You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

.rserv wants to connect to cuojshtbohnt.com

I have the message:


.rserv wants to connect to cuojshtbohnt.com


what is .rserv? I googled it and couldn't locate anything ligitimate.


thanks

MacBook Pro, Mac OS X (10.6.8)

Posted on Mar 31, 2012 3:18 PM

Reply
Question marked as Top-ranking reply

Posted on Mar 31, 2012 6:21 PM

I have the same thing happening. Isn't it odd that it's on the same day? Google it now and every entry is from today, within the last 2 hours.


😮


I'll do a text level search of the whole drive and report back if I find something.


GL

228 replies

Mar 31, 2012 10:31 PM in response to sthej

sthej wrote:


Thanks for your help on this in general...


I ran the defaults read ~/.MacOSX/environment command in terminal and got a does not exist.


Looking around on google it seems like similar behavior to the flashback trojan as well as the rr.nu domains.


Well you seemed to satisfy yours but I would download Adobe Reader from the Adobe Site. I am still curious how that LaunchAgent got in there in the first place.

Mar 31, 2012 10:42 PM in response to X423424X

I'm sure the mere mention of the word "trojan" is going to attract certain interested readers to this thread. So just in case, to make it easier for them, here's that adobe reader LaunchAgents plist in a more readable (i.e., formatted) form:


<?xml version="1.0" encoding="UTF-8"?>

<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

<plist version="1.0">

<dict>

<key>Label</key>

<string>com.adobe.reader</string>

<key>ProgramArguments</key>

<array>

<string>/Users/trungson/.rserv</string>

</array>

<key>RunAtLoad</key>

<true/>

<key>StartInterval</key>

<integer>4212</integer>

<key>StandardErrorPath</key>

<string>/dev/null</string>

<key>StandardOutPath</key>

<string>/dev/null</string>

</dict>

</plist>


Why would a launchd plist in a user's LaunchAgents have to specify RunAtLoad (it would run at login anyhow) and a StartInterval (or is this why RunAtLoad is needed)?

Mar 31, 2012 10:41 PM in response to trungson

trungson wrote:


/Users/trungson/Library/LaunchAgents/com.adobe.reader.plist:

(I'll assume this is on the level.)


The syntax is valid; also, it has nothing to do with Adobe Reader. (The latter's identifier is probably "com.adobe.Reader", and there would be no need for it to implement anything as a launch agent.)


This plist implements a launch agent. It tells launchd to run </Users/trungson/.rserv> every 4212 seconds, discarding any output and error. The process is not kept alive—launchd runs it, it does whatever it was designed to do, then terminates, and launchd runs it again some 70 mins later. (Which explains why ps didn't list it.) If I were to speculate (without any evidence), I'd say it's trying to connect to the mothership to download the actual payload.

Mar 31, 2012 10:47 PM in response to fane_j

It's just these kind of things why I consider Little Snitch a "must have" on my systems. The last thing I want is something, anything, sent back to adobe, no matter what.

The syntax is valid; also, it has nothing to do with Adobe Reader. (The latter's identifier is probably "com.adobe.Reader", and there would be no need for it to implement anything as a launch agent.)


Why use the id "com.adobe.Reader" if it wasn't associated with Adobe Reader? I do know the current AR doesn't instll this.

Mar 31, 2012 10:46 PM in response to X423424X

I don't have Adobe Reader, but I do have Acrobat Professional 8. There is no Adobe .plist file at the locations you asked about.


Did you see my earlier post that I found the .rsvr file, it's 59.9K and it was downloaded by PluginProcess.app on March 30, 2012 (part of the webkit2 framework)? I could try to Zip it and email it to someone you if you want it.

Mar 31, 2012 10:50 PM in response to bgw1

Did you see my earlier post that I found the .rsvr file, it's 59.9K and it was downloaded by PluginProcess.app on March 30, 2012 (part of the webkit2 framework)? I could try to Zip it and email it to someone you if you want it.


I guess I missed that. I don't know what PluginProcess.app is. So long as you found it, ok.

Mar 31, 2012 10:53 PM in response to X423424X

X423424X wrote:


here's that adobe reader LaunchAgents plist in a more readable (i.e., formatted) form:

That's useful. Just a couple of comments.


The plist has nothing to do with Adobe Reader. The Label key is a unique identifier, required by launchd to keep track of agents. But it can be any string. If launchd's database is case-sensitive, and the Adobe Reader identifier is, as I suspect, com.adobe.Reader, then it's enough.


RunAtLoad key is optional key "used to control whether your job is launched once at the time the job is loaded". (It's in the launchd.plist manpage.)


As to how it was installed… My bet would still be CVE-2011-3544.

Mar 31, 2012 10:56 PM in response to bgw1

bgw1 wrote:


it was downloaded by PluginProcess.app on March 30, 2012

PluginProcess lives here


</System/Library/PrivateFrameworks/WebKit2.framework/PluginProcess.app>


So this was in all likelihood downloaded by Safari (possibly also Chrome?). You should make a list of all sites visited on that date. Any Wordpress blogs among them?

.rserv wants to connect to cuojshtbohnt.com

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.