New To Mac-Forums?

Welcome to our community! Join the discussion today by registering your FREE account. If you have any problems with the registration process, please contact us!

Get your questions answered by community gurus Advice and insight from world-class Apple enthusiasts Exclusive access to members-only contests, giveaways and deals

Join today!

 
Start a Discussion
 

Mac-Forums Brief

Subscribe to Mac-Forums Brief to receive special offers from Mac-Forums partners and sponsors

Join the conversation RSS
OS X - Operating System General OS operation information and support

New OS X Malware (Snow Leopard)


Post Reply New Thread Subscribe

 
Thread Tools
RkadE_ian

 
Member Since: Jun 24, 2011
Posts: 1
RkadE_ian is on a distinguished road

RkadE_ian is offline
The Mac in question has 2 user accounts and my SO (not a very sophisticated user) began getting dialogue box pop-ups about a week ago on her log-on - no issues with mine. Of course she only mentions this last night.

A box appeared every few minutes asking if you wanted to open a text editor file from Google. I opened a few of these (instead of canceling) and saved the payload which appears to be code to do with google ads. I have a saved copy at home I can post later if it helps. Opening the first file caused a toggle through of all open windows for about 10 seconds then nothing???

I looked at incoming/outgoing connections and traced a few to blacklisted ip addresses - 2 in China, 1 in Netherlands, etc. Around 4 or 5, not a ton. I have a screen shot of that output as well. After disconing the Mac from the internet, I searched on another computer for any trace of this from other users and found nothing. Tons of posts about MACdefender, which this is definitely not. Other machines on my network don't appear to be affected.

Am I infected? thus far I've flushed the DNS cache, cleared cookies, uninstalled firefox (thinking could be some sort of browser hijack). I also checked related /etc file and nothing unusual going on there. Help!
Next steps?
QUOTE Thanks
northrnchimp

 
northrnchimp's Avatar
 
Member Since: Jun 13, 2010
Location: England
Posts: 217
northrnchimp will become famous soon enough
Mac Specs: rMBP 13 2.5GHz 121GB SSD

northrnchimp is offline
Might be an idea to just create a new user account for her (him?) and copy docs across. Then delete the old account.
QUOTE Thanks
Lifeisabeach

 
Lifeisabeach's Avatar
 
Member Since: Sep 30, 2007
Location: Wilmington, NC
Posts: 6,835
Lifeisabeach has a reputation beyond reputeLifeisabeach has a reputation beyond reputeLifeisabeach has a reputation beyond reputeLifeisabeach has a reputation beyond reputeLifeisabeach has a reputation beyond reputeLifeisabeach has a reputation beyond reputeLifeisabeach has a reputation beyond reputeLifeisabeach has a reputation beyond reputeLifeisabeach has a reputation beyond reputeLifeisabeach has a reputation beyond reputeLifeisabeach has a reputation beyond repute
Mac Specs: iMac i3 (mid-2010) + OS 10.9; TV 3; iPhone 5S; iPad 4

Lifeisabeach is offline
If it's confined to just her user account, then an extremely simple way of handling this is to make a backup copy of her user Library, then delete the old. On re-logging into it, OS X will re-create a virgin copy and yer back in business. Just keep the copy around to recover things like Safari bookmarks and other data that may be stored there that she may want.

EDIT: Actually before going that far… have you checked her login items in the System Preferences to see if anything is suspect?


Please verify and include the exact model/year of your Mac and OS X version number (available from "About This Mac", then "More Info" on the Apple menu). Also advise us if you have any antivirus or "cleaning" software installed on your Mac. If you are using MacKeeper, you are hereby advised to uninstall it.
------
Links to commonly recommended software and instructions: Onyx | Apple Hardware Test | How to test your hard drive | How to reveal the User Library
------
Having issues with Safari? Adware is on the rise. See this guide on how to remove it: The Safe Mac Adware Removal Guide
------
Lifeisabeach - Mac-Forums Member of the Month June 2009, Feb 2012, and March 2013.
QUOTE Thanks
schweb

 
schweb's Avatar
 
Member Since: Oct 27, 2002
Location: Cleveland, Ohio
Posts: 13,212
schweb has a reputation beyond reputeschweb has a reputation beyond reputeschweb has a reputation beyond reputeschweb has a reputation beyond reputeschweb has a reputation beyond reputeschweb has a reputation beyond reputeschweb has a reputation beyond reputeschweb has a reputation beyond reputeschweb has a reputation beyond reputeschweb has a reputation beyond reputeschweb has a reputation beyond repute
Mac Specs: MacBook Pro | LED Cinema Display | iPhone 4 | iPad 2

schweb is offline
You are not infected.

Many member ask the question about viruses and malware on the Mac and in addition to using the search function at the top of the forum, you'll find almost all your answers here:

Official Antivirus, Malware, and Firewall FAQ

schweb | community leader
flickr facebook twitter tumblr google+ about.me

Mac-Forums: On Twitter | On Facebook | On Flickr

QUOTE Thanks

Post Reply New Thread Subscribe


« Secure Empty Trash | Make finder locate network computers? »
Thread Tools

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off
Forum Jump

Similar Threads
Thread
Thread Starter
Forum
Replies
Last Post
probelms with graphic card after upgrading to snow leopard reese125 Switcher Hangout 6 12-07-2010 08:54 PM
Snow leopard disaster - apple is replacing my macbook pro.. EntropyX Switcher Hangout 15 10-05-2010 04:04 AM
From Tiger to Snow Leopard? Jospho OS X - Operating System 6 02-25-2010 10:52 AM
Please Help: Pirated Snow Leopard peepz OS X - Operating System 3 11-13-2009 02:14 AM
How Do I Uninstall Snow Leopard? c12susan OS X - Operating System 3 09-23-2009 10:44 PM

All times are GMT -4. The time now is 06:29 PM.

Powered by vBulletin
Copyright ©2000 - 2014, Jelsoft Enterprises Ltd.
X

Welcome to Mac-Forums.com

Create your username to jump into the discussion!

New members like you have made this community the ultimate source for your Mac since 2003!


(4 digit year)

Already a member?