New OS X Malware (Snow Leopard)

Joined
Jun 24, 2011
Messages
1
Reaction score
0
Points
1
The Mac in question has 2 user accounts and my SO (not a very sophisticated user) began getting dialogue box pop-ups about a week ago on her log-on - no issues with mine. Of course she only mentions this last night.

A box appeared every few minutes asking if you wanted to open a text editor file from Google. I opened a few of these (instead of canceling) and saved the payload which appears to be code to do with google ads. I have a saved copy at home I can post later if it helps. Opening the first file caused a toggle through of all open windows for about 10 seconds then nothing???

I looked at incoming/outgoing connections and traced a few to blacklisted ip addresses - 2 in China, 1 in Netherlands, etc. Around 4 or 5, not a ton. I have a screen shot of that output as well. After disconing the Mac from the internet, I searched on another computer for any trace of this from other users and found nothing. Tons of posts about MACdefender, which this is definitely not. Other machines on my network don't appear to be affected.

Am I infected? thus far I've flushed the DNS cache, cleared cookies, uninstalled firefox (thinking could be some sort of browser hijack). I also checked related /etc file and nothing unusual going on there. Help! :[
Next steps?
 
Joined
Jun 13, 2010
Messages
217
Reaction score
8
Points
18
Location
England
Your Mac's Specs
rMBP 13 2.5GHz 121GB SSD
Might be an idea to just create a new user account for her (him?) and copy docs across. Then delete the old account.
 
Joined
Sep 30, 2007
Messages
9,962
Reaction score
1,235
Points
113
Location
The Republic of Neptune
Your Mac's Specs
2019 iMac 27"; 2020 M1 MacBook Air; macOS up-to-date... always.
If it's confined to just her user account, then an extremely simple way of handling this is to make a backup copy of her user Library, then delete the old. On re-logging into it, OS X will re-create a virgin copy and yer back in business. Just keep the copy around to recover things like Safari bookmarks and other data that may be stored there that she may want.

EDIT: Actually before going that far… have you checked her login items in the System Preferences to see if anything is suspect?
 
Joined
Oct 27, 2002
Messages
13,172
Reaction score
348
Points
83
Location
Cleveland, Ohio
Your Mac's Specs
MacBook Pro | LED Cinema Display | iPhone 4 | iPad 2

Shop Amazon


Shop for your Apple, Mac, iPhone and other computer products on Amazon.
We are a participant in the Amazon Services LLC Associates Program, an affiliate program designed to provide a means for us to earn fees by linking to Amazon and affiliated sites.
Top