Apple Event: May 7th at 7 am PT

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

virus JS.Obfus-48

Today Jan-8 ClamXav found a virus called JS.Obfus-48 after I downgraded my Firefox version from 9.01 to 8. The Virus was found in the Users/(mydirectory)/Library/Caches/Firefox/Profiles/gn7cw1kc.default/Cache/9/C0 /787ABd01.


I am wondering if anyone has had any experience with this virus?

MacBook Pro, Mac OS X (10.6.8)

Posted on Jan 8, 2012 3:20 PM

Reply
Question marked as Best reply

Posted on Jan 8, 2012 6:51 PM

macfrombrampton wrote:


Today Jan-8 ClamXav found a virus called JS.Obfus-48 after I downgraded my Firefox version from 9.01 to 8. The Virus was found in the Users/(mydirectory)/Library/Caches/Firefox/Profiles/gn7cw1kc.default/Cache/9/C0 /787ABd01.


I am wondering if anyone has had any experience with this virus?

No, but I'll tell you what I think I know about it.


First, it's not a Mac OS X specific infection or it would have "OSX" in it's name. Nor is it a virus. It's a JavaScript which seems to have been designed to obfuscate a hyperlink. Since it's in your FireFox Cache it means you visited a web page using FireFox at the date and time this file was created and it contained a JavaScript which would have run if you clicked on it. Any harm it might have done is in the past and if it is a threat to your Mac it is harmless sitting in your cache. If I were guessing I would say that if you clicked on the link you would have ended up on a different web page than the one you thought you were going to. What was on that page is anybody's guess.


Since clamav does not provide descriptions of any of their infections and every AV software provider is free to name their malware whatever they want to, there is no way to know exactly what most malware does. The clamav database currently has 778 signatures that start with "JS" and 163 of those are "JS.Obfus." I have translated the signature but won't post it here as that would just result in all readers having it in their browser cache.

42 replies

Apr 4, 2012 5:22 AM in response to eww

STOP saying this garbage about mac's NOT GETTING VIRUSES?!


The ONLY reason that was ever the case was the ratio of macs to pc's. Well wake up-that ratio is far from current and we ALL have these viruses and need flipping help!


Does anyone actually know what to do?


This false reality, despite data to the contrary is getting ridiculous and insulting. WE ARE GETTING VIRUSES


<Edited by Host>

Apr 4, 2012 4:31 AM in response to macfrombrampton

Yes- It is DEFINITELY virus and clamxav found them. I tried the other software but the "Virus" killed it halfway. This is really frustrating. Why are they repeating that these are not malware or virus? My computer is being killed off-and with iCloud had to shut down all access to Internet -may be too late.


I am on another computer that is not connected. If you read the Log views, it is unreall! Total infection and don't know how to quaratine.

Apr 5, 2012 11:37 PM in response to jelly2donuts

Jelly2donuts , I suspect they are saying there is o virus because they are using the virus and don't want anyone to be aware of them. It is unbelivable that someone today would think there is no Malware for Mac's.


Has anyone have any function infomration for what these malware attempt to perform? I find it interested Clamxav can find the Malware but not identify its function.


The name of the malware Clamxav found is "JS.Obfus-48" and ""Heuristic.Phishing.email.SpoofedDomain" It still is occasionally place on my Macbook pro running Leopard even after removing.

Apr 6, 2012 1:28 AM in response to macfrombrampton

Well you two (mac and jelly) are certainly eager to mess up this thread.

This "virus" does not do anything on a Mac. That it is detected by Clamxav does not say anything. Because Clamxav only does identify files and not if it is dangerous or not.

It is in a cache folder, and deggie explained how you got it and how to delete it: empty the cache completely, uninstall that Firefox and delete the install file.

If you want Firefox, download Firefox from the Mozilla website and reinstall it.

Apr 6, 2012 2:31 AM in response to macfrombrampton

The effect of this malware, which will be obvious by now to anyone who has followed this thread, is to make any Mac user whose alias is "macfrombrampton" endlessly and obsessively repeat exactly the same questions and paranoid suppositions month after month while ignoring all replies from people who are well informed. The malware is completely inert and harmless on any Mac computer, but migrates to the mind of any macfrombrampton and does all its nefarious work there instead of on his computer.

Apr 6, 2012 5:30 AM in response to macfrombrampton

Earlier post insisting "Viruses can not, do not, have never affected Mac Computers" ( EWW) and others:



As of this writing: ONE MILLION Apple Computers are affected by this Virus. 😉


BITDEFENDER from Mac App Store killed my Trojan, successfully. Highly recommend and FREE!!!


Not a designer, programmer or tech support. That said- my brain is open to information. When people are complaining or looking for help it is ALWAYS for a reason.


Countless times, I have been sure my computer's problems were "user-generated" and spent days if not weeks working on the issues. In 10 years-it has never been me. NEVER. Still, I assume it is, and work thru the issues if it is possible.


My point is, if forums were more willing to acknowledge new issues and unknown problems with a bit of humility, it would be a huge service to the community. None of us know everything or even most. Technology is always changing and rhetoric rampant in the industry.


People ask for help when they have a problem-not because they are stupid.

Apr 6, 2012 5:40 AM in response to jelly2donuts

no one here has been asking about a solution for a "problem" or was "complaining". Someone asked what a particular file does, called it a virus, but had no problems. And two persons in this thread have sent panic posts, unproven statements, "countless problems", etcetera. Thomas and eww have been polite and patient. And now, after stating that you know undisputable, you say that your "brain is open for information". If it is open for information, will it also processing this information?

virus JS.Obfus-48

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.