ClamXAV shows Exploit.Iframe-1 infection?

To start with, I run 10.6.2, I browse with Opera 10.1, and I use ClamXAV on my computer set up to monitor certain folders.

Today I was browsing about the web, when ClamXAV popped up to tell me that it had quarantined files. My options were to 'Open Quarantine Folder' or 'Ignore Warning'. When I opened the quarantine folder, I saw four files inside:

opr0TRGU
opr0TRLF
opr0TRMB
opr0TRMH

Checking my ClamXAV log showed these files as being identified as 'Exploit.Iframe-1' threats. I immediately secure-deleted the files from the computer.

I was really hoping I wouldn't have to deal with viruses with my Mac 😟 Can someone tell me what I need to do to remove and fix this infection? I really don't want to have to reformat!

Thanks.

Mac OS X (10.6.2)

Posted on Feb 10, 2010 8:52 AM

Reply
2 replies

Feb 10, 2010 9:07 AM in response to Carbonyl

Exploit.iFrame is a trojan that can be attached to web pages or to an email; in your case, almost certainly a web site infected (accidentally or deliberately) with that malware. This is a Windows virus and cannot infect your Mac (the vast majority of the AV database in ClamAV is Windows-related malware). As long as you've deleted those quarantined files, you probably cannot inadvertently pass them on to some other computer.

Regards.

Feb 10, 2010 9:25 AM in response to varjak paw

Thank you for the helpful reply! I've been hearing more about attacks targeting OS X, so I was a little worried. Particularly since I wasn't downloading or installing any software (I haven't for months!)

I checked the clamXAV logs in the console, and found that the files originated in the /Library/Caches/Opera/cache/ directory, though. So I'm guessing that a cached webpage must have had something malicious encoded into it. I browse with javascript off, so this combined with what you say about the trojan leveraging Windows as a point of attack makes me feel this thing was neutered before it even hit my HD 🙂 I feel better now.

Thanks for the help!

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

ClamXAV shows Exploit.Iframe-1 infection?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.