You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

.rserv wants to connect to cuojshtbohnt.com

I have the message:


.rserv wants to connect to cuojshtbohnt.com


what is .rserv? I googled it and couldn't locate anything ligitimate.


thanks

MacBook Pro, Mac OS X (10.6.8)

Posted on Mar 31, 2012 3:18 PM

Reply
Question marked as Top-ranking reply

Posted on Mar 31, 2012 6:21 PM

I have the same thing happening. Isn't it odd that it's on the same day? Google it now and every entry is from today, within the last 2 hours.


😮


I'll do a text level search of the whole drive and report back if I find something.


GL

228 replies

Apr 12, 2012 8:26 PM in response to tetonfromthatplace

The terminal commands from F--secure did NOT detect the virus


Go to F_Secure's Flashback Removal Tool web page, download their Flashback trojan detection/removal tool, and follow the instructions you find there. That will detect those files and remove them it you allow it.


Also download the latest Apple Java update that came out today and it may detect those files too and remove them.

Apr 12, 2012 8:45 PM in response to X423424X

from F-secure's website I ran


defaults read /Applications/Safari.app/Contents/Info LSEnvironment

and

defaults read ~/.MacOSX/environment DYLD_INSERT_LIBRARIES


neither one of these found the virus. I had already installed the apply java update. Not sure why neither one of those things worked? It wasn't until I installed Little Snatch that I saw what was happening and worked backwards.

Of course now I realize i have to figure out how to turn of Little Snatch.


And, was simply deleting the two files clean things up. Or is there a more thorough investigation I need to do. I'm normally pretty good about not installing downloaded programs unless I know what it is, so I am actually rather suprised my computer was infected.

Apr 12, 2012 8:53 PM in response to tetonfromthatplace

tetonfromthatplace wrote:


from F-secure's website I ran


defaults read /Applications/Safari.app/Contents/Info LSEnvironment

and

defaults read ~/.MacOSX/environment DYLD_INSERT_LIBRARIES

I think you were probably using the wrong F-Secure guidance. The current one is for the "K" variant and has 18 steps.

I had already installed the apply java update.

He's referring to the new one that came out today which removes most Flashware malware.

And, was simply deleting the two files clean things up. Or is there a more thorough investigation I need to do.

Run the software update.

.rserv wants to connect to cuojshtbohnt.com

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.