RansomWhere?

Joined
Nov 29, 2010
Messages
2,513
Reaction score
134
Points
63
Location
Warrington, UK
Your Mac's Specs
PPC Mini, 10.4.11. Intel Mini, 10.6.8. MacBook Pro, 10.14.6. M1 MBA 11.6.3 iPhone 5 iOS 12.5,
Just recently, when I restart my MBP, which is not very often, I get two popups. One asking if I want to update my version of RansomeWhere?, and another saying that RansomeWhere? wants to make some changes and asking for my password.

I haven't installed RansomeWhere? and a search with Spotlight and Find Any File shows nothing.

Has anyone else had this?
 
Joined
May 21, 2012
Messages
10,745
Reaction score
1,192
Points
113
Location
Rhode Island
Your Mac's Specs
M1 Mac Studio, 11" iPad Pro 3rd Gen, iPhone 13 Pro Max, Watch Series 7, AirPods Pro
I'm using OS 10.11.5 and it's not happening here. What OS X are you running? Have you tried to run Malwarebytes?
 
Joined
Nov 28, 2007
Messages
25,564
Reaction score
486
Points
83
Location
Blue Mountains NSW Australia
Your Mac's Specs
Silver M1 iMac 512/16/8/8 macOS 11.6
If you did not install it, get red of it.
 
Joined
Oct 16, 2010
Messages
17,541
Reaction score
1,576
Points
113
Location
Brentwood Bay, BC, Canada
Your Mac's Specs
2011 27" iMac, 1TB(partitioned) SSD, 20GB, OS X 10.11.6 El Capitan
Man, I'd sure get all traces of such traces removed from my Mac so fast it would make your head spin.

Especially considering the "developer" even has the lack of any principles to release malware samples downloads to anyone… gads!!!
"OS X Malware Samples"
https://objective-see.com/malware.html

Just the thing everyone wants to receive, some malware sample some nut/"friend" downloaded — I think NOT!!!




- Patrick
======
 
Last edited:
Joined
Oct 16, 2010
Messages
17,541
Reaction score
1,576
Points
113
Location
Brentwood Bay, BC, Canada
Your Mac's Specs
2011 27" iMac, 1TB(partitioned) SSD, 20GB, OS X 10.11.6 El Capitan
M

MacInWin

Guest
I remember now when there was a dustup in the Interwebz about the KeRanger ransomware. This guy offered his "finder" for that kind of malware then, and apparently has updated it to plug some of the holes in his finder. Don't think it's malicious in itself, but I think Apple has plugged the KeRanger-like holes with SIP. Of course, if you disable SIP...
 

Rod


Joined
Jun 12, 2011
Messages
9,697
Reaction score
1,884
Points
113
Location
Melbourne, Australia and Ubud, Bali, Indonesia
Your Mac's Specs
2021 M1 MacBook Pro 14" macOS 14.4.1, Mid 2010MacBook 13" iPhone 13 Pro max, iPad 6, Apple Watch SE.
It is another thing running in the background, a utility I know, but non the less using resources i wonder that everybody doesn't just use a VPN and Ghostery. You can set your VPN to your real location and still get all of the benefits of anonymity and encryption. I run mine full time now so that I appear to be in my country of origin, thus giving me access to content I would be unable to access from Indonesia but you don't have to do that. The same app runs on my iPhone. I can use my phone for online banking now and I have not had a malware or hacking issue on OSX for years.
 
OP
MightyGem
Joined
Nov 29, 2010
Messages
2,513
Reaction score
134
Points
63
Location
Warrington, UK
Your Mac's Specs
PPC Mini, 10.4.11. Intel Mini, 10.6.8. MacBook Pro, 10.14.6. M1 MBA 11.6.3 iPhone 5 iOS 12.5,
Have you tried to run Malwarebytes?
I have now, thanks. It found a process which I terminated. A restart still produced a popup, but this time I noticed the RansomeWhere? icon in the Dock. Right Click>Options>Show in Finder found it and I deleted it.

Strange that Spotlight and Find Any File couldn't find it though.
 
Joined
Oct 16, 2010
Messages
17,541
Reaction score
1,576
Points
113
Location
Brentwood Bay, BC, Canada
Your Mac's Specs
2011 27" iMac, 1TB(partitioned) SSD, 20GB, OS X 10.11.6 El Capitan
I find that amazing that Find Any File couldn't find anything related. Did you use any copy-paste on any of the associated names…???

Sure not unusual for Spotlight (aka: stoplight) to fail, but sure not Find Any File. :\
 
OP
MightyGem
Joined
Nov 29, 2010
Messages
2,513
Reaction score
134
Points
63
Location
Warrington, UK
Your Mac's Specs
PPC Mini, 10.4.11. Intel Mini, 10.6.8. MacBook Pro, 10.14.6. M1 MBA 11.6.3 iPhone 5 iOS 12.5,
Did you use any copy-paste on any of the associated names…???
No, just the name, RansomeWhere? It found Safari history pages but not the app.
 
Joined
Oct 16, 2010
Messages
17,541
Reaction score
1,576
Points
113
Location
Brentwood Bay, BC, Canada
Your Mac's Specs
2011 27" iMac, 1TB(partitioned) SSD, 20GB, OS X 10.11.6 El Capitan
No, just the name, RansomeWhere? It found Safari history pages but not the app.


If you want to make sure you got rid of all bits and pieces, do a search with FAF for anything containing any of the following:
com.objectiveSee.
RansomWhere (no ? in name)
objectiveSee

and there may be some other files and stuff along where such files are located.

PS: Double check the locations and dates to confirm you've got the correct stuff before Trashing. ;)
 

Rod


Joined
Jun 12, 2011
Messages
9,697
Reaction score
1,884
Points
113
Location
Melbourne, Australia and Ubud, Bali, Indonesia
Your Mac's Specs
2021 M1 MacBook Pro 14" macOS 14.4.1, Mid 2010MacBook 13" iPhone 13 Pro max, iPad 6, Apple Watch SE.
Most associated files are lower case titles so just "ransom" should work with FAF but yes check dates.
 
OP
MightyGem
Joined
Nov 29, 2010
Messages
2,513
Reaction score
134
Points
63
Location
Warrington, UK
Your Mac's Specs
PPC Mini, 10.4.11. Intel Mini, 10.6.8. MacBook Pro, 10.14.6. M1 MBA 11.6.3 iPhone 5 iOS 12.5,

Rod


Joined
Jun 12, 2011
Messages
9,697
Reaction score
1,884
Points
113
Location
Melbourne, Australia and Ubud, Bali, Indonesia
Your Mac's Specs
2021 M1 MacBook Pro 14" macOS 14.4.1, Mid 2010MacBook 13" iPhone 13 Pro max, iPad 6, Apple Watch SE.
SarahJohnMS, thats very true as stated in my post to this thread on the 06/06 but I added Ghostery to the lineup because it stops trackers and you might want to include AdBlock as well.
 
Joined
Jun 14, 2016
Messages
15
Reaction score
0
Points
1
YOU ARE ABSOLUTELY RIGHT Rod Sprague, TRACKERS, SUSPICIOUS LINKS, POP-UPS AND EMAIL SPAMS ARE THE MAIN CULPRITS AND USERS MUST NOT DOWNLOAD OTHER THAN APP STORES Y PPL DUN UNDERSTAND THIS AND JUST CARELESSLY CLICK ANY LINK COMES IN THEIR WAY
 

Shop Amazon


Shop for your Apple, Mac, iPhone and other computer products on Amazon.
We are a participant in the Amazon Services LLC Associates Program, an affiliate program designed to provide a means for us to earn fees by linking to Amazon and affiliated sites.
Top