Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Finder shows strange letter and number strings, programs "quit unexpectedly"

A couple of things have been happening. My finder, on right click, shows strange strings of letters and numbers in place of the words that used to be there. For instance, "Open in" now says "N152." (see link: http://www.insanelymac.com/forum/lofiversion/index.php/t85009.html)


Also, some programs are saying they "quit unexpectedly" when I try to launch them. Excel and My profile reminder for my eye1display2 are the two I have seen do this so far.


Do you have any ideas about what happened and how to fix it?


I have a Macbook Pro, Mac OS X 10.6.8.


Thank you so much!

Kristen

MacBook Pro, Mac OS X (10.6.8)

Posted on Sep 27, 2011 10:05 PM

Reply
185 replies

Oct 5, 2011 9:50 AM in response to sig

@ sig No I gave the advice to make a clean install, which is finally not wrong, although I did not know to read well the error logs. But you may correct me, instead of giving advices, so that we learn all from your wisdom.


@ Linc Davis Thank you for this deep insight and the serious words. One thing I am wondering: which was the hint to the trojan in the posted error log? Please enlighten me and the forum. I am eager to learn.



marek

Oct 5, 2011 10:20 AM in response to noellle

My Dad told me there were no Mac viruses.


Strictly speaking, he's right, but the advice was somewhat misleading. A virus, in the strict sense, is malware that spreads without human intervention. For example, all you do is visit a website, and you're infected. That sort of thing happens to Windows users, but not to Mac users -- so far. A trojan horse is malware that the user is duped into installing voluntarily. That's what happened to you. Mac trojans used to be very rare, but they're becoming less so, and there will be more of them in the future. The only real defense is safe computing practices. Don't rely on software to protect you.


I have two external drives for files and an external drive for backing up via Crash Plan. Is that going to make things worse?


Make sure you disinfect your backups.

Oct 5, 2011 2:26 PM in response to Linc Davis

Linc Davis wrote:


Regrettably, you installed the "Flashback" trojan.


Download the ClamXav anti-malware application and run it. It should find the trojan and remove it. If not, you'll need to remove at least the following files from your home folder, then log out and log back in:


  1. .MacOSX/environment.plist
  2. Library/LaunchAgents/com.apple.SystemUI.plist
  3. Library/Preferences/perflib
  4. Library/Preferences/Preferences.dylib
  5. Library/Logs/swlog

Unfortunately ClamXav will only detect the installer which destroys itself after installation of the above files. Since there is evidence that the bad guys are changing the signature of the installer, perhaps for every download, there is a strong possibility that it won't even detect the installer. Same goes for Apple's XProtect system.


I believe, the only way I know of to see if your infected is to check for the presence of these files and, as you suggested, remove all of them during the same session or risk not being able to log back into the account.


Linc, if you still have these files can you upload them all to VirusTotal and clamav? As I recall the log file was blank, so you would only need to upload the first four. Be sure and use the keyword "macos" on the clamav site.

Oct 5, 2011 3:05 PM in response to MadMacs0

Thank you for your insight, MadMacs0. Clamav is still working through my machine itsef and hasn't found anything yet. I guess I will let it finish its thing, just in case (It's on the "Users" folder now, and seems to be going alphabetiacally.)


Then, I will look for those files and log out and log back in.


I will keep you all updated. I really appreciate everyone taking the time to help me!

Oct 5, 2011 3:32 PM in response to noellle

noellle wrote:


I will look for those files and log out and log back in.

If you find the files, move them all into a folder on your desktop first in case I need you to upload them to a couple of AV Sample databases so that the AV community can code up signatures for them. I'm hoping Linc will take care of that, but just in case he no longer has them.

Oct 5, 2011 4:09 PM in response to MadMacs0

Unfortunately ClamXav will only detect the installer which destroys itself after installation of the above files.


That's news to me.


Linc, if you still have these files can you upload them...


I'm afraid I don't, but I downloaded the installer from a link posted on Mailinator which I think you also had. All I did was run it, under controlled conditions, of course.


As I recall the log file was blank, so you would only need to upload the first four.


The log file wasn't empty, but the contents were variable.

Oct 5, 2011 4:17 PM in response to noellle

Ok - so if they are just on my desktop, they are not dangerous?


To be clear, moving the files to the Desktop does not inactivate the trojan. You must move or delete the files and then log out.


Since you have to do this manually, you should know that one of the items you need to delete is invisible in the Finder. Launch the Terminal application, copy or drag -- do not type -- the line below into the window, and press return:


rm -r .MacOSX


You can then quit Terminal.

Oct 5, 2011 4:21 PM in response to Linc Davis

Hi All,

I had this same issue and had started another thread on it a few days ago. I just did as Linc suggested and now the issue no longer exists. I've moved the files to my desktop. Be forewarned, when I logged back in after removing the files, my screen went blank which made my heart skip a beat. I had to restart and then everything was just like always except those wierd numbers were finally gone. I have the files to upload to AV and will be glad to be rid of them. Thanks!

Oct 5, 2011 5:20 PM in response to Linc Davis

Linc Davis wrote:


Unfortunately ClamXav will only detect the installer which destroys itself after installation of the above files.


That's news to me.

News that it only detects the installer or that it destroys itself. Did your's not disappear?

I'm afraid I don't, but I downloaded the installer from a link posted on Mailinator which I think you also had.

Yes, I posted the link, but it would not let me download the file, possibly because I'm running Leopard on a PPC.

Finder shows strange letter and number strings, programs "quit unexpectedly"

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.