Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

new malware disguised as flash installer

I'm a dummy....fell for the ruse, any ideas on how to get rid of this new malware? thanks

iMac, Mac OS X (10.6.8)

Posted on Sep 27, 2011 7:45 AM

Reply
128 replies

Sep 27, 2011 1:01 PM in response to Shirley Drabble1

Shirley Drabble1 wrote:


I tried spotlight for that .dylib file but the results were inconclusive. I am guessing SPotlight doesn't look in libraries

What if anything should I do now?

Go to the Applications/Utilities folder, and near the bottom is an application Terminal.app Double click on it, and when the terminal window appears, copy/paste the following command into the terminal window:


ls -ld ~/Library/Preferences/P*

ls -l ~/Library/LaunchAgents/


Nothing on my system looks remotely similar to ~/Library/Preferences/Preferences.dylib or ~/Library/LaunchAgents/com.apple.SystemUI.plist, so I hope that means I'm ok...

Sep 27, 2011 1:38 PM in response to Kurt Lang

Oh dear! I downloaded it and ran it about a week or so ago. However, I do not have the file mentioned in the MacFixit site mentioned above, shown below:


‘Intego says the program installs its malicious dynamic library in the/username/Library/Preferences/ folder as the file "Preferences.dyld,"so you can go to that location and remove that file to dispose of the code.’


I have searched for a file called “"Preferences.dyld"and it is not there. But I have lots of files starting with “dyld” (no dot). They are all in my external backup HD which is a clone of my system disc, done by Carbon Copy Cloner. They are either in a top level folder called _CCC Archives, or in a top level folder called Developer which I am fairly sure is part of Apple’s Xcode which I down loaded a few days ago.


One good thing is that whenever I give my credit card details over the Internet, the documents involved (screen grabs of the transaction) are stored in an encrypted disc image, and my bank account details have never appeared in my computer.


Have I escaped? If not, what to do? Get Intego pronto?

Sep 27, 2011 1:48 PM in response to Kurt Lang

Sorry. I meant is this part of Apple Firewall set up and is it controlled remotely rather than from my own system. OH and this is what happened when I typed into terminal



Last login: Tue Sep 13 19:43:53 on console

**************:~ *********$ ls -ld ~/Library/Preferences/P*

drwxr-xr-x 2 ********* staff 68 20 Dec 2009 /Users/*************/Library/Preferences/PiratePoppers

-rw-r--r--@ 1 ******* staff 86 1 Dec 2009 /Users/*************/Library/Preferences/Pref Kunvert 1.0.2***********-MacBook-Pro:~ ***********$

*****************MacBook-Pro:~ ************$ ls -l ~/Library/LaunchAgents/

total 88

-rw-r--r-- 1 *********** staff 589 5 Oct 2010 com.adobe.ARM.925793fb327152fd34795896fa1fb9ffa268b2a852256fe56609efa3.plist

-rw-r--r-- 1 ************* staff 543 23 Oct 2010 com.akamai.client.plist

-rw-r--r-- 1 ************* staff 463 15 Oct 2010 com.apple.FTMonitor.plist

-rw-r--r-- 1 ************* staff 425 28 Jul 22:45 com.apple.FolderActions.enabled.plist

-rw-r--r-- 1 ************* staff 589 13 Sep 19:44 com.apple.FolderActions.folders.plist

-rw-r--r-- 1 ************* staff 581 20 Mar 2010 com.apple.MobileMeSyncClientAgent.plist

-rw-r--r-- 1 ************* staff 817 20 Mar 2010 com.apple.SafariBookmarksSyncer.plist

-rw-r--r-- 1 ************* staff 552 20 Oct 2010 com.apple.apsd-ft.plist

-rw-r--r-- 1 ************* staff 411 13 Oct 2010 com.apple.imagent.plist

-rw-r--r-- 1 ************* staff 447 13 Oct 2010 com.apple.marcoagent.plist

-rw-r--r-- 1 ************* staff 561 10 Jul 23:26 com.zeobit.MacKeeper.Helper

*************-MacBook-Pro:~ *************$

*************-MacBook-Pro:~ *************$



This looks OK to me, is it the sort of response I should expect if I don;t have anything nasty.:-)

This is getting a bit confusing.

Oh and I run CLAMXAV as antivirus would that pick it up at all. I am always aware that I could pass on a nasty thourhg emails or whatever to my non- MAc user friends.

Thnks

****** to hide my system name

Sep 27, 2011 2:08 PM in response to andyBall_uk

Hi Andy,


It would certainly help if Adobe would stick with one name. I just downloaded the Flash player from their site, and the file has this name:


install_flash_player_osx_intel.dmg


Though the name would be different for Windows, Linux or a PowerPC Mac.


More important is to watch what comes up when you launch the installer. The Trojan looks like this:

User uploaded file

The real Adobe installer displays this:

User uploaded file

The image above I incorrectly flagged was the icon that displays when you open the Adobe .dmg file:

User uploaded file

Upon opening that, the installer package should look like this:

User uploaded file

Be very wary of anything else you may download.

Sep 27, 2011 2:04 PM in response to SteveKir

I have now used Finder to list "~Library/Preferences" in a standard Finder window and there is no sign of "Preferences.dylib". Does that mean it is not there?


Not necessarily. The file could be hidden in the Finder. You could have a variant of the trojan that doesn't install that file, or the information you're relying on could be inaccurate. Trying to detect trojans by poking around with the Finder, without really knowing what you're looking for, is not much use.


And, do you know why Spotlight would not find it?


It doesn't show that type of file. If you want comprehensive file searches by name, you either have to use a shell command, which is unsuitable for non-technical users, or a third-party tool such as EasyFind.

Sep 27, 2011 2:17 PM in response to Sam Beaver

Sam Beaver wrote:


thanks for the heads up. this install flash thing had popped open earlier today, but never got around to installing it.

Any luck on a URL for this thing? We really need to get this thing to the right folks. It should still be in your browser history. Send the URL in a message to <makeupanyname>@mailinator.com and let us know what "makeupanyname" is.

new malware disguised as flash installer

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.