Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Possible Virus?!

Hi there,


The other day I tried to download a subtitle file for a film I was watching, and the website I was on brought up some sort of sex ad which followed the page down as I scrolled down.


Shortly after, firefox (version 3.6.16) started opening multple windows automatically, all sex type pages!! I had to force quit.


This has never happened to me on a mac before so I am quite concerned that I may have been unfortunate enough to have caught a virus! I have no virus protection as I understand that it is very unlikely to be neccessary on a mac..


Upon restarting the machine, I found some new files in the trash. it has created a "recovered files" folder within which are two folders named "plugtmp" and "plugtmp-1". In each of these are two files, exactly the same in each folder. These are "plugin-crossdomain.xml" and "plugin-policy.html"


Does anyone have any advice what to do now? Are there any good, non-system-debilatating, free virus scanners which people recommend? Should I delete these files? And is there anything to look out for which may indicate some form of infection?


Many thanks,

MBP i7 15" hi res anti glare 500GB 7200

Posted on Apr 20, 2011 10:41 AM

Reply
8 replies

Apr 20, 2011 11:26 AM in response to Requiembeats

Shortly after, firefox (version 3.6.16) started opening multple windows automatically, all sex type pages!! I had to force quit.

That's typical of a Java popup storm. Each page that came up had a Java command in it to launch a new page and fill it with whatever URL it called for. So they go nuts calling one new page after another. It doesn't take a virus, or any type of malware to do that. You just need Java and Javascript enabled in any browser, and away they go.


In each of these are two files, exactly the same in each folder. These are "plugin-crossdomain.xml" and "plugin-policy.html"

The only relevant information I could find on these names were here. It seems to be an attempt to find a flaw in Flash. I was thinking that maybe it was trying to replace files within the Flash player with the ones you name. But I checked through the entire Flash Player 10 plugin, and there are no such files by those names.


Certainly wouldn't hurt to try MacScan, or the free ClamXAV, but I doubt either one will find anything.

Apr 20, 2011 11:28 AM in response to Requiembeats

I believe that you are seeing is part of the ongoing security problems enabled by Adobe Flash. It's not a virus, but rather a "Feature" that can combine with Javascript and can be taken advantage of by websites for whatever purposes they want to exploit. Here's a description of the problem.


The sex page popups are generating cash for the site owner. The owners of the sites that initiate the popups doesn't care if you look at the pages, or buy any products. Their server records the hits and they get paid by the content owner.


Adobe has patched Flash at least 30 times in the last 3 years. It's a constant security problem for all OS's. You should check to see if you are running the latest version ofFlash.


The recovered files in the trash problem has been around for quite a few years. It doesn't mean much, and the files can be safely deleted.

Apr 20, 2011 12:46 PM in response to Requiembeats

Nobody's commenting on the downloading-something-to-help-watch-a-video plus sex thing, but that sounds suspiciously like the MO for the RSPlug trojan. Admittedly, the traditional ploy was for it to be a plug-in used for watching sex videos, so it's not quite the same thing, but it's close enough to be worth thinking about. Especially since alternate forms of RSPlug have been seen in the wild.


Note that I don't necessarily think this is likely, nor do I think that most/any of the other symptoms described might be caused by an RSPlug infection. However, it's definitely worth running a scan for malware using something like ClamXav:


http://www.clamxav.com/


For more information on this topic, see my Mac Virus Guide:


http://www.reedcorner.net/guides/macvirus/

Possible Virus?!

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.