I have a Mac Trojan

Joined
Sep 28, 2007
Messages
43
Reaction score
2
Points
8
I think I've come across a real Mac trojan,disguised an an application.

It automatically opens every application on your Mac forcing it to crash.

Can you guys verify this is a new Trojan ? Who can I send it to for testing or verification ?

It's a ZIP file, and an application in the file called Mudskipp.
 
Joined
Dec 18, 2005
Messages
2,288
Reaction score
51
Points
48
Location
Devon, England
Your Mac's Specs
ibook g4, imac 2ghz c2d, mbp 2.4ghz c2d - 10.5.1
does it do it on another account ?
 
OP
M
Joined
Sep 28, 2007
Messages
43
Reaction score
2
Points
8
Sorry didn't understand what you mean ... it opens all apps immediately, and so far with all friends who've tried it, it works.

It looks like a cute game icon, but when it's clicked it happens.

Can I post it here for you people to verify this thing ?

I thought there were no trojans for Mac .. I think it's an automator action hidden in an application.
 
Joined
Dec 18, 2005
Messages
2,288
Reaction score
51
Points
48
Location
Devon, England
Your Mac's Specs
ibook g4, imac 2ghz c2d, mbp 2.4ghz c2d - 10.5.1
go to system preferences.

accounts

create a new account and see if the programs still open all at once on it.
call it test account or something.

I highly doubt its a trojan and I dont think there are any. As you said its probably an automator action which has gone wrong.
 
Joined
Nov 26, 2004
Messages
913
Reaction score
38
Points
28
Location
Oklahoma
Sorry didn't understand what you mean ... it opens all apps immediately, and so far with all friends who've tried it, it works.

It looks like a cute game icon, but when it's clicked it happens.

Can I post it here for you people to verify this thing ?

I thought there were no trojans for Mac .. I think it's an automator action hidden in an application.

Well ya..... when you click on it that gives it permission to run. I don't think there are any out there for the mac that can auto run theirselves, you have to give it permission to do so. Any one can write a program for any platform that will do that, the trick is for it to do it on its own hook.
 
Joined
Dec 18, 2005
Messages
2,288
Reaction score
51
Points
48
Location
Devon, England
Your Mac's Specs
ibook g4, imac 2ghz c2d, mbp 2.4ghz c2d - 10.5.1
check in automator for a script that is running this. or delete the program that is running this.
 
OP
M
Joined
Sep 28, 2007
Messages
43
Reaction score
2
Points
8
Well, it doesn't ask for a password just runs .. and it's disguised as some kind of game application when it's really an automator action .. I think that's the definition of a Trojan.

I'm sending it to Apple and uploaded it here for testing -- it's not dangerous other than just opening all apps, hope some more tech dudes can analyze it further -
 
Joined
Mar 9, 2004
Messages
9,065
Reaction score
331
Points
83
Location
Munich
Your Mac's Specs
Aluminium Macbook 2.4 Ghz 4GB RAM, SSD 24" Samsung Display, iPhone 4, iPad 2
It doesn't actually do anything on my system, apart from launch an Automator "Watch me do" script which just causes the system to beep twice.

I'd guess it does something along the lines of "Switch to Finder, hit Shift+Command+A to bring up the apps folder, hit "Command+A" to select all apps, hit "Command+O" to open all applications.

But it could very easily do more damage. (e.g. Command+A to select all apps and then Shift+Command+Backspace to any apps that aren't currently open - assuming you're an Administrator) so watch out what Apps you download from the internet and run.
 
OP
M
Joined
Sep 28, 2007
Messages
43
Reaction score
2
Points
8
That sounds dangerous -- shouldn't Apple make it so Mac OS X automatically doesn't run external scripts without permission/password, for the moving apps to trash can example, that would be really bothersome, as you can't restore apps to their original location with a 'restore' option and have to manually move them back.

Apple need to fix this i think.
 
M

MacHeadCase

Guest
How did this script get on your Mac in the first place? Why did you install it? Where did you get it?

I know I don't click on something unless I know what it's doing on my Mac.
 
Joined
Nov 2, 2006
Messages
476
Reaction score
9
Points
18
Your Mac's Specs
24" 2.8ghz IMAC, MB Pro
If you really think you have a virus you submit it to an anti virus company like Symantec or McAfee you don't attempt to spread it to other users on a mac forum. If you ask me you should be banned for trying to spread the program. I believe personally that you made this script yourself and are trying to see if you can manage to get it distributed.

Guess what? A little automator script ISN"T a virus or a trojan. No matter what you name the file or what icon you give it.
 
Joined
Apr 20, 2006
Messages
2,255
Reaction score
47
Points
48
Your Mac's Specs
Al iMac 20" 2.4Ghz Intel Core 2 Duo
A Trojan digs itself into the system, on the back of a legitimate looking program, without your knowledge.

You have a single program which just doesn't do what the filename says.
 
OP
M
Joined
Sep 28, 2007
Messages
43
Reaction score
2
Points
8
Are you kidding me ? Before making mindless accusations, I never said it was a virus, I mentioned it only opened all apps and nothing more, and I don't have the abilities to even know how to make an automator script.

A friend sent it to me saying it was a game and when i tried it found out, and told him there were no trojans on a mac and he says no there is, and this is one.
 
Joined
Nov 5, 2007
Messages
985
Reaction score
31
Points
28
Your Mac's Specs
Black MacBook- 2.2GHz, 1gb RAM, 160GB, Double-Layer Superdrive.
It's not really a trojan, it's just some automator script with a pretty icon...
 
OP
M
Joined
Sep 28, 2007
Messages
43
Reaction score
2
Points
8
how do i remove the download ??

Doesn't do much but maybe its just best the pros look at it, not sure who exactly to send it to to study it.
 
Joined
Nov 2, 2006
Messages
476
Reaction score
9
Points
18
Your Mac's Specs
24" 2.8ghz IMAC, MB Pro
You drag it to your trash. Also you may consider not using your mac from an admin account.
 
Joined
Mar 9, 2004
Messages
9,065
Reaction score
331
Points
83
Location
Munich
Your Mac's Specs
Aluminium Macbook 2.4 Ghz 4GB RAM, SSD 24" Samsung Display, iPhone 4, iPad 2
That sounds dangerous -- shouldn't Apple make it so Mac OS X automatically doesn't run external scripts without permission/password, for the moving apps to trash can example, that would be really bothersome, as you can't restore apps to their original location with a 'restore' option and have to manually move them back.

Apple need to fix this i think.
OS X warns you before you launch the script as it was downloaded from the internet.

If it asked you for the password AFTER you already agreed to launching it, it would be fairly pointless a you'd be just as willing to type it in. Plus then you start getting into Vista territory.

You will be asked to delete apps if you run as a regular user - that's the risk of being logged in as an admin all the time.
Restoring the applications is just a matter of dragging them back out of the trash.

If the script wanted to do something really malicious to your system files, it would have to ask you for a password.
 
OP
M
Joined
Sep 28, 2007
Messages
43
Reaction score
2
Points
8
That's a relief. I deleted the link anyway.

Looks like a harmless prank ,, but its worrying as a social engineering tool ,,
 
Joined
Nov 5, 2007
Messages
985
Reaction score
31
Points
28
Your Mac's Specs
Black MacBook- 2.2GHz, 1gb RAM, 160GB, Double-Layer Superdrive.
how do i remove the download ??

Doesn't do much but maybe its just best the pros look at it, not sure who exactly to send it to to study it.

No one needs to study it just put it in the trash it's just some automator script that anyone who can use automator could make.
 

Shop Amazon


Shop for your Apple, Mac, iPhone and other computer products on Amazon.
We are a participant in the Amazon Services LLC Associates Program, an affiliate program designed to provide a means for us to earn fees by linking to Amazon and affiliated sites.
Top