecycle in distributed systems?

    Hi there, I am currently working on a distributed clients-server system where a GUI resides on the clients whereas the programmer programs to server-side dummies like the GUI would be running local. Therefor I map between client-side-Implementation a

  • InDesign won't export pdf

    I'm using InDesign CS5 on OSX 10.8. I've tried to export multiple pdfs from various files and have this problem every now and then (Which happend on both OSX 10.7 and 10.8). The empty pdf file will start as if nothing is wrong and then just disappear

  • How do I dynamicaly sum a column in Pages without specifiying start/end?

    How do I dynamicaly sum a column without specifiying a start/end range? I want to add a new row anytime and have that sum total reflect the new row value.