• This forum is for posting news stories or links from rumor sites. When you start a thread, please include a link to the site you're referencing.

    THIS IS NOT A FORUM TO ASK "WHAT IF?" TYPE QUESTIONS.

    THIS IS NOT A FORUM FOR ASKING QUESTIONS ABOUT HOW TO USE YOUR MAC OR SOFTWARE.

    This is a NEWS and RUMORS forum as the name implies. If your thread is neither of those things, then please find the appropriate forum to ask your question.

    If you don't have a link to a news story, do not post the thread here.

    If you don't follow these rules, then your post may be deleted.

OS X virus!!!!

W

WilliS

Guest
ok... first off, if anyone knows anything about this, or has advice on how to fix this, please let me know.... im not going to go around repairing permissions or doing some crons task... so dont bother suggesting it....im a little tense at the moment, so excuse my slight sarcasm in some of my comments in this post...

this is my issue:

I have a mail account at college (penn state), and just today i recieved 2 messages (see image 1) from some U.S. National Bank or something... anyway, i knew it was fake... and just wanted to see what the link took me to (figuring it was either a funny webpage which asked to you put in your card number/pin on your ATM card, or something silly like that.)

So i opened the email... (see image 2) and that is what it said.

so, i click on the link..which is http://210.118.170.142/swf/ (WARNING... I DO NOT KNOW WHAT THAT SWF FILE DOES, CLICKING ON IT MAY INFECT YOUR COMPUTER)

so..i figured it was a flash file... swf.. but i failed to notice that it was a directory and not just a .swf... so clicking on the link did nothing at all...

notice, there was 2 of these messages... one with that link, and one with the link to the ip address alone... i clicked on the other link, which produced image # 3

ok... now... obviously it was some sort of virus or something... but anyway, it seemed to do nothing (like every other virus ive found... i click them for fun because nothing has ever previously affected mac...so ive tried to open the .exe files and stuff, or send them to my friends on winxp and stuff and laugh at them lol... )

anyway... what now happens is:

i click on a link in my inbox and what displays is image #2.... so i click on some other emails... and what i notice is, the virus switches the link of one email with the next... so i go to click on a message from a friend, and up pops a message from a forum... i click on the message from a forum, and up pops a tracked package from a few weeks ago....i click on the tracked package, and up pops an email from someone else...and so on... each link has a new destination...... although all the emails are still there, the links dont match up to what the title to them says they should be.

holy ****, someone help me!!!!!!!

if someone tells me to repair permissions i will make sure you get a virus! ;) ;) ;) ;) :D

View attachment Picture 3.pdf

View attachment Picture 5.pdf
 

Attachments

  • Picture 1.pdf
    276.5 KB · Views: 44
Joined
Mar 9, 2004
Messages
2,860
Reaction score
21
Points
38
Location
Miami FL
Your Mac's Specs
G4 1Ghz OS X 10.4.7
Get a virus?! Not bloody likey -- I was a doz boy too long! but what you are seeing is very strange but not a doz class virus... But it's quite strange, IP where that came from and such may help
 
OP
W

WilliS

Guest
what are you telling me?

its not a virus? well its something.... go try to load the page with the IP/swf/ and tell me if it messes with your mail account :)... if not, ill forward you the email, and you can give it a shot from there if you would like... but i guarantee you im not hallucinating or anything..and you can deny it all you want, but its on my computer...and i can give it to you to check out if you really want
 
Joined
Mar 9, 2004
Messages
2,860
Reaction score
21
Points
38
Location
Miami FL
Your Mac's Specs
G4 1Ghz OS X 10.4.7
DualG5Lova said:
... if not, ill forward you the email, and you can give it a shot from there if you would like... but i guarantee you im not hallucinating or anything..and you can deny it all you want, but its on my computer...and i can give it to you to check out if you really want
What e-mail client received this?
 
Joined
Mar 9, 2004
Messages
2,860
Reaction score
21
Points
38
Location
Miami FL
Your Mac's Specs
G4 1Ghz OS X 10.4.7
Someone e-mailed you links look to e-mails weeks older? Dude, this has been set up by your "friends" in PSU I bet ;)
 
OP
W

WilliS

Guest
witeshark said:
Someone e-mailed you links look to e-mails weeks older? Dude, this has been set up by your "friends" in PSU I bet ;)

1. you misread what i said, whatever this "virus" (for lack of a better word) did to my mail, what is obvious that it did was scrambled my messages.... you know how you click on the email after reading the subject? and expect to get an email pertaining to that subject? well, its not...

2. none of my "friends" at psu could manage to do anything like this.. for one thing, its a big time offence to do what the phish was intended to do... which was make an email that collects bank information... the email was obviously set up to have you enter in your account information to a website that looked identical to a bank website, but instead of send it to the bank, it would just collect it and send it to the maker of the virus.

3. unless you have anything important to say, im not in the mood to hear the "repair permissions and crons tasks" lecture, nor in the mood to explain that yes, it really is a problem... the "big bad osx fortress" isnt so hard to break into when i clicked on the link.. pretty much saying "hey! hack me plz!"..... so i would rather hear something from someone who may have stumbled upon this somewhere on the web, or had this same thing happen to them, rather than the possibilities of my friends breaking through osx..

no offense...but currently im in the "instant gratification" mode... if you cant help me fix it, i really dont care to hear the stories of the "doz dayz"
 
Joined
Jul 21, 2003
Messages
1,185
Reaction score
16
Points
38
Location
Coruscant, Galactic Republic
Your Mac's Specs
14" iBook G3 900/640/40 _ _ Power Macintosh G3 All-In-One 315/768/20 _ _ 20 GB iPod
DualG5Lova said:
to add to the fun... the emails will not delete off the server

I can imagine how frustrating something like that must be. My only to suggestions would be:

A) Make sure no one else on campus is experiencing similar problems, thus indicating a problem/infection with the server itself.

B) Purchase a Mac-specific anti-virus application. If there is indeed a virus infecting your machine, it will be difficult to remedy without such an application.

"C" would be to perform a complete format and reinstall of the OS, which is obviously a last resort.

BTW - This is completely unrelated, but you wouldn't happen to know a girl by the name of Jennifer Curley that attends your school, would you?
 
Joined
Nov 4, 2003
Messages
654
Reaction score
11
Points
18
Location
Southern Indiana
Your Mac's Specs
Mac Pro Quad Xeon 2.66GHz 3GB RAM, G4 Quicksilver w/Sonnet 1GHz Encore ST, 1ghz G4 Powerbook
…and "D" BACKUP! BACKUP! BACKUP! (or is that D, E and F?)
 
Joined
Apr 9, 2004
Messages
973
Reaction score
4
Points
18
Location
Dubai
Your Mac's Specs
15" MBP 2.16GHz ^ATI Radeon X1600 256MB ^100GB @ 7200 rpm ^2GB RAM ^Glossy Screen +iPod 4G 20 gigs
Talk to ur admin and see what he has to say. Good luck.
 
OP
S

StarManta

Guest
....um, what do you have against repairing permissions? This seems to me exactly the sort of problems that that would fix.

That IP address isn't giving me any info on Network Utility's Whois, and it didn't respond when I clicked it... so whatever that was it's probably down.

It sounds more like your mail itself got corrupted somehow, rather than Mail.app.
 
OP
W

WilliS

Guest
i woke up this morning, after putting my G5 to sleep last night... when i hit the space bar, horizantal pink lines took up the entire screen... so i turned the computer off... then i powered it back up, and nothing worked... it was on, but no display.... i went and took a shower, came back, powered it on again, and its working....

i have no clue whats wrong.

btw... what i have against repair permissions is that it seems to be everyones solution to everything :p... "oh your getting bad grades in school? try repairing permissions on your ibook..that might help"

anyway... i have repaired them...did not help

whatever it is, not only is on the server side, messing up my emails, but also on my side, affecting my computer in some weird way.

and no, i dont know jennifer.. sorry hehe
 
Joined
Aug 5, 2003
Messages
1,246
Reaction score
0
Points
36
Location
I'm slowly sinking in the posts of Mac-forums
Your Mac's Specs
PowerBook 12" Combo Drive/867 MHz/256 MB RAM/40 GB hard drive/Mac OS X 10.3.5/AirPort Extreme it sux
What the **** are you smoking? There are no Mac OS X viruses were not on doz! It's just a permission's issue. Repair your permissions and run cron tasks, it's just a fault!

No one says that... ever.
 
Joined
Jul 22, 2003
Messages
6,999
Reaction score
187
Points
63
Location
Hamilton College
Your Mac's Specs
20" iMac C2D 2.16ghz, 13" MacBook 2.0ghz, 60gb iPod vid, 1gb nano
I just tried the page and nothing is loading on it
 
Joined
Aug 5, 2003
Messages
1,246
Reaction score
0
Points
36
Location
I'm slowly sinking in the posts of Mac-forums
Your Mac's Specs
PowerBook 12" Combo Drive/867 MHz/256 MB RAM/40 GB hard drive/Mac OS X 10.3.5/AirPort Extreme it sux
Umm, to those who PMed me saying "OMG NO ONE EVER SAYS THAT?!?! HAVE U SEEN HALF OF WHITESHARKS POSTS?!!?", it was sarcasm.
 
Joined
Mar 9, 2004
Messages
2,860
Reaction score
21
Points
38
Location
Miami FL
Your Mac's Specs
G4 1Ghz OS X 10.4.7
So is this issue cleared up? I never saw anything malicious happen when I looked at the attachments... Hope it's all done! Any word as to what it was?
 
OP
W

WilliS

Guest
i dunno... i deleted all of my emails, and the ones which wouldnt delete before, finally deleted... of course, ive never seen pink lines run across my screen before... so i would have to say that was an affect of whatever i have been infected with... of course, it was only after my G5 was asleep all night

anyway... i havent SEEN anything today... and i have no mail left in my mailbox.. lol... the virus could very well be on my system though...doing things right before my eyes...and i cant even see it....

its there, im sure :p... i just dont have a clue what its doing
 
Joined
Mar 9, 2004
Messages
2,860
Reaction score
21
Points
38
Location
Miami FL
Your Mac's Specs
G4 1Ghz OS X 10.4.7
I have read about that pink lines thing before, the one I read about did not involve a virus, but I'm not sure what it turned out to be If in the wost case you do a full reinstall... well who knows...
 
Joined
Aug 5, 2003
Messages
1,246
Reaction score
0
Points
36
Location
I'm slowly sinking in the posts of Mac-forums
Your Mac's Specs
PowerBook 12" Combo Drive/867 MHz/256 MB RAM/40 GB hard drive/Mac OS X 10.3.5/AirPort Extreme it sux
witeshark said:
I have read about that pink lines thing before, the one I read about did not involve a virus, but I'm not sure what it turned out to be If in the wost case you do a full reinstall... well who knows...
Yeah, umm, I don't want to meantion my dead iMac that shows pink lines when you boot OS X...
...oops. I did. Damnit.
 

Shop Amazon


Shop for your Apple, Mac, iPhone and other computer products on Amazon.
We are a participant in the Amazon Services LLC Associates Program, an affiliate program designed to provide a means for us to earn fees by linking to Amazon and affiliated sites.
Top