Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

A mac virus?

Hello,

For some reason my Firefox all of the sudden runs slow and just shows "white" when I try to access some sites (istock for example). Every now and then a full screen window will pop up (e.g., http://www.epoclick.com/?ad=1287502829). Did some virus infect my firefox?
I ran ClamXav and it didn't find anything.
I uninstalled firefox and the reinstalled it. That epoclick stuff still popsup.

What's this epoclick junk...and how do I get rid of it? (I'm running Snow Leopard on my iMac).

I appreciate your professional help!

John

iMac 27", Mac OS X (10.6.4)

Posted on Oct 19, 2010 8:54 AM

Reply
75 replies

Oct 19, 2010 9:26 AM in response to jester4jc

It's unlikely that it's a virus; there have been no confirmed reports of any viruses or worms that can infect Mac OS X.

Have you tried clearing out the caches and cookies in Firefox? Those would be preserved even through a reinstallation, so clearing them might help. It also could be popups attached to those web sites; epoclick seems to be an ad network, so it might not be something with your system at all. If you don't have the popup blocker turned on in Firefox, give that a try as well.

Hope this helps.

Oct 19, 2010 9:46 AM in response to varjak paw

Hmmmmm...no I hadn't cleaned out the caches and history. I had it set not to save those though. I'll clear them.

I think the popup blocker was on...but it only inhibits the window from displaying the content (thus a white popup window).

Phew! Its a relief to know that its probably not a virus. Could it be spyware or something?

Thanks Dave!!

Oct 19, 2010 11:14 AM in response to varjak paw

The problem is independent of browser and OS
I have the same problem on Windows XP regardless of IE, FF or Safari.

Must be some kind of malware. Virusscan tool find nothing. Reinstalling FF did not help.
Must be a fairly new kind of attack, as whois for epoclick.com says domain was registered 2010-10-11.

If anybody succeeds in removing this nuisance, I would highly appreciate info on how you did it

Oct 19, 2010 11:48 AM in response to Jonas Wood

If you have the same problem in Windows, then while I can't say it's not possible, it's highly unlikely to be malware on your system and is most likely a problem with the web sites themselves unless something has hijacked your router. My guess is that someone is attaching these to various web sites that are insufficiently protected, perhaps using invisible web "bugs".

Oct 19, 2010 2:04 PM in response to Jonas Wood

There may be a new attack against Windows systems, but such an attack would not affect Mac OS X. That would require a separate attack, and I've seen nothing to indicate that any such attack has been given any sort of solid evidence, much less confirmed. There has been one trojan horse attack, DNSChanger, that caused redirection of Mac web browsers to other sites, but it required social engineering to get the user to him/herself download and install the malware. It's possible that there has been a new trojan, but I would want to see some sort of confirmation from the original poster that he/she recently downloaded and installed something from a web site before I would make such a judgement. Otherwise, unless s/he was actually running Windows on his/her Mac and it was under that OS that the problem occurred, the probability that the problem stems from a virus or worm attacking Mac OS X is very small, though by no means zero.

Message was edited by: Dave Sawyer

Oct 19, 2010 5:22 PM in response to Jonas Wood

Jonas, I'm assuming you're seeing the same thing as John, but on both a Mac and a Windows system. Is that correct? If so, obviously it can't be malware, as Windows malware cannot affect the Mac OS and vice versa. You could have some kind of DNS poisoning, as Dave has indicated. There could be a problem with your ISP's DNS servers, or something might have messed with the DNS server settings on your wireless router. It's very unlikely that you've gotten DNS-changing malware simultaneously on both your Mac and Windows machines, especially since the Mac trojan that people call "DNS Changer" (aka, RSPlug) is screened against by Snow Leopard. (Details on these malware issues can be found on my [Mac Virus guide|http://www.reedcorner.net/thomas/guides/macvirus>.)

Of course, these things are all more elaborate explanations than necessary. Pop-up blockers are not perfect... I get "pop-unders" now and then in Safari, despite having the blocker turned on. Most likely, the sites you guys are visiting simply have ads that were written to bypass the common pop-up blockers. We'd be able to say one way or the other for sure if someone would post an exact location to visit to get one of these pop-ups, which nobody has yet done.

Oct 19, 2010 9:43 PM in response to jester4jc

I have the same issue. I get popups despite popup blockers on a windows 7 machine, windows XP machine and a brand new Imac. I usually get the same pop up, although nothing ever loads. it is www.epoclick.com/?ad=1287549163

It definitely has something to do with www.goggle-analytics.com because I cannot visit any site that uses Goggle Analytics. It hangs while loading data from the site. Which is alot of sites. So basically, I can't visit half the web until I figure this out.

I am running a Netgear wireless router with the above 3 machines connected, 2 are wireless.

Andrew

Oct 19, 2010 11:34 PM in response to droidtn

Wow...I just returned and am surprised at your responses.

I have not downloaded any other program other than Google Chrome about 2 weeks ago and ClamXav recently (due to this issue). I do not frequent strange sites (mainly design blogs, PSD tutorials and graphic arts related sites, e.g., smashingmagazine, istockphoto, gettyimages.com, graphic-exchange.com...etc).

The problem only happens in Firefox.

THIS IS SCARY...Firefox was open with other apps and suddenly the semi-transparent screen flowed down (from top to bottom) saying something to the effect of, "you need to shut down your computer because it encountered a problem. I couldn't do anything but hold the power button until it shut down.


I cannot make sense of the report but here it is...DO YOU SEE anything?




*You shut down the computer because of a problem.*

Interval Since Last Panic Report: 2682799 sec
Panics Since Last Report: 1
Anonymous UUID: A14CAA8E-BD80-4449-AD36-DFC8121486AF

Tue Oct 19 23:19:01 2010
panic(cpu 2 caller 0x26fed3): "vm object_pagercreate(): object size 0x101f28000 >= 4GB\n"@/SourceCache/xnu/xnu-1504.7.4/osfmk/vm/vm_object.c:4100
Backtrace (CPU 2), Frame : Return Address (4 potential args on stack)
0x6046beb8 : 0x21b455 (0x5cf328 0x6046beec 0x2238b1 0x0)
0x6046bf08 : 0x26fed3 (0x589db4 0x1f28000 0x1 0x1)
0x6046bf68 : 0x275279 (0xcdc2564 0x0 0x0 0x1)
0x6046bfc8 : 0x29e6cc (0x849908 0x0 0x10 0x9f8bc20)

BSD process name corresponding to current thread: kernel_task

Mac OS version:
10F569

Kernel version:
Darwin Kernel Version 10.4.0: Fri Apr 23 18:28:53 PDT 2010; root:xnu-1504.7.4~1/RELEASE_I386
System model name: iMac11,1 (Mac-F2268DAE)

System uptime in nanoseconds: 86239710358252
unloaded kexts:
com.apple.driver.AppleFileSystemDriver 2.0 (addr 0xdde000, size 0x12288) - last unloaded 93446579685
loaded kexts:
com.InternetSafety.kext.internetcontrol 7
com.intego.iokit.VirusBarrierService 10.5.9
com.pctools.iantivirus.kfs 1.0.1
com.apple.filesystems.afpfs 9.7 - last loaded 4201679794416
com.apple.nke.asp_tcp 5.0
com.apple.driver.AppleBluetoothMultitouch 51.2
com.apple.filesystems.autofs 2.1.0
com.apple.driver.AGPM 100.12.12
com.apple.driver.AppleHWSensor 1.9.3d0
com.apple.driver.AppleMikeyHIDDriver 1.2.0
com.apple.driver.AppleUpstreamUserClient 3.3.2
com.apple.driver.AppleHDA 1.8.7f1
com.apple.kext.ATIFramebuffer 6.1.8
com.apple.driver.AppleMikeyDriver 1.8.7f1
com.apple.driver.AudioAUUC 1.4
com.apple.ATIRadeonX2000 6.1.8
com.apple.Dont Steal_Mac_OSX 7.0.0
com.apple.driver.AudioIPCDriver 1.1.2
com.apple.driver.AirPort.Atheros21 423.9.9
com.apple.driver.ACPI SMCPlatformPlugin 4.1.2b1
com.apple.driver.AppleLPC 1.4.12
com.apple.driver.AppleBacklight 170.0.24
com.apple.driver.AppleIRController 303.8
com.apple.driver.AppleUSBCardReader 2.5.4
com.apple.iokit.SCSITaskUserClient 2.6.5
com.apple.BootCache 31
com.apple.AppleFSCompression.AppleFSCompressionTypeZlib 1.0.0d1
com.apple.iokit.IOAHCIBlockStorage 1.6.2
com.apple.driver.AppleFWOHCI 4.7.1
com.apple.iokit.AppleBCM5701Ethernet 2.3.8b2
com.apple.driver.AppleEFINVRAM 1.3.0
com.apple.driver.AppleUSBHub 4.0.0
com.apple.driver.AppleUSBEHCI 4.0.2
com.apple.driver.AppleUSBUHCI 4.0.2
com.apple.driver.AppleAHCIPort 2.1.2
com.apple.driver.AppleACPIButtons 1.3.2
com.apple.driver.AppleRTC 1.3.1
com.apple.driver.AppleHPET 1.5
com.apple.driver.AppleSMBIOS 1.6
com.apple.driver.AppleACPIEC 1.3.2
com.apple.driver.AppleAPIC 1.4
com.apple.driver.AppleIntelCPUPowerManagementClient 105.10.0
com.apple.security.sandbox 0
com.apple.security.quarantine 0
com.apple.nke.applicationfirewall 2.1.11
com.apple.driver.AppleIntelCPUPowerManagement 105.10.0
com.apple.driver.IOBluetoothHIDDriver 2.3.3f8
com.apple.driver.AppleMultitouchDriver 204.13
com.apple.iokit.IOBluetoothSerialManager 2.3.3f8
com.apple.iokit.IOSerialFamily 10.0.3
com.apple.driver.AppleProfileReadCounterAction 17
com.apple.driver.DspFuncLib 1.8.7f1
com.apple.driver.AppleProfileTimestampAction 10
com.apple.driver.AppleProfileThreadInfoAction 14
com.apple.driver.AppleProfileRegisterStateAction 10
com.apple.driver.AppleProfileKEventAction 10
com.apple.driver.AppleProfileCallstackAction 20
com.apple.driver.AppleSMBusController 1.0.8d0
com.apple.kext.ATI4800Controller 6.1.8
com.apple.kext.ATISupport 6.1.8
com.apple.iokit.IOFireWireIP 2.0.3
com.apple.iokit.IOSurface 74.0
com.apple.iokit.IOAudioFamily 1.7.6fc2
com.apple.kext.OSvKernDSPLib 1.3
com.apple.driver.AppleHDAController 1.8.7f1
com.apple.iokit.IOHDAFamily 1.8.7f1
com.apple.iokit.IO80211Family 311.1
com.apple.iokit.AppleProfileFamily 41
com.apple.driver.AppleSMC 3.0.1d2
com.apple.driver.IOPlatformPluginFamily 4.1.2b1
com.apple.driver.AppleSMBusPCI 1.0.8d0
com.apple.iokit.IONDRVSupport 2.1
com.apple.iokit.IOGraphicsFamily 2.1
com.apple.driver.AppleUSBHIDKeyboard 1.2.0a3
com.apple.driver.AppleHIDKeyboard 1.2.0a3
com.apple.driver.BroadcomUSBBluetoothHCIController 2.3.3f8
com.apple.driver.AppleUSBBluetoothHCIController 2.3.3f8
com.apple.iokit.IOBluetoothFamily 2.3.3f8
com.apple.iokit.IOUSBHIDDriver 4.0.2
com.apple.iokit.IOSCSIBlockCommandsDevice 2.6.5
com.apple.iokit.IOUSBMassStorageClass 2.6.1
com.apple.iokit.IOSCSIMultimediaCommandsDevice 2.6.5
com.apple.iokit.IOBDStorageFamily 1.6
com.apple.iokit.IODVDStorageFamily 1.6
com.apple.iokit.IOCDStorageFamily 1.6
com.apple.driver.AppleUSBMergeNub 4.0.0
com.apple.driver.AppleUSBComposite 3.9.0
com.apple.driver.XsanFilter 402.1
com.apple.iokit.IOAHCISerialATAPI 1.2.4
com.apple.iokit.IOSCSIArchitectureModelFamily 2.6.5
com.apple.iokit.IOFireWireFamily 4.2.6
com.apple.iokit.IONetworkingFamily 1.9
com.apple.iokit.IOUSBUserClient 4.0.0
com.apple.iokit.IOUSBFamily 4.0.2
com.apple.iokit.IOAHCIFamily 2.0.4
com.apple.driver.AppleEFIRuntime 1.3.0
com.apple.iokit.IOHIDFamily 1.6.4
com.apple.iokit.IOSMBusFamily 1.1
com.apple.kext.AppleMatch 1.0.0d1
com.apple.security.TMSafetyNet 6
com.apple.driver.DiskImages 283
com.apple.iokit.IOStorageFamily 1.6.1
com.apple.driver.AppleACPIPlatform 1.3.2
com.apple.iokit.IOPCIFamily 2.6
com.apple.iokit.IOACPIFamily 1.3.0
Model: iMac11,1, BootROM IM111.0034.B02, 4 processors, Intel Core i7, 2.8 GHz, 4 GB, SMC 1.54f36
Graphics: ATI Radeon HD 4850, ATI Radeon HD 4850, PCIe, 512 MB
Memory Module: global_name
AirPort: spairport wireless_card_type_airportextreme (0x168C, 0x8F), Atheros 9280: 2.1.9.8.1
Bluetooth: Version 2.3.3f8, 2 service, 19 devices, 1 incoming serial ports
Network Service: AirPort, AirPort, en1
Serial ATA Device: ST31000528ASQ, 931.51 GB
Serial ATA Device: HL-DT-ST DVDRW GA11N
USB Device: Hub, 0x0424 (SMSC), 0x2514, 0xfd100000
USB Device: Photosmart C4200 series, 0x03f0 (Hewlett Packard), 0x5c11, 0xfd130000
USB Device: Built-in iSight, 0x05ac (Apple Inc.), 0x8502, 0xfd110000
USB Device: IR Receiver, 0x05ac (Apple Inc.), 0x8242, 0xfd120000
USB Device: Hub, 0x0424 (SMSC), 0x2514, 0xfa100000
USB Device: USB2.0 Hub, 0x05e3 (Genesys Logic, Inc.), 0x0608, 0xfa130000
USB Device: My Book, 0x1058 (Western Digital Technologies, Inc.), 0x1103, 0xfa134000
USB Device: Keyboard Hub, 0x05ac (Apple Inc.), 0x1006, 0xfa133000
USB Device: Apple Keyboard, 0x05ac (Apple Inc.), 0x0220, 0xfa133200
USB Device: Internal Memory Card Reader, 0x05ac (Apple Inc.), 0x8403, 0xfa120000
USB Device: BRCM2046 Hub, 0x0a5c (Broadcom Corp.), 0x4500, 0xfa110000
USB Device: Bluetooth USB Host Controller, 0x05ac (Apple Inc.), 0x8215, 0xfa111000

Oct 20, 2010 10:27 AM in response to droidtn

droidtn wrote:
I have the same issue. I get popups despite popup blockers on a windows 7 machine, windows XP machine and a brand new Imac. I usually get the same pop up, although nothing ever loads. it is www.epoclick.com/?ad=1287549163

It definitely has something to do with www.goggle-analytics.com because I cannot visit any site that uses Goggle Analytics. It hangs while loading data from the site. Which is alot of sites. So basically, I can't visit half the web until I figure this out.

I am running a Netgear wireless router with the above 3 machines connected, 2 are wireless.

Andrew



So any idea as to my problem. Its obivous many users have some issue with google analytics and some type of malware. As I posted above it affects all 3 computers on my network with 3 different OS's and different browsers. I have scanned my PC's with no less than 3 virus and malware softwares, nothing to be found.
Is there a way that a router can be infected? I didnt think routers had any memory and certainly no hard drive. If so, he can they be cleansed.

A mac virus?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.