noellle

Q: Finder shows strange letter and number strings, programs "quit unexpectedly"

A couple of things have been happening. My finder, on right click, shows strange strings of letters and numbers in place of the words that used to be there. For instance, "Open in" now says "N152." (see link: http://www.insanelymac.com/forum/lofiversion/index.php/t85009.html)

 

Also, some programs are saying they "quit unexpectedly" when I try to launch them. Excel and My profile reminder for my eye1display2 are the two I have seen do this so far.

 

Do you have any ideas about what happened and how to fix it?

 

I have a Macbook Pro, Mac OS X 10.6.8.

 

Thank you so much!

Kristen

MacBook Pro, Mac OS X (10.6.8)

Posted on Sep 27, 2011 10:05 PM

Close

Q: Finder shows strange letter and number strings, programs "quit unexpectedly"

  • All replies
  • Helpful answers

first Previous Page 5 of 13 last Next
  • by noellle,

    noellle noellle Oct 6, 2011 11:01 PM in response to MadMacs0
    Level 1 (4 points)
    Desktops
    Oct 6, 2011 11:01 PM in response to MadMacs0

    Oh and do you think I need to do anything else, due to the backdoor?

  • by MadMacs0,

    MadMacs0 MadMacs0 Oct 6, 2011 11:10 PM in response to noellle
    Level 5 (4,801 points)
    Oct 6, 2011 11:10 PM in response to noellle

    noellle wrote:

     

    Is that garbage? Shall I trash it?

     

    Do I need to change my passwords again, now that I've found this file, do you suppose?

    Yes, go ahead and trash it. I'm sure it means something to them, but not to me. I've asked another user to post his to see how it compares.

     

    Since it's just a text file that means it can't actively do anything, so if you've changed your password since you trashed the others I'm sure you are OK.

     

    According to the Intego article they only collected information about your computer, not about you or your passwords, but it never hurts to do easy things like that.

  • by MadMacs0,

    MadMacs0 MadMacs0 Oct 6, 2011 11:17 PM in response to noellle
    Level 5 (4,801 points)
    Oct 6, 2011 11:17 PM in response to noellle

    noellle wrote:

     

    I just tried to scan my CrashPlan Backup drive with Calxav, but it couldn't do it - finishes in seconds and says it found nothing. I'm assuming that, since it's a clone of all of my drives, basically, that when it purges my father's email files that I just deleted, everything will be a-okay with it, right?

    Backup volumes are another special case for AV software, just like email. They have an index that keeps track of what's where and if you delete something without it's knowledge you could lose it all. With Time Machine you can get TM to delete files for you, but I'm not aware of any way to do that with CrashPlan. I use both. My daughter and I CrashPlan backup to each other over the internet and I use TM for a local backup along with a periodic SuperDuper! clone. All the advise I've read says not to use AV software on backkups. My understanding of CrashPlan is that those files will be deleted the next time it updates.

  • by noellle,

    noellle noellle Oct 6, 2011 11:27 PM in response to MadMacs0
    Level 1 (4 points)
    Desktops
    Oct 6, 2011 11:27 PM in response to MadMacs0

    Ok. Thanks!

     

     

    MadMacs0 wrote:


    You probably did the right thing. You must always download FlashPlayer directly from http://get.adobe.com/FlashPlayer, but I it sounds like they may now have an extension for FireFox 7 instead of the usual Plug-In. Since I'm running a much older OS X than you are, I think I'd better defer to other users who have been through this already.

     

     

     

    Were you referring to how to find out how I should install the newest FlashPlayer for Firefox?

     

    Are all of my problems solved now, as far as the trojan, etc. are concerned?

  • by noellle,

    noellle noellle Oct 6, 2011 11:28 PM in response to noellle
    Level 1 (4 points)
    Desktops
    Oct 6, 2011 11:28 PM in response to noellle

    or is the backdoor still an issue?

  • by MadMacs0,

    MadMacs0 MadMacs0 Oct 6, 2011 11:48 PM in response to noellle
    Level 5 (4,801 points)
    Oct 6, 2011 11:48 PM in response to noellle

    noellle wrote:

     

    I'm not sure if I should post this here or on the Intego site link you gave me, since you know all that has been happening with my machine and what I have done about it.

     

    Here is a concern, based on what "Louie, "Intego," and "Steve Joblard" posted on that link.

     

    ...

     

    Intego said that they have found several variants and it might change over time.

    Will Calxav do what Intego will do? I don't really want to have to buy something but will if I have to...or do I need to do something else? - Like Louie starting from scratch?

    There is a lot of paranoid advise being given around the net every time something new comes out. One user who came from a PC background always recommends to people who are infected with a new piece of malware that they unplug from the internet, totally erase their drive, install the OS, plug back into the internet and install all updates then start over with your applications and data. I wouldn't be surprised if that's not the best answer for PC users, but I still don't believe the Mac has progressed to that point.

     

    As far as the backdoor is concerned, Intego did tell us it was there, but since there have been no reports of that site coming back to life and nobody has been reporting anything new since then that they haven't gotten to that point yet. I think they were just trying to build up their network of infected Macs, which they now have a record of, and planned to move to the next phase once the heat is off. The anomalies that you observed may mean they went back to the drawing board to work on v1.1.

     

    As far as several variants are concerned, I have observed the same thing. Apple found a total of eight different signatures and none of them matched the one that Linc Davis, Thomas Reed and I obtained. But the only thing they changed was the "signature" of the installer, but I believe that the files installed were all the same.  When I uploaded the one I had, none of the 43 AV scanners on that site identified the file.  So they have apparently found a way to stay ahead of the AV folks who write signatures.

     

    That reminds me of one more thing you should do. The name of the downloaded installer was probably "FlashPlayer-11-macos.pkg" and would have been placed in your download folder. It reportedly destroys itself when finished with the installation, so it should not be there, but take a look just in case.

     

    Oh, and thanks for the points. I'm not really trying to collect them, but appreciate the thought.

  • by MadMacs0,

    MadMacs0 MadMacs0 Oct 6, 2011 11:54 PM in response to noellle
    Level 5 (4,801 points)
    Oct 6, 2011 11:54 PM in response to noellle

    noellle wrote:

     

    Ok. Thanks!

     

     

    MadMacs0 wrote:


    You probably did the right thing. You must always download FlashPlayer directly from http://get.adobe.com/FlashPlayer

    Were you referring to how to find out how I should install the newest FlashPlayer for Firefox?

    Yes, as far as I know you should be able to get all your updates for FlashPlayer at that site. If FireFox has something else going, I'll defer to somebody else to answer that question as I cannot.

    Are all of my problems solved now, as far as the trojan, etc. are concerned?

     

    or is the backdoor still an issue?

    Looks like I was answering that when you wrote this.

  • by noellle,

    noellle noellle Oct 7, 2011 8:12 AM in response to MadMacs0
    Level 1 (4 points)
    Desktops
    Oct 7, 2011 8:12 AM in response to MadMacs0

    That was all very helpful! Thank you!

     

    I don't really know what the point are for but figured if someone else was searching for an answer to the same problem I had, they would want to know what the answer was, and that would help them find it.

     

    I remembered one more thing:

     

    It said something like asking me if I wanted to install this program - Flashplayer, which was found in my extensions folder.

    Should I delete the file in my extensions folder? Was that part of the trojan thing?

  • by trickmonkey,

    trickmonkey trickmonkey Oct 7, 2011 8:24 AM in response to Linc Davis
    Level 1 (4 points)
    iTunes
    Oct 7, 2011 8:24 AM in response to Linc Davis

    I'm new to this discussion, but in serious need of assistance. It's clear my machine is infected with this malware. I have the same strange numbers replacing certain functions in contextual menus and applications not opening. I ran ClamXav, but it found nothing. I'm now trying to delete the files mentioned above, but cannot find them all. I can't open Terminal to copy/paste Linc's code for the .MacOSX file, and when I went to the folder via 'Go To Folder' as suggested, it was empty. There was no environment.plist.

     

    Also, I have been unable to find the 'Library/Preferences/Preferences.dylib' file or the swlog file (though, I did find the softwareupdate file that was mentioned).

     

    Any help would be much appreciated! I've moved the files I did find to the trash, but I don't want to proceed without getting everything.

  • by trickmonkey,

    trickmonkey trickmonkey Oct 7, 2011 10:12 AM in response to trickmonkey
    Level 1 (4 points)
    iTunes
    Oct 7, 2011 10:12 AM in response to trickmonkey

    Desperate for help with this, if anyone can offer assistance.

  • by trickmonkey,

    trickmonkey trickmonkey Oct 7, 2011 10:47 AM in response to trickmonkey
    Level 1 (4 points)
    iTunes
    Oct 7, 2011 10:47 AM in response to trickmonkey

    Could I possibly erase my drive and re-install from Time Machine (from a backup date that predates the infection)?

  • by trickmonkey,

    trickmonkey trickmonkey Oct 7, 2011 10:55 AM in response to trickmonkey
    Level 1 (4 points)
    iTunes
    Oct 7, 2011 10:55 AM in response to trickmonkey

    I've tried, at the suggestion of others, to download and run MacScan and VirusBarrierX6, but my machine cannot even mount the installers, apparently due to this malware. Help!

  • by trickmonkey,

    trickmonkey trickmonkey Oct 7, 2011 1:25 PM in response to trickmonkey
    Level 1 (4 points)
    iTunes
    Oct 7, 2011 1:25 PM in response to trickmonkey

    Anyone?

  • by noellle,

    noellle noellle Oct 7, 2011 1:29 PM in response to trickmonkey
    Level 1 (4 points)
    Desktops
    Oct 7, 2011 1:29 PM in response to trickmonkey

    @trickmonkey: I am no expert on this by any means. I really know nothing but what others have told me and what I have experienced.

     

    When I couldn't open Terminal (or any application for that matter,) I temporarily moved back the files that I had moved to the trash. (Right click on the files in the trash and choose "put back" or whatever it's called.)

     

    I don't know why you can't find the preferences.dylib file. I know that I couldn't find all the files, and it wasn't a big deal. Yet, from my understanding, the .dylib one is pretty key. I may be wrong.

     

    I don't think you need to erase and start over, because MadMacs0 didn't think that step was usually necessary with a mac :

     

    MadMacs0 wrote:

     

    There is a lot of paranoid advise being given around the net every time something new comes out. One user who came from a PC background always recommends to people who are infected with a new piece of malware that they unplug from the internet, totally erase their drive, install the OS, plug back into the internet and install all updates then start over with your applications and data. I wouldn't be surprised if that's not the best answer for PC users, but I still don't believe the Mac has progressed to that point.

     

     

     

    Also from my understanding, the Virus detection programs can't find it cause the part they would recognize erases right after installation.

     

    I'm sure someone else can help you. Also, MadMacs0 gave me a link to this site. Maybe someone there knows the answer or has written it in the comments already: I"ll get the link in a moment.

  • by noellle,

    noellle noellle Oct 7, 2011 1:31 PM in response to noellle
    Level 1 (4 points)
    Desktops
    Oct 7, 2011 1:31 PM in response to noellle

    Link to the Flashback trojan discussion on the Intego site:

     

    MadMacs0 wrote:

     

    Flashback Trojan Spreading; Mac Users Should Be Wary of Flash Installers

first Previous Page 5 of 13 last Next