Possible malware or infection??

so my iphone was recently booted from my schools wifi network because they say they detected a malware infection on my" computer" . Now my iphone seems to be working fine, no signs of a problem. But they said i cant get access back till i've identified the problem and cleaned it up. is there any way to identify such a problem on my iphone if one existed????

evilclaw2321,
Without some verification that the packages you install only do the things they say they will, there is no way to tell what is happening.
Without some verification and certification of the applications, whether or not a give application does more than what it says, is entirely up to how trustworthy the author and source for getting it is.
Yes, it is possible you could have malware installed. However, troubleshooting specific applications installed by breaking your iPhone's license agreement is not something that can be done within Apple Discussions.
Hope this helps,
Nathan C.

Similar Messages

  • My wife has been having problems with Safari, and many third party software and malware programs infecting her Mac Book Pro.

    My wife has been having problems with Safari, and many third party software and malware programs infecting her Mac Book Pro. I have tried to reset Safari but it keeps coming back, taking over Safari, changing defaults, start pages, and search engines, Etc.
    Is it safe to use programs like MacKeeper, who keeps send my wife's computer message and alerts, or should I just wipe the drive and start over?
    Skip

    I am having lot's of lag time with Safari, etc..
    I'll type in a website.. and it will take 15-20 seconds to start..
    Start time: 17:51:37 12/02/14
    Model Identifier: MacBookPro11,3
    System Version: OS X 10.10.1 (14B25)
    Kernel Version: Darwin 14.0.0
    Time since boot: 14 days 3:02
    USB
       My Passport 07B8 (Western Digital Technologies, Inc.)
    Diagnostic reports
       2014-11-13 QuickLookSatellite crash x2
       2014-11-21 com.apple.WebKit.Plugin.64 crash
    Log
       Nov 30 21:32:39 PM notification timeout (pid 345, Adobe CEF Helper)
       Nov 30 21:32:39 PM notification timeout (pid 99018, CEPHtmlEngine)
       Nov 30 21:32:39 PM notification timeout (pid 99019, CEPHtmlEngine He)
       Dec  1 09:09:03 [[0xffffff802bfa4000]  OpCode 0x0C01 (Set Event Mask) from: kernel_task (0)  Synchronous  status: 0x00 (kIOReturnSuccess) state: 2 (BUSY) timeout: 5000] Bluetooth warning: An HCI Req timeout occurred.
       Dec  1 09:52:03 PM notification timeout (pid 266, Creative Cloud)
       Dec  1 09:52:03 PM notification timeout (pid 346, Adobe CEF Helper)
       Dec  1 09:52:03 PM notification timeout (pid 345, Adobe CEF Helper)
       Dec  1 10:04:37 process WindowServer[114] caught causing excessive wakeups. Observed wakeups rate (per sec): 170; Maximum permitted wakeups rate (per sec): 150; Observation period: 300 seconds; Task lifetime number of wakeups: 12755007
       Dec  1 10:31:08 ALF: ifnet_get_address_list_family error 12
       Dec  1 10:59:17 process Meeting Center[2921] caught causing excessive wakeups. Observed wakeups rate (per sec): 647; Maximum permitted wakeups rate (per sec): 150; Observation period: 300 seconds; Task lifetime number of wakeups: 45104
       Dec  1 12:24:35 process com.apple.WebKit[4567] caught causing excessive wakeups. Observed wakeups rate (per sec): 297; Maximum permitted wakeups rate (per sec): 150; Observation period: 300 seconds; Task lifetime number of wakeups: 76962
       Dec  1 14:31:01 process com.apple.WebKit[7400] caught causing excessive wakeups. Observed wakeups rate (per sec): 397; Maximum permitted wakeups rate (per sec): 150; Observation period: 300 seconds; Task lifetime number of wakeups: 53188
       Dec  1 14:43:52 process com.apple.WebKit[7400] caught causing excessive wakeups. Observed wakeups rate (per sec): 224; Maximum permitted wakeups rate (per sec): 150; Observation period: 300 seconds; Task lifetime number of wakeups: 150084
       Dec  1 14:47:34 process com.apple.WebKit[7400] caught causing excessive wakeups. Observed wakeups rate (per sec): 332; Maximum permitted wakeups rate (per sec): 150; Observation period: 300 seconds; Task lifetime number of wakeups: 222103
       Dec  1 15:03:29 process com.apple.WebKit[7400] caught causing excessive wakeups. Observed wakeups rate (per sec): 214; Maximum permitted wakeups rate (per sec): 150; Observation period: 300 seconds; Task lifetime number of wakeups: 370572
       Dec  1 16:38:03 SIOCPROTODETACH_IN6: utun2 error=6
       Dec  1 16:38:08 SIOCPROTODETACH_IN6: utun2 error=6
       Dec  1 20:08:30 jnl: disk3s2: replay_journal: from: 112328704 to: 113115136 (joffset 0x3a38000)
       Dec  1 20:08:30 jnl: disk3s2: journal replay done.
       Dec  1 20:27:11 com.adobe.acc.AdobeCreativeCloud.75292.UUID: Service exited with abnormal code: 5
       Dec  2 08:23:00 process com.apple.WebKit[11891] caught causing excessive wakeups. Observed wakeups rate (per sec): 161; Maximum permitted wakeups rate (per sec): 150; Observation period: 300 seconds; Task lifetime number of wakeups: 527508
       Dec  2 09:29:37 firefox (map: 0xffffff80317c5960) triggered DYLD shared region unnest for map: 0xffffff80317c5960, region 0x7fff9ae00000->0x7fff9b000000. While not abnormal for debuggers, this increases system memory footprint until the target exits.
       Dec  2 10:04:39 SIOCPROTODETACH_IN6: utun2 error=6
       Dec  2 10:04:44 SIOCPROTODETACH_IN6: utun2 error=6
       Dec  2 16:42:24 process com.apple.WebKit[26151] caught causing excessive wakeups. Observed wakeups rate (per sec): 153; Maximum permitted wakeups rate (per sec): 150; Observation period: 300 seconds; Task lifetime number of wakeups: 45002
    Swap (MiB): 41556
    Activity
       Net: 210 in, 20 out (KiB/s)
    Memory: kernel_task (UID 0) is using 1632 MB
    kexts
       com.cisco.kext.acsock (1.1.0)
       com.wdc.driver.USB.64.10.9 (1.0.1)
    Daemons
       com.cisco.anyconnect.vpnagentd
       com.oracle.java.JavaUpdateHelper
       com.apple.installer.osmessagetracing
       com.microsoft.office.licensing.helper
       com.google.keystone.daemon
       com.wdc.WDSmartWareService
       com.oracle.java.Helper-Tool
       com.adobe.fpsaud
       com.wdc.SmartwareDriveService
    Agents
       com.adobe.AdobeCreativeCloud
       com.zimbra.desktop
       com.citrix.ServiceRecords
       com.google.keystone.system.agent
       com.apple.photostream-agent
       com.genieo.completer.download
       com.genieo.completer.update
       com.cisco.anyconnect.gui
       com.citrix.ReceiverHelper
       com.citrix.AuthManager_Mac
       com.citrix.FMDAgent.14800.UUID
       com.oracle.java.Java-Updater
       com.fiplab.MailTabProHelper
       com.adobe.PDApp.AAMUpdatesNotifier.74724.UUID
       com.citrixonline.GoToMeeting.G2MUpdate
       com.apple.AirPortBaseStationAgent
       com.microsoft.SyncServicesAgent
    Startup items
       /System/Library/StartupItems/ciscod/ciscod
       /System/Library/StartupItems/ciscod/StartupParameters.plist
    Bundles
       /System/Library/Extensions/hp_fax_io.kext
       - com.hp.kext.hp-fax-io
       /System/Library/Extensions/hp_Inkjet1_io_enabler.kext
       - com.hp.print.hpio.Inkjet1.kext
       /System/Library/Extensions/hp_Inkjet4_io_enabler.kext
       - com.hp.print.hpio.Inkjet4.kext
       /System/Library/Extensions/hp_Inkjet8_io_enabler.kext
       - com.hp.print.hpio.inkjet8.kext
       /System/Library/Extensions/JMicronATA.kext
       - com.jmicron.JMicronATA
       /System/Library/Extensions/WD1394_64_109HPDriver.kext
       - com.wdc.driver.1394.64.10.9
       /System/Library/Extensions/WDUSB_64_109HPDriver.kext
       - com.wdc.driver.USB.64.10.9
       /Library/Extensions/hp_io_printerclassdriver_enabler.kext
       - com.hp.hpio.hp-io-printerclassdriver-enabler
       /Library/Internet Plug-Ins/AdobeAAMDetect.plugin
       - com.AdobeAAMDetectLib.AdobeAAMDetect
       /Library/Internet Plug-Ins/CitrixICAClientPlugIn.plugin
       - com.citrix.citrixicaclientplugIn
       /Library/Internet Plug-Ins/Flash Player.plugin
       - N/A
       /Library/Internet Plug-Ins/googletalkbrowserplugin.plugin
       - com.google.googletalkbrowserplugin
       /Library/Internet Plug-Ins/JavaAppletPlugin.plugin
       - com.oracle.java.JavaAppletPlugin
       /Library/Internet Plug-Ins/npg.plugin
       - npg.graphon.com
       /Library/Internet Plug-Ins/o1dbrowserplugin.plugin
       - com.google.o1dbrowserplugin
       /Library/Internet Plug-Ins/SharePointBrowserPlugin.plugin
       - com.microsoft.sharepoint.browserplugin
       /Library/Internet Plug-Ins/SharePointWebKitPlugin.webplugin
       - com.microsoft.sharepoint.webkitplugin
       /Library/Internet Plug-Ins/Silverlight.plugin
       - com.microsoft.SilverlightPlugin
       /Library/Internet Plug-Ins/SlingPlayer.plugin
       - com.slingmedia.slingplayer.plugin.nspapi
       /Library/PreferencePanes/Flash Player.prefPane
       - com.adobe.flashplayerpreferences
       /Library/PreferencePanes/FMDSysPrefPane.prefPane
       - Citrix.FMDSysPrefPane
       /Library/PreferencePanes/JavaControlPanel.prefPane
       - com.oracle.java.JavaControlPanel
       /Library/PreferencePanes/WDQuickViewPrefsPane.prefPane
       - com.westerndigital.quickview.prefpanel
       /Library/PreferencePanes/Zimbra.prefPane
       - com.zimbra.prefpanel
       /Library/ScriptingAdditions/Adobe Unit Types.osax
       - N/A
       Library/Address Book Plug-Ins/SkypeABDialer.bundle
       - com.skype.skypeabdialer
       Library/Address Book Plug-Ins/SkypeABSMS.bundle
       - com.skype.skypeabsms
       Library/Internet Plug-Ins/CitrixOnlineWebDeploymentPlugin.plugin
       - com.citrixonline.mac.WebDeploymentPlugin
       Library/Internet Plug-Ins/Google Earth Web Plug-in.plugin
       - com.Google.GoogleEarthPlugin.plugin
       Library/Internet Plug-Ins/WebEx.plugin
       - com.webex.WebEx
       Library/Internet Plug-Ins/WebEx.plugin/Contents/Resources
       - com.webex.WebEx
       Library/Internet Plug-Ins/WebEx64.plugin
       - com.cisco_webex.plugin.gpc64
    dylibs
       /usr/lib/libaudioc.dylib
       /usr/lib/libclipc.dylib
       /usr/lib/libcs.dylib
       /usr/lib/libdc.dylib
       /usr/lib/libfilec.dylib
       /usr/lib/libMonoPosixHelper.dylib
       /usr/lib/libpbr.dylib
       /usr/lib/libprintc.dylib
       /usr/lib/libsc.dylib
       /usr/lib/libSFFileMonitor.32.dylib
       /usr/lib/libSFIPC.32.dylib
       /usr/lib/libSFIPC.I.dylib
       /usr/lib/libSFsqlite3.7.4.dylib
       /usr/lib/libSFSyncEngine.I.dylib
       /usr/lib/libupc.dylib
    App extensions
       it.bloop.airmail.beta10.Airmail-Today-Beta
       it.bloop.airmail.beta10.Airmail-Composer-Beta
       com.wunderkinder.wunderlistdesktop.sharingextension
       com.wunderkinder.wunderlistdesktop.todayextension
       com.readitlater.PocketMac.AddToPocketShareExtension
       com.stylemac.instadesk.Photodesk-Feed
       it.bloop.airmail.beta10.Airmail-Share-Beta
    Apps
       /Applications/Uninstall IM Completer.app
    Contents of /Library/LaunchAgents/com.cisco.anyconnect.gui.plist (checksum 1087717482)
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
       <plist version="1.0">
       <dict>
        <key>KeepAlive</key>
        <dict>
        <key>PathState</key>
        <dict>
        <key>/opt/cisco/anyconnect/gui_keepalive</key>
        <true/>
        </dict>
        </dict>
        <key>Label</key>
        <string>com.cisco.anyconnect.gui</string>
        <key>LimitLoadToSessionType</key>
        <string>Aqua</string>
        <key>ProgramArguments</key>
        <array>
        <string>open</string>
        <string>--wait-apps</string>
        <string>/Applications/Cisco/Cisco AnyConnect Secure Mobility Client.app</string>
        </array>
       </dict>
       </plist>
    Contents of /Library/LaunchAgents/com.citrix.AuthManager_Mac.plist (checksum 1591517921)
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
       <plist version="1.0">
       <dict>
        <key>ServiceIPC</key>
        <true/>
        <key>MachServices</key>
        <dict>
        <key>com.citrix.AuthManager_Mac</key>
        <true/>
        </dict>
        <key>Label</key>
        <string>com.citrix.AuthManager_Mac</string>
        <key>WaitForDebugger</key>
        <false/>
        <key>ProgramArguments</key>
        <array>
        <string>/usr/local/libexec/AuthManager_Mac.app/Contents/MacOS/AuthManager_Mac</ string>
        </array>
        <key>LimitLoadToSessionType</key>
        <string>Aqua</string>
        <key>Disabled</key>
        <false/>
       </dict>
       </plist>
    Contents of /Library/LaunchAgents/com.citrix.ReceiverHelper.plist (checksum 676087606)
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
       <plist version="1.0">
       <dict>
        <key>Label</key>
        <string>com.citrix.ReceiverHelper</string>
        <key>RunAtLoad</key>
        <true/>
        <key>KeepAlive</key>
        <dict>
        <key>SuccessfulExit</key>
        <false/>
        </dict>
        <key>WaitForDebugger</key>
        <false/>
        <key>ProgramArguments</key>
        <array>
        <string>/usr/local/libexec/ReceiverHelper.app/Contents/MacOS/ReceiverHelper</st ring>
        </array>
        <key>LimitLoadToSessionType</key>
        <string>Aqua</string>
        <key>Disabled</key>
        <false/>
       </dict>
       </plist>
    Contents of /Library/LaunchAgents/com.citrix.ServiceRecords.plist (checksum 1445213025)
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
       <plist version="1.0">
       <dict>
        <key>ServiceIPC</key>
        <true/>
        <key>MachServices</key>
        <dict>
        <key>com.citrix.Beacons</key>
        <true/>
        <key>com.citrix.ServiceRecords</key>
        <true/>
        </dict>
        <key>Label</key>
        <string>com.citrix.ServiceRecords</string>
        <key>RunAtLoad</key>
        <true/>
        <key>KeepAlive</key>
        <true/>
        <key>WaitForDebugger</key>
        <false/>
        <key>ProgramArguments</key>
        <array>
        <string>/usr/local/libexec/ServiceRecords.app/Contents/MacOS/ServiceRecords</st ring>
        </array>
       ...and 8 more line(s)
    Contents of /Library/LaunchAgents/com.oracle.java.Java-Updater.plist (checksum 3453356730)
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
       <plist version="1.0">
       <dict>
        <key>Label</key>
        <string>com.oracle.java.Java-Updater</string>
        <key>ProgramArguments</key>
        <array>
        <string>/Library/Internet Plug-Ins/JavaAppletPlugin.plugin/Contents/Resources/Java Updater.app/Contents/MacOS/Java Updater</string>
        <string>-bgcheck</string>
        </array>
        <key>StandardErrorPath</key>
        <string>/dev/null</string>
        <key>StandardOutPath</key>
        <string>/dev/null</string>
        <key>StartCalendarInterval</key>
        <dict>
        <key>Hour</key>
        <integer>9</integer>
        <key>Minute</key>
        <integer>57</integer>
        <key>Weekday</key>
        <integer>3</integer>
        </dict>
       </dict>
       ...and 1 more line(s)
    Contents of /Library/LaunchDaemons/com.cisco.anyconnect.vpnagentd.plist (checksum 2630047092)
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC -//Apple Computer//DTD PLIST 1.0//EN
       http://www.apple.com/DTDs/PropertyList-1.0.dtd >
       <plist version="1.0">
       <dict>
            <key>Label</key>
            <string>com.cisco.anyconnect.vpnagentd</string>
            <key>ProgramArguments</key>
            <array>
                 <string>/opt/cisco/anyconnect/bin/vpnagentd</string>
                 <string>-execv_instance</string>
            </array>
            <key>KeepAlive</key>
            <true/>
            <key>RunAtLoad</key>
            <true/>
            <key>AbandonProcessGroup</key>
            <true/>
            <key>EnableTransactions</key>
            <false/>
       </dict>
       </plist>
    Contents of /Library/LaunchDaemons/com.wdc.SmartwareDriveService.plist (checksum 2733252498)
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
       <plist version="1.0">
       <dict>
        <key>Label</key>
        <string>com.wdc.SmartwareDriveService</string>
        <key>Program</key>
        <string>/Library/Application Support/WD SmartWare Services/SmartwareDriveService</string>
        <key>RunAtLoad</key>
        <true/>
        <key>StandardErrorPath</key>
        <string>/dev/null</string>
       </dict>
       </plist>
    Contents of /Library/LaunchDaemons/com.wdc.WDSmartWareService.plist (checksum 1153517838)
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
       <plist version="1.0">
       <dict>
        <key>Label</key>
        <string>com.wdc.WDSmartWareService</string>
       <!-- <key>Program</key>
        <string>/Library/Application Support/WD SmartWare Services/SmartwareServerApp.app/Contents/MacOS/SmartwareServiceApp</string> -->
        <key>ProgramArguments</key>
        <array>
        <string>/Library/Application Support/WD SmartWare Services/SmartwareServiceApp.app/Contents/MacOS/SmartwareServiceApp</string>
        </array>
        <key>RunAtLoad</key>
        <true/>
        <key>StandardErrorPath</key>
        <string>/dev/null</string>
       </dict>
       </plist>
    Contents of Library/LaunchAgents/com.genieo.completer.download.plist (checksum 1894818845)
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
       <plist version="1.0">
       <dict>
        <key>Label</key>
        <string>com.genieo.completer.download</string>
        <key>ProgramArguments</key>
        <array>
        <string>/Users/USER/Library/Application Support/com.genieoinnovation.Installer/Completer.app/Contents/MacOS/Installer</ string>
        <string>-trigger</string>
        <string>download</string>
        <string>-isDev</string>
        <string>0</string>
        <string>-installVersion</string>
        <string>15886</string>
        <string>-firstAppId</string>
        <string>19340001</string>
        </array>
        <key>WatchPaths</key>
        <array>
        <string>/Users/USER/Downloads</string>
        </array>
       </dict>
       </plist>
    Contents of Library/LaunchAgents/com.genieo.completer.update.plist (checksum 2339121592)
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
       <plist version="1.0">
       <dict>
        <key>Label</key>
        <string>com.genieo.completer.update</string>
        <key>ProgramArguments</key>
        <array>
        <string>/Users/USER/Library/Application Support/com.genieoinnovation.Installer/Completer.app/Contents/MacOS/Installer</ string>
        <string>-trigger</string>
        <string>update</string>
        <string>-isDev</string>
        <string>0</string>
        <string>-installVersion</string>
        <string>15886</string>
        <string>-firstAppId</string>
        <string>19340001</string>
        </array>
        <key>StartInterval</key>
        <integer>86400</integer>
       </dict>
       </plist>
    Contents of Library/LaunchAgents/com.microsoft.LaunchAgent.SyncServicesAgent.plist (checksum 3051698494)
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
       <plist version="1.0">
       <dict>
        <key>KeepAlive</key>
        <false/>
        <key>Label</key>
        <string>com.microsoft.SyncServicesAgent</string>
        <key>OnDemand</key>
        <false/>
        <key>ProgramArguments</key>
        <array>
        <string>/Applications/Microsoft Office 2011/Office/SyncServicesAgent.app/Contents/MacOS/SyncServicesAgent</string>
        </array>
       </dict>
       </plist>
    Contents of Library/LaunchAgents/com.zimbra.desktop.plist (checksum 3676173668)
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC "-//Apple Computer//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
       <plist version="1.0">
       <dict>
               <key>Label</key>
               <string>com.zimbra.desktop</string>
               <key>ProgramArguments</key>
               <array>
                       <string>/Users/USER/Library/Zimbra Desktop/bin/zdesktop</string>
                       <string>start</string>
                       <string>-w</string>
               </array>
       

  • I opened an email that I later identified on hoaxbusters as depositing malware.  I have malwarebytes on my laptop, but nothing similar on my iphone4  what app should I buy?  If I run it, will it find or fix the possible malware?

    I opened an email on my phone that I later identified on hoaxbusters as depositing malware.  I have malwarebytes on my laptop, but nothing similar on my iphone4.  What app should I buy?  If I run it, will it find or fix the possible malware?

    The creeps that generate this code figured that the iPhone since is is selling so well would be a great market for them even if iOS makes it impossible for their code to do anything practical unless it is jail broken first.
    For additional information on jailbreaking, read http://en.wikipedia.org/wiki/IOS_jailbreaking

  • File Sharing Enabling Itself/ Possible Malware Infection?

    Greetings to all,
    I'm posting this out of sheer desperation because no one else seems to have reported such an issue (or so Google would have me believe).
    A bit of background info:
    I'm running 10.8.5 and Firefox 24.0, no frills, no extra customisations apart from one add-on; pretty much everything left to the default settings (homepage, theme, etc.).
    I noticed two weeks ago that my first tab in Firefox kept shivering every time a new tab was opened or an existing one was closed.  The only thing that had been installed was AdBlock Plus and that was running flawlessly for a month.
    I researched the problem on my own and found that previous versions of Firefox had similar shaking issues but none were related to AdBlock.
    I reset my browser and the shaking stopped.  I re-installed AdBlock and the issue returned in ten minutes.  I reported this to AdBlock Plus but have yet to hear back from them.
    Now moving onto the crux of the issue:
    I noticed in the last week that File Sharing has been turning itself on.  I have another Mac on the network but I have only used this feature a handful of times and always make sure to disable it as soon as I'm done.  This is combination with e-mails that I did not send that appear to be sent from my account despite having changed my password several times in the last year.  None of my contacts have reported that they received spam from me.
    I had been mildly suspicious of some such malware due to Netflix/ Hulu magically playing videos on their own well after they had already timed out.
    I checked Activity Monitor and there were no suspicious processes but I figured if a keylogger, for instance, were sophisticated enough, I still might not be able to see it.
    Enter MacScan 2.9.4.  I downloaded it directly from their website and ran a full-system scan which ultimately yielded nothing.
    I re-open Firefox and what do I see?  Yahoo! has been made my new homepage and a bunch of Spigot searchbars have been added, namely that for Amazon and eBay.
    When I Googled the company name, almost all the of articles referred to it as malware.
    I have since reset my browser and I'm starting to freak out more than just a little.
    A well-known and recommended AV hijacks my browser, spam is being sent to me by 'me', File Sharing is enabling itself, and of course, the phantom video playing.
    Has anyone seen this conglomeration of symptoms before and if so, what can I do about it?
    If not, am I going to have to wipe both Macs?
    Please some kind soul out there, help!

    I'm not following your description well enough to know exactly what happened. What site were you viewing when this happened, and did it happen immediately on clicking a link or did it just happen spontaneously? What is a "corrupted install window"? And what is "the corrupt file" you found in your download folder? Without more information, it's difficult to say, but it doesn't sound like malware to me. Of course, if you wish to set your mind at ease, get a copy of [ClamXav|http://www.clamxav.com> and scan your hard drive. Also, I would point you to my [Mac Virus guide|http://www.reedcorner.net/thomas/guides/macvirus>, but as I've received private communications from you already, I see you've found it!
    Note that files ending in .part are temp files... they are the beginnings of files that your browser started downloading. When you cancel a download, whatever had been downloaded to that point is left in a .part file, I believe to allow for resumption of the download later (if the server in question supports that). Whatever's in there is not complete and could not possibly be opened, so it is not a threat.

  • Possible Malware infection?

    I was surfing a website with firefox, and my download window popped open with the list cleared. I never clear my list. Then a corrupted install window opened asking me to install a dmg that was like a clean file i had downloaded earlier. i didn't install and i shut down the computer. On reopening i found in my download folder the corrupt file and a file with random letters ending in a ".part" file name.
    Any clarification would be helpful?
    Thanks

    I'm not following your description well enough to know exactly what happened. What site were you viewing when this happened, and did it happen immediately on clicking a link or did it just happen spontaneously? What is a "corrupted install window"? And what is "the corrupt file" you found in your download folder? Without more information, it's difficult to say, but it doesn't sound like malware to me. Of course, if you wish to set your mind at ease, get a copy of [ClamXav|http://www.clamxav.com> and scan your hard drive. Also, I would point you to my [Mac Virus guide|http://www.reedcorner.net/thomas/guides/macvirus>, but as I've received private communications from you already, I see you've found it!
    Note that files ending in .part are temp files... they are the beginnings of files that your browser started downloading. When you cancel a download, whatever had been downloaded to that point is left in a .part file, I believe to allow for resumption of the download later (if the server in question supports that). Whatever's in there is not complete and could not possibly be opened, so it is not a threat.

  • Suspicious metadata suggests possible malware...

    I have this really weird problem that just came up, and I don't know what to think except "malware?".
    I run an old program called Business Sense using Classic. I have several copies of the application on my machine, and I recently noticed some strange behavior: if I open a Business Sense file (not the application directly), it opens the program (no problems). But if I try to open the application itself, the computer instead tries to open it as a file in Script Editor. Get Info reveals that the kind is listed as "application" instead of "Application (Classic)". The "Open With" panel shows up, and the Memory panel does not. Two copies of the program have this problem, and the other 5 or so do not. Other Classic apps do not have this problem as far as I can see. Sometimes the Business Sense icon changes to a weird "color glitch" square (sort of like TV noise but with color). If I use SetFileInfo (from the developer tools) to turn off the custom icon flag, the weird icon goes away.
    Here's the really weird part. I used an Automator workflow that I cobbled together from macosxhints.com to view all of the metadata for the file (it uses the mdls command in the command line). The funky copies of Business Sense show this metadata:
    */Documents/BS Data/B $‚Ñ¢ 2.3 -------------*
    *kMDItemAttributeChangeDate = 2007-11-25 19:33:02 -0800*
    *kMDItemContentCreationDate = 1993-12-22 09:00:00 -0800*
    *kMDItemContentModificationDate = 2007-11-25 19:33:01 -0800*
    *kMDItemContentType = "com.prospa.manpage"*
    *kMDItemContentTypeTree = ("com.prospa.manpage", "public.data", "public.item")*
    *kMDItemDisplayName = "B $‚Ñ¢ 2.3"*
    *kMDItemFSContentChangeDate = 2007-11-25 19:33:01 -0800*
    *kMDItemFSCreationDate = 1993-12-22 09:00:00 -0800*
    *kMDItemFSCreatorCode = 1112755795*
    *kMDItemFSFinderFlags = 9472*
    *kMDItemFSInvisible = 0*
    *kMDItemFSIsExtensionHidden = 0*
    *kMDItemFSLabel = 0*
    *kMDItemFSName = "B $‚Ñ¢ 2.3"*
    *kMDItemFSNodeCount = 0*
    *kMDItemFSOwnerGroupID = 80*
    *kMDItemFSOwnerUserID = 501*
    *kMDItemFSSize = 411634*
    *kMDItemFSTypeCode = 1095782476*
    *kMDItemID = 208135*
    *kMDItemKind = "application"*
    *kMDItemLastUsedDate = 2004-12-11 16:34:45 -0800*
    *kMDItemUsedDates = (2004-12-11 16:34:45 -0800)*
    Don't mind the funky file name (it's named "B $™ 2.3" in the Finder). The weird part is what are in the ContentType and ContentTypeTree fields. For comparison, here's the metadata from one of the normal Business Sense applications:
    */Documents/BS Data/Empty DDS/B $‚Ñ¢ 2.3 -------------*
    *kMDItemAttributeChangeDate = 2007-06-25 20:10:46 -0700*
    *kMDItemContentCreationDate = 1993-12-22 09:00:00 -0800*
    *kMDItemContentModificationDate = 2002-07-13 16:52:09 -0700*
    *kMDItemContentType = "com.apple.application-file"*
    *kMDItemContentTypeTree = (*
    "com.apple.application-file",
    "com.apple.application",
    "public.executable",
    "public.data",
    "public.item"
    *kMDItemDisplayName = "B $‚Ñ¢ 2.3"*
    *kMDItemFSContentChangeDate = 2002-07-13 16:52:09 -0700*
    *kMDItemFSCreationDate = 1993-12-22 09:00:00 -0800*
    *kMDItemFSCreatorCode = 1112755795*
    *kMDItemFSFinderFlags = 8448*
    *kMDItemFSInvisible = 0*
    *kMDItemFSIsExtensionHidden = 0*
    *kMDItemFSLabel = 0*
    *kMDItemFSName = "B $‚Ñ¢ 2.3"*
    *kMDItemFSNodeCount = 0*
    *kMDItemFSOwnerGroupID = 80*
    *kMDItemFSOwnerUserID = 501*
    *kMDItemFSSize = 408262*
    *kMDItemFSTypeCode = 1095782476*
    *kMDItemID = 208691*
    *kMDItemKind = "Classic Application"*
    *kMDItemLastUsedDate = 2002-07-13 16:52:09 -0700*
    *kMDItemUsedDates = (2002-07-13 16:52:09 -0700)*
    Whereas the normal one has metadata values one would expect ("com.apple.application-file", "com.apple.application", "public.executable", etc.), the funky one has a value that doesn't make any sense: "com.prospa.manpage"
    Where the heck did that come from? I tried going to that website (prospa.com) and it's just a placeholder for a domain squatter. Interestingly, manpage.prospa.com does exist, and redirects to prospa.com. On that website, a contact address is listed: [email protected], but the words "contact us" to the right of that send the user to http://paty-poker.net/ which looks almost exactly the same as the first site.
    A whois inquiry of prospa.com is shown below. It reveals that the owner is in South Korea, and lists a different contact email address ([email protected])
    *Tue Dec 04 08:00 PM*
    *cybertoothdog $ whois prospa.com*
    *Whois Server Version 2.0*
    *Domain names in the .com and .net domains can now be registered*
    *with many different competing registrars. Go to http://www.internic.net*
    *for detailed information.*
    *Domain Name: PROSPA.COM*
    *Registrar: CYDENTITY, INC. D/B/A CYPACK.COM*
    *Whois Server: whois.cypack.com*
    *Referral URL: http://www.cypack.com*
    *Name Server: NS1.HOSTNAME.NET*
    *Name Server: NS2.HOSTNAME.NET*
    *Status: clientDeleteProhibited*
    *Status: clientTransferProhibited*
    *Status: clientUpdateProhibited*
    *Updated Date: 12-jul-2007*
    *Creation Date: 14-jun-2001*
    *Expiration Date: 14-jun-2008*
    *>>> Last update of whois database: Wed, 05 Dec 2007 04:00:42 UTC <<<*
    *The Registry database contains ONLY .COM, .NET, .EDU domains and*
    Registrars.
    *Welcome to CyDentity, Inc. dba CyPack.com's WHOIS Service*
    *Domain Name: PROSPA.COM*
    *Domain Status: LOCK*
    *Registrar: CyDentity, Inc. dba CyPack.com*
    *Referral URL: <a class="jive-link-external-small" href="http://">http://www.CyPack.com*
    *Domain Registration Date....: 2001-06-14 GMT.*
    *Domain Expiration Date......: 2008-06-14 GMT.*
    Registrant:
    kimtaeho
    *17-211, Maewol-dong, Seo-gu*
    *Gwangju, Gwangju 502153*
    KR
    *Administrative, Technical, Billing Contact:*
    *kimtaeho [email protected]*
    *17-211, Maewol-dong, Seo-gu*
    *Gwangju, Gwangju 502153*
    KR
    *(PHONE) +82-11-226-2899 (FAX) +82-62-603-0969*
    *Domain Name Servers in listed order:*
    NS1.HOSTNAME.NET
    NS2.HOSTNAME.NET
    I don't know Korean. I don't go to Korean websites. Where in the heck did my computer get the information to put "com.prospa.manpage" into the metadata of a random Classic application on my computer? I can't think of any reason that makes any sense other than malware. I looked up "com.prospa.manpage" and "prospa.com" on Google, Yahoo, and Altavista; nothing comes up for the first one, and nothing that seems relevant comes up for the second one. I also tried searching for "prospa.com", "com.prospa" and "prospa" in Spotlight - not a single result listed. Not even the funky Business Sense application.
    Does anyone have any idea what this could be? I hate bringing up the idea of "malware", but that's the only thing that makes any sense to me. What else would it be?
    So far, the only thing I could think of to do was to email the [email protected] address using a junk email account saying that I was "interested" in the prospa.com website. I just did that this evening, so I don't expect to hear anything back for a while - although I don't know what good it's going to do. Does anyone know how to report this to Apple directly?
    Any help or suggestions greatly appreciated!

    I figured it out. I feel sort of silly.
    At one point, my son's PowerBook hard drive was connected to the computer. He had a spotlight importer called manimporter.mdimporter installed. Somehow, the file associations for that mdimporter got added to my lsregister database, so any file that ended in .[number] (such as B $™ 2.3) was seen as a man file. I re-indexed the lsregister database using the command found at the bottom of this macosxhints.com hint:
    http://www.macosxhints.com/article.php?story=20071014124330643
    and that fixed the problem (perhaps this information will help someone with a similar problem in the future, like it did for me). I had to modify the search slightly, as just updating the database didn't get rid of the entry for manimporter.mdimporter. Using the following two variants seems to have returned everything to normal:
    ./lsregister -kill -f -domain local -domain system -domain user -domain network -dump
    +This one kills the current database and forces a new update of all possible domains. I also added a+ *> ~/file.txt* +to the end so that the dump command would load all the data into a text file that I could look at later.+
    ./lsregister -f -R /system/library/
    +This one picks up things like .dmg and .zip. I don't know why those weren't indexed in the first command. This one gives a lot of errors as it encounters things like jpeg files, but it seems to be ok.+
    I don't recall whether I had to run these commands as root or not. Anyway, I hope this helps somebody.

  • Possible Malware or Virus on IMac?

    Today one of my family members visited the site Neopets, as she does almost everyday. What is strange is that every link she clicks on the site, be it for playing a game, checking contact information at the bottom of the site, starting a game etc,would cause a pop up to appear saying that we do not have the updated player. By pressing ok, it redirects us to a site called updateplayer.us. It is almost identical to the adobe/flash site which makes me believe that its some type of phishing scam. Furthermore, it will again redirect us to other sites, all similar but with different names (i.e. bamplay.net, and fatplay.net). These sites were identical to one another (bamplay and fatplay). So my question is, do we have a virus or malware on or mac? We have the lion OS. Everything is up to date, (flash player is 13.0.0.214) and our system updates are all up to date. We only download updates through system preferences/ software update. Other than pictures that we have recieved from friends and family, and the occasional pdf we download for school/taxes, the only downloading/installing we have done is from the system/flash updates. We don't visit any malicious websites and are fairly cautious internet users. This just started happening today for the first time ever, and it only appears to be happening on Neopets. Do we have a virus or malicious software installed? Everything else seems to be running fine. Safari still seems to be fast. Or is this something on Neopets end? I'm not very skilled with computers so any help would be appreciated!
    Thanks!
    P.S.
    Has anyone else who visits the site been experiencing this?

    If Neopets requires Adobe Flash Player, always navigate on your own to Adobe's website and download the installer from them, and never from within someone else's website including this one. Fortunately, thousands of Apple Support Communities participants are here to rapidly respond to anyone's malicious intent.
    Adobe's website is as follows, which you will be able to see for yourself exactly as it appears, in your browser's URL field:
    https://get.adobe.com/flashplayer/
    Ignore unexpected popups or solicitations to update Flash Player; they can direct you to fraudulent sites that will attempt to convince you to install malicious software, or to reveal personal information such as your Apple ID credentials.
    Or is this something on Neopets end?
    That is another possibility, as are other potential causes, but the malicious router hacking I described is a serious concern and must be ruled out at your earliest opportunity.

  • Chkrootkit - Possible LKM Trojan infection

    Sorry to be a bother but I have a quick question. I installed Blackbuntu in Virtualbox to play with and happened to notice an unusual connection to a remote server from the VM. After shutting it down I had a usual bout of paranoia, so I ran chkrootkit... it came back with a result saying I had several hidden processes and a potential LKM Trojan along with the usual
    The tty of the following user process(es) were not found
    in /var/run/utmp !
    ! RUID PID TTY CMD
    ! jon 9854 tty3 /usr/bin/X -nolisten tcp :0 -auth /tmp/serverauth.ymiB45cvJk
    result. I restarted X and have run the program repeatedly. I have not recived that warning again. An NMap gives the usual results and rkhunter comes back fine aside from the common Arch false-postives.
    Based on some Googling it seems likely that the warning was caused by a short-lived process running then and there as it where. Has anyone experienced this? Should I be worried or is it just a false alarm?
    (Note: I do not run SSH, Apache or anything of that ilk.)
    Thanks,
    Jon
    Edit:
    Another site recommended running chkrootkit ps lkm which gave me an infected result then a clean one immediately after.
    jon@Set ~]$ sudo chkrootkit ps lkm
    ROOTDIR is `/'
    Checking `ps'... not infected
    Checking `lkm'... You have 4 process hidden for readdir command
    You have 4 process hidden for ps command
    chkproc: Warning: Possible LKM Trojan installed
    chkdirs: nothing detected
    [jon@Set ~]$ sudo chkrootkit ps lkm
    ROOTDIR is `/'
    Checking `ps'... not infected
    Checking `lkm'... chkproc: nothing detected
    chkdirs: nothing detected
    Last edited by jon.wulf (2011-03-16 01:10:48)

    This is because you're running BlackBuntu I would assume that's the problem considering BlackBuntu has trojans and such on it.

  • Possible malware on my macbook.

    Hi guys,
    Firstly let me start off by apologising as i know this topic has been somewhat covered in the past, but i thought their might be new information available that could help me out.
    I play world of warcraft on my macbook, just last night i tried to log in only to find my account had been hacked and my password changed, I used secret question etc to reset and choose anew password a few hours later the password had changed again. On contacting blizzard they said it was most likely that i had a keylogger on my system either as a downloaded addon for the game or from visiting some wow related site. So my question that i really hope you may be able to answer is;
    1. Assuming there is a keylogger on my system (i think thats the safest stance to take) how do i remove it ? I have ran clamxav, ianti virus and macscan all clean except for some Tracking cookies that look innocent enough.
    I can do a system restore as a lst resort but im hoping to avoid it if possible.
    thanks for your time and help
    Conor

    Yes, an erase and fresh install is the safest way to go.
    While there are no known viruses that attack Mac OS X at the present time it is possible for other malware to get onto your Mac, like your keylogger.
    So I go to lengths to protect my user. A hosed system can be replaced but a compromised user folder is compromised forever. Along with all your important data like bank records, credit cards, ... I.e. your "identity" stolen.
    The best way to avoid that is by being a frustrating target. Use your built-in firewall which is industrial strength and/or a hard wired router, downloading only from "trusted" sites, installing all security updates and being careful about what you give administrative power to.
    Don't use Limewire or any other P2P service to download your software, get it from reputable sources. In addition, always keep at least your users backed up, preferably a clone of your entire system on a separate disk. And put your sensitive passwords, bank accounts, credit card numbers in a "secure note" in a new keychain or in an encrypted folder.
    If and when a Mac virus does appear it will be headline news and you can download the AV software then. If you feel you have to run an AV program I'd suggest ClamXav a mac friendly freeware app that is very stable with OS X. It will check for known virus signatures at any rate.
    Hope this helps.
    -mj

  • Possible Malware effecting Dreamweaver

    I have been using Dreamweaver for a number of years and in the past few months have been encountering a problem that appears to be malware related.
    When I am using the software, spurious changes are being made in both the html and css files which I have not touched.
    These sorts of changes include:
    Text characters piled up on top of each other
    Randon price changes from $9.95 to $9.96 or $100 to $101 or $100.01
    Headings are srunched up
    Ad hoc adjustments to layout alignments such as one column partially overlapping another or complete resizing of the width
    Inseting a stack of extra quotes around values (with the old style sloping quote marks) so they wont work
    Random removal of classes
    Removal of spacing
    List goes on and on.
    Many of these problems will correct themselves perhaps some hours or days later, but when one thing has gone back to normal it implements something else instead, making use of the software almost impossible.
    I have run full Norton's scans including their additional heavy duty programs, and also followed advice to run Malwarebytes and Super-AntiSpyware, but none of these have found any problem.
    When I was running the Malwarebyes, my computer became unstable - I was unable to start up and had to restore back to a point 6 weeks prior.
    I am loosing faith that anyone has ever heard of this problem let alone know how to rectify it,
    Any help would be greatly appreciated.
    Cheers,
    Alison.

    Sounds like a hardware problem. You may not be infected with anything. If you haven't already, backup all your data to reliable external drives & take your PC in for service.  Oftentimes a faulty fan, chip or failing hard drive can corrupt data files. 
    Good luck,
    Nancy O.

  • Isis Mobile wallet possible malware

    I upgraded my sim to the nfc secure and installed Isis mobile wallet
    Vipre is the best antivirus around found ... I have informed Verizon and Vipre ... Vipre techs are researching to see if it has malware or just a false positive i will post as soon as they let me know .... this posted just to make you aware of a possible security issue
    Antivirus Scan 1 threat was detected:  Trojan.AndroidOS.Generic.A
    Type: Malware
    Level: High
    about 23 hours ago  
    App Uninstalled   Application com.isis.mclient.verizon.activity was uninstalled from your device  about 23 hours ago  

    It is a false positive so no malware at all

  • Flashlight app possible malware?

    According to the attached video the top ten flashlight apps are malware.  Does anyone know if the iphone flashlight is secure?
    http://www.youtube.com/watch?feature=player_embedded&v=Q8xz8xKEFvU

    wragwriter wrote:
    The one that comes with iPhone seems OK. The ones we download are the problem. One expert says if the app takes up more than a megabyte it's probably malware. This makes sense since turning on a flashlight is such a simple operation - not worthy of megs of memory. You can check the amount of memory used by going to Settings - General - Usage - Manage Storage.The expert says if you have a large (> 1Meg) flashlight go to your provider or an apple store to get reset to factory setting. Deleting the app is  not enough.
    The "expert" specifically says "apps you download from the Google play store". You cannot download iPhone apps from the Google Play Store. Unlike Android phones, apps on your iPhone cannot access any of your data without asking your permission, so if a flashlight app asks to see your contacts, location, or any other information then I would delete the app and report it to Apple.
    It's well known that Android phones are highly susceptible to malware. One of the security companies a few months ago identified 297 apps that were malware. All but 3 were for Android devices. The 3 that could infect an iPhone all had been removed from the App store and deleted from phones within days of their release.

  • My Macbook Pro is running slow, possible malware

    Hi there,
    I know this is an annoying redundant question but I am an idiot and I did it.  A couple months ago, I made the mistake of downloading Trojan.  I tried deleting the application but the pop ads (Mackeeper) continued.  I looked further into the problem, I deleted all the extensions on safari and chrome, that didn't work. Also,  I checked my memory  421. GB free of 498 GB yet I still find my Macbook running slow when opening different applications.   I am scared that I may have malware.  What should I do?

    There is no need to download anything to solve this problem. You may have installed a variant of the "VSearch" ad-injection malware.
    Malware is always changing to get around the defenses against it. These instructions are valid as of today, as far as I know. They won't necessarily be valid in the future. Anyone finding this comment a few days or more after it was posted should look for a more recent discussion, or start a new one.
    The VSearch malware tries to hide itself by varying the names of the files it installs. To remove it, you must first identify the naming pattern.
    Triple-click the line below on this page to select it, then copy the text to the Clipboard by pressing the key combination  command-C:
    /Library/LaunchDaemons
    In the Finder, select
              Go ▹ Go to Folder...
    from the menu bar and paste into the box that opens by pressing command-V. You won't see what you pasted because a line break is included. Press return.
    A folder named "LaunchDaemons" may open. Look inside it for two files with names of the form
              com.something.daemon.plist
    and
               com.something.helper.plist
    Here something is a variable word, which can be different in each case. So far it has always been a string of letters without punctuation, such as "cloud," "dot," "highway," "submarine," or "trusteddownloads." Sometimes the word is "apple," and then you must be especially careful not to delete the wrong files, because many built-in OS X files have similar names.
    If you find these files, leave the LaunchDaemons folder open, and open the following folder in the same way:
    /Library/LaunchAgents
    In this folder, there may be a file named
              com.something.agent.plist
    where the word something is the same as before.
    If you feel confident that you've identified the above files, back up all data, then drag just those three files—nothing else—to the Trash. You may be prompted for your administrator login password. Close the Finder windows and restart the computer.
    Don't delete the "LaunchAgents" or "LaunchDaemons" folder or anything else inside either one.
    The malware is now permanently inactivated, as long as you never reinstall it. You can stop here if you like, or you can remove two remaining components for the sake of completeness.
    Open this folder:
    /Library/Application Support
    If it has a subfolder named just
               something
    where something is the same word you saw before, drag that subfolder to the Trash and close the window.
    Don't delete the "Application Support" folder or anything else inside it.
    Finally, in this folder:
    /System/Library/Frameworks
    there may an item named exactly
                v.framework
    It's actually a folder, though it has a different icon than usual. This item always has the above name. Drag it to the Trash and close the window.
    Don't delete the "Frameworks" folder or anything else inside it.
    If you didn't find the files or you're not sure about the identification, post what you found.
    If in doubt, or if you have no backups, change nothing at all.
    The trouble may have started when you downloaded and ran an application called "MPlayerX." That's the name of a legitimate free movie player, but the name is also used fraudulently to distribute VSearch. If there is an item with that name in the Applications folder, delete it, and if you wish, replace it with the genuine article from mplayerx.org.
    This trojan is often found on illegal websites that traffic in pirated content such as movies. If you, or anyone else who uses the computer, visit such sites and follow prompts to install software, you can expect more of the same, and worse, to follow. Never install any software that you downloaded from a bittorrent, or that was downloaded by someone else from an unknown source.
    In the Security & Privacy pane of System Preferences, select the General tab. The radio button marked Anywhere  should not be selected. If it is, click the lock icon to unlock the settings, then select one of the other buttons. After that, don't ignore a warning that you are about to run or install an application from an unknown developer.
    Then, still in System Preferences, open the App Store or Software Update pane and check the box marked
              Install system data files and security updates (OS X 10.10 or later)
    or
              Download updates automatically (OS X 10.9 or earlier)
    if it's not already checked.

  • Possible Malware in the latest 11.1.102.63

    hi guys found a possible bug on flash
    thats the screen shot
    can conform this has happened after i installed the latest version of flash
    also happens on google chrome
    http://www.avgthreatlabs.com/webthreats/info/Blackhole%20Exploit%20Kit%20Detection%20%28ty pe%201889%29/
    also happens on chrome and safari and IE

    Hello
    wrong forum used.
    Flash Player 11.1 = http://forums.adobe.com/community/flashplayer
    Report it to AVG and the webmaster of the website you have opened.
    It could be a false alarm.
    You can compare it with some online/offline virus scanners.

  • ALERT! Possible malware email spam

    I received an e-mail from the iTunes store this morning stating that I received an iTunes gift card.
    It included a zip file that opens to an .exe file. I suspect this is malware. No one I know purchased a gift card from iTunes. I have not been able to contact Apple yet. Beware.
    Email;
    From: iTunes Products <[email protected]>
    Subject: Thank you for buying iTunes Gift Certificate!
    Date: May 26, 2010 9:19:26 AM EDT
    To: Edward Glasheen
    Hello!
    You have received an iTunes Gift Certificate in the amount of $50.00
    You can find your certificate code in attachment below.
    Then you need to open iTunes. Once you verify your account, $50.00 will be credited to your account, so you can start buying music, games, video right away.
    iTunes Store.
    Gift Certificate. zip ( 28.8 KB )

    I received the same e-mail this morning and deleted it right away because file contained a zip file and was sent to a fake e-mail address that is close to my e-mail address but not the right one and definitely not the e-mail address I have registered with iTunes.
    I came in this site in hopes that a would find an e-mail address where I could forward the phishing e-mail but all I could find was this discussion board.

Maybe you are looking for

  • Error in receiver JDBC channel

    Hi, I have a receiver JDBC scenario, which must execute a stored procedure. Output message seems correct: <ns0:MT_SQL xmlns:ns0="http://www.xxxx"> <STATEMENT1>    <DIRECC ACTION="EXECUTE">        <TABLE>biz_mag_clientes_direcciones</TABLE>        <id

  • Rented Video on ATV not showing up in iTunes

    I have rented videos on my ATV with no problem and transferred them to iTunes. Now, today, a rented video on my ATV is not showing up in iTunes. Is there a setting that could have been changed? Any ideas? Jonathan

  • Two dimension string array in teststand

    Hello, I want to pass a two dimension string array from a labWindows dll into Teststand. My labwindows dll: #define NR_columns 12 #define NR_rows  1200 #define NR_hight   1024 int__declspec(dllexport) __stdcall  sort( char pspec[NR_columns][NR_rows][

  • I can't watch You Tube videos via WiFi but I can in 3G.

    This is on all iDevices - not just iPad.  It's a new router that supports Smart Wi-Fi apps. Why?  Is this a setting?  And it only seems to be You Tube.  It says Playback Error or Video Not Available. Thoughts?

  • Only half the screen updated in Camera Raw.

    My system stopped updating half of the screen for camera raw. If i make a change in Camera raw, it only updates half the picture. I have to drag the window onto my second screen and back to see the entire image updated. This did not occur from the be