noellle

Q: Finder shows strange letter and number strings, programs "quit unexpectedly"

A couple of things have been happening. My finder, on right click, shows strange strings of letters and numbers in place of the words that used to be there. For instance, "Open in" now says "N152." (see link: http://www.insanelymac.com/forum/lofiversion/index.php/t85009.html)

 

Also, some programs are saying they "quit unexpectedly" when I try to launch them. Excel and My profile reminder for my eye1display2 are the two I have seen do this so far.

 

Do you have any ideas about what happened and how to fix it?

 

I have a Macbook Pro, Mac OS X 10.6.8.

 

Thank you so much!

Kristen

MacBook Pro, Mac OS X (10.6.8)

Posted on Sep 27, 2011 10:05 PM

Close

Q: Finder shows strange letter and number strings, programs "quit unexpectedly"

  • All replies
  • Helpful answers

first Previous Page 6 of 13 last Next
  • by noellle,

    noellle noellle Oct 7, 2011 1:32 PM in response to noellle
    Level 1 (4 points)
    Desktops
    Oct 7, 2011 1:32 PM in response to noellle

    although it looks like noone has replied on that for a week.

  • by trickmonkey,

    trickmonkey trickmonkey Oct 7, 2011 1:37 PM in response to noellle
    Level 1 (4 points)
    iTunes
    Oct 7, 2011 1:37 PM in response to noellle

    Thank you for your replies, noellle. I will try moving the files back, as you said, but how can you be sure your machine isn't still infected at some level, and that it can't be accessed by someone on the outside?

     

    I figured erasing and starting fresh would be the only way to be sure.

     

    Also, I'm concerned about this .dylib file and why I can't locate it. On the Intego site people said if the .dylib file wasn't there then you weren't infected, but there's no question that my machine is f'd up by this malware right now.

  • by trickmonkey,

    trickmonkey trickmonkey Oct 7, 2011 1:41 PM in response to trickmonkey
    Level 1 (4 points)
    iTunes
    Oct 7, 2011 1:41 PM in response to trickmonkey

    I put the trashed files back, but it did no good.

    I think nuking it is the only thing left to do.

  • by noellle,

    noellle noellle Oct 7, 2011 1:47 PM in response to trickmonkey
    Level 1 (4 points)
    Desktops
    Oct 7, 2011 1:47 PM in response to trickmonkey

    You're welcome.

     

    I guess I can't be sure it's not infectected on some level, but MadMacs0 didn't seem to have any concern. He said he looks at their server or something every day, and it has been wiped clean, like they moved on or were captured.

     

    MadMacs0 wrote:

     

    As far as the backdoor is concerned, Intego did tell us it was there, but since there have been no reports of that site coming back to life and nobody has been reporting anything new since then that they haven't gotten to that point yet. I think they were just trying to build up their network of infected Macs, which they now have a record of, and planned to move to the next phase once the heat is off. The anomalies that you observed may mean they went back to the drawing board to work on v1.1.

     

     

    I suppose you can do what you like, but I would wait for someone else to respond. They may just be working and need to get back to this when they are done with their workday. It's up to you.

  • by trickmonkey,

    trickmonkey trickmonkey Oct 7, 2011 6:01 PM in response to noellle
    Level 1 (4 points)
    iTunes
    Oct 7, 2011 6:01 PM in response to noellle

    Linc or MadMacs0, if you guys have any suggestions I am desperate for some.

  • by trickmonkey,

    trickmonkey trickmonkey Oct 7, 2011 7:11 PM in response to trickmonkey
    Level 1 (4 points)
    iTunes
    Oct 7, 2011 7:11 PM in response to trickmonkey

    I've scoured the net for more answer to no avail. The only real information I've come across is in this thread. I clearly have been infected by this malware, yet the file that everyone says is a clear indicator (Preferences.dylib) is nowhere to be found.

     

    If anyone can offer any help at all I'm very much in need of it.

     

    Thank you.

  • by MadMacs0,

    MadMacs0 MadMacs0 Oct 7, 2011 7:36 PM in response to trickmonkey
    Level 5 (4,801 points)
    Oct 7, 2011 7:36 PM in response to trickmonkey

    trickmonkey wrote:

     

    I can't open Terminal to copy/paste Linc's code for the .MacOSX file, and when I went to the folder via 'Go To Folder' as suggested, it was empty. There was no environment.plist.

     

    Also, I have been unable to find the 'Library/Preferences/Preferences.dylib' file or the swlog file (though, I did find the softwareupdate file that was mentioned).

    The only things I can think of is that you either have a new version of this thing which has placed the functionality of those files elsewhere or the installer didn't finish it's task for whatever reason.

     

    Have you checked your downloads folder for a FlashPlayer installer of some sort?

     

    The other clue would be if you can figure out when all this happened? If you recall seeing any of the art work displayed at the Intego site and were prompted to download and install a flash update, was it a couple of weeks ago or something that just happened?  That's important if you decide you want to restore from Time Machine. You should be able to find the exact time you installed it by going back through the install logs that Console can display.

     

    One user who did failed to remove the environment.plist was unable to log back into his account. Fortunately he had another admin account established from which he was able to find and delete it. Otherwise I think he would have lost everything.  I'm hesitant to tell you to trash what you have as it could have similar results.

     

    I'll read through your other questions in a bit and get back to you.

  • by trickmonkey,

    trickmonkey trickmonkey Oct 7, 2011 8:25 PM in response to MadMacs0
    Level 1 (4 points)
    iTunes
    Oct 7, 2011 8:25 PM in response to MadMacs0

    Hi MadMacs0,

     

    Thanks much for your reply. I'm not sure when I got the phony installer pop-up. Maybe last week or early this week? I know I saw the first symptom (the weird N152 in place of 'Open With') yesterday. Or maybe the day before. It's all starting to blur.

  • by MadMacs0,

    MadMacs0 MadMacs0 Oct 7, 2011 9:42 PM in response to trickmonkey
    Level 5 (4,801 points)
    Oct 7, 2011 9:42 PM in response to trickmonkey

    trickmonkey wrote:

    I'm not sure when I got the phony installer pop-up. Maybe last week or early this week? I know I saw the first symptom (the weird N152 in place of 'Open With') yesterday. Or maybe the day before. It's all starting to blur.

    I take it you able to open applications again. If so, open up the Console app in /Applications/Utilities/ and there should be a list of files on the left. If not use the "Show Log List" button, the under "LOG FILES" find /var/log/ (if you don't see these click on the small disclosure triangle so it points down) and scroll down to the first install.log. There's a box in the upper right corner of the window above the words "Filter" that has gray "String Matching" Try entering "flashplayer" without the quotes and see if it tells you when you installed it and what it was called. The one I have is "FlashPlayer-11-macos.pkg".

  • by noellle,

    noellle noellle Oct 7, 2011 10:14 PM in response to MadMacs0
    Level 1 (4 points)
    Desktops
    Oct 7, 2011 10:14 PM in response to MadMacs0

    Oh boy. I'm back. I don't know if this is related, but it sure has uncanny timing.

     

    My business website, www.kristenbuchmann.com has been hacked or something. here are screenshots of what my client saw and what I see when I try to visit my site:

     

    ok nevermind. It won't let me upload the screenshots. strange.

     

    Anyway, if you visit the site youself, you will see that it says that my site may harm your computer and may contain malware....

     

    I changed my password with my hosting company's web panel. I also have a web panel password for two other parts of my site (a wordpress blog hosted on my site and also a flash site with a separate web panel,) but they have urls that are part of my site, so I am nervous to click through to change them. What should I do ???

     

    Do you think this is related or just bad timing?

     

    Do you know how I can get Google to relist me as safe???! Very bad for business.

  • by MadMacs0,

    MadMacs0 MadMacs0 Oct 7, 2011 11:28 PM in response to noellle
    Level 5 (4,801 points)
    Oct 7, 2011 11:28 PM in response to noellle

    noellle wrote:

     

    My business website, www.kristenbuchmann.com has been hacked or something....

     

    I changed my password with my hosting company's web panel. I also have a web panel password for two other parts of my site (a wordpress blog hosted on my site and also a flash site with a separate web panel,) but they have urls that are part of my site, so I am nervous to click through to change them. What should I do ???

    First I would start a new thread with a more appropriate title which will attract folks who know more about this than I do.

    Do you think this is related or just bad timing?

     

    Do you know how I can get Google to relist me as safe???! Very bad for business.

    I don't really see how it could be related, unless that's where you picked up the Trojan.

     

    This site has some tips on what to do and how to contact them. I think someone is going to have to scan the code on your pages and remove whatever is causing it.

     

    I think I may have to take a look at your site once you get it fixed. Looks quite elegant.

  • by MadMacs0,

    MadMacs0 MadMacs0 Oct 7, 2011 11:39 PM in response to MadMacs0
    Level 5 (4,801 points)
    Oct 7, 2011 11:39 PM in response to MadMacs0

    OK, I clicked on Lifestyle Portraits, I think, and was redirected to macosxsoftwareupdate.org-slash-flashplugin-slash-7f-slash- (I used -slash- for / so that people won't be tempted to click on it) which is the site I've been watching. As I said yesterday, that address has been removed from the DNS database, so it doesn't work, but you still need to clean that redirect off of your site in order to get Google to take you off the blacklist and if that site ever goes active...well you know what happens next.

  • by noellle,

    noellle noellle Oct 7, 2011 11:50 PM in response to MadMacs0
    Level 1 (4 points)
    Desktops
    Oct 7, 2011 11:50 PM in response to MadMacs0

    Oh my gosh! It IS connected?! What in the world?

     

    This site has some tips on what to do and how to contact them. I think someone is going to have to scan the code on your pages and remove whatever is causing it....

     

    but you still need to clean that redirect off of your site in order to get Google to take you off the blacklist

     

     

     

    Are you saying that I need to clean it by having someone scan it and remove it?

     

    I started to follow the steps linked to that site - http://25yearsofprogramming.com/blog/20070704.htm

     

    and can't get past the first step. I use Dreamhost, which doesn't use cpanel.

     

    So, I want to take my site offline using the method on the link I mention above, but I can't figure out how to make an .htaccess code because this page: http://www.javascriptkit.com/howto/htaccess.shtml

     

    said

    htaccess files must be uploaded as ASCII mode, not BINARY. You may need to CHMOD the htaccess file to 644 or (RW-R--R--). This makes the file usable by the server, but prevents it from being read by a browser, which can seriously compromise your security. (For example, if you have password protected directories, if a browser can read the htaccess file, then they can get the location of the authentication file and then reverse engineer the list to get full access to any portion that you previously had protected. There are different ways to prevent this, one being to place all your authentication files above the root directory so that they are not www accessible, and the other is through an htaccess series of commands that prevents itself from being accessed by a browser, more on that later)

     

    and I am so LOST. I don't understand it. I don't have an .htaccess file, and I am SO tired from staying up late dealing with all of this.

  • by noellle,

    noellle noellle Oct 7, 2011 11:51 PM in response to noellle
    Level 1 (4 points)
    Desktops
    Oct 7, 2011 11:51 PM in response to noellle

    I think I just need to go to sleep and will maybe think more clearly in the morning. I am just afraid that damage will be done while I sleep.

  • by noellle,

    noellle noellle Oct 8, 2011 12:09 AM in response to noellle
    Level 1 (4 points)
    Desktops
    Oct 8, 2011 12:09 AM in response to noellle

    Okay, I have started this new discussion on this new thread. Thank you, MadMacs0 (and others who have been so helpful!)

    Flashback virus hacked my business website and computer. What should I do?

first Previous Page 6 of 13 last Next