Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Software - Troubleshooting and Discussion > Mac OS X > 'OSX.RSPlug.A.postflight' Trojan?

'OSX.RSPlug.A.postflight' Trojan?
Thread Tools
Dedicated MacNNer
Join Date: Oct 2003
Location: London UK
Status: Offline
Reply With Quote
Mar 31, 2008, 10:48 AM
 
Hi there,
First of all, i hope this is in the correct forum - and my apologies if not!

I have just scanned my system (10.5.2) with both ClamXav and then VirusBarrier X4 and the above 'Trojan Horse infection' was thrown up as "postugrade is infected by 'OSX.RSPlug.A.postflight'".
Also thrown up was "'postinstall' is infected by 'OSX.RSPlug.A.postflight'".

Would anyone know what OSX.RSPlug.A.postflight is and how can I get rid of it?
Plus, would anyone know what 'postinstall' and postupgrade' is?
As usual - all help is gratefully received!
best
voicebox
"If you don't like the heat, don't go in the kitchen!"
17" Core2duo MacBook Pro 2.4Ghz 4Gb/160HD Snow Leopard 10.6.8 || 15" PowerBook 1Gz 1Gb/120 HD Tiger 10.4.11|| 24" iMac 3.06Gz 4Gb/1TB HD Lion 10.7.2
     
Clinically Insane
Join Date: Jun 2001
Location: planning a comeback !
Status: Offline
Reply With Quote
Mar 31, 2008, 11:02 AM
 
Congratulations

You are among the few elite Mac users that managed to get infected by a trojan.

Or, in other words, you got PWNED !

Here's some info and how to remove it:
2007 October | Geek stuff

-t
     
Addicted to MacNN
Join Date: Aug 2004
Location: FFM
Status: Offline
Reply With Quote
Mar 31, 2008, 11:04 AM
 
When a pornsite asks you to install something, don't do that in the future. Only install software you acquired directly from trusted sources. postupgrade and postinstall are scripts within an installer package that are run during installation. It seems you have this installer package that installs the trojan still lying around. Trash it. Also check whether you installed the trojan. I found more info about this in this article:

Macworld | First Look: Trojan Horse warning: What you need to know
     
Addicted to MacNN
Join Date: Mar 2006
Status: Offline
Reply With Quote
Mar 31, 2008, 11:14 AM
 
Ironic that on porn sites you have to be careful of trojans.
     
Mac Elite
Join Date: Oct 1999
Location: Montréal, Québec (Canada)
Status: Offline
Reply With Quote
Mar 31, 2008, 12:37 PM
 
Originally Posted by peeb View Post
Ironic that on porn sites you have to be careful of trojans.
     
Mac Elite
Join Date: Aug 2007
Status: Offline
Reply With Quote
Mar 31, 2008, 12:38 PM
 
Go porn!
MacBook Pro 13" 2.8GHz Core i7/8GB RAM/750GB Hard Drive - Mac OS X 10.7.3
     
Dedicated MacNNer
Join Date: Oct 2003
Location: London UK
Status: Offline
Reply With Quote
Mar 31, 2008, 05:03 PM
 
Originally Posted by turtle777 View Post
Congratulations

You are among the few elite Mac users that managed to get infected by a trojan.

Or, in other words, you got PWNED !

Here's some info and how to remove it:
2007 October | Geek stuff

-t
Thank you boys and girls(?) for all for your replies, and to you turtle777 and TETENAL - but I have to tell you all that I have never visited a porn site in my life.... although I may know of a small person or persons who has/have.....!!

A good rule: "Never ever turn your back on nephews & nieces in your family when you allow them to use your laptop during Sunday Lunch" ....!!
Yet another rule: "Never EVER let nephews and nieces use your laptop during Sunday Lunch"....
I am afraid I broke both rules!!
Thanks guys - I'll try the fix ...!!
"If you don't like the heat, don't go in the kitchen!"
17" Core2duo MacBook Pro 2.4Ghz 4Gb/160HD Snow Leopard 10.6.8 || 15" PowerBook 1Gz 1Gb/120 HD Tiger 10.4.11|| 24" iMac 3.06Gz 4Gb/1TB HD Lion 10.7.2
     
Addicted to MacNN
Join Date: Aug 2004
Location: FFM
Status: Offline
Reply With Quote
Mar 31, 2008, 05:05 PM
 
---> Guest Account!
     
Fresh-Faced Recruit
Join Date: Jan 2008
Status: Offline
Reply With Quote
Mar 31, 2008, 05:10 PM
 
Hey, voicebox. There is a good possibility that the trojan didn't get installed since it would require an administrator name and password, but it would still be a good idea read the link turtle777 posted and check your DNS settings and root crontab.
(Last edited by geekjon; Mar 31, 2008 at 05:11 PM. (Reason:more info))
     
Addicted to MacNN
Join Date: Mar 2006
Status: Offline
Reply With Quote
Mar 31, 2008, 05:53 PM
 
The DNS settings grey thing seems to be bogus. There are other reasons for grayed DNS entries.
     
Banned
Join Date: Jun 2003
Status: Offline
Reply With Quote
Mar 31, 2008, 07:08 PM
 
That trojan requires an admin password I believe. This is something your nephew/niece wouldn't be able to install...but you would be able to install it.
     
Grizzled Veteran
Join Date: Mar 2004
Status: Offline
Reply With Quote
Mar 31, 2008, 11:46 PM
 
Here's a slightly more in-depth study (more recent as well):
As it mentions at the end:
Later versions of this trojan scripts are obfuscated, making it a little difficult
for security analyst and researchers to read the code.
 
Though not conclusive, if you run cat /etc/resolv.conf in Terminal, and see nameserver addresses starting with 85.255.x.x
-- those are known undesirable domains of late... among way <<too many>> others, unfortunately.

Along with tons of Cnet and PCWorld type coverage, here is some more obscure linkage:
-HI-
     
Dedicated MacNNer
Join Date: Oct 2003
Location: London UK
Status: Offline
Reply With Quote
Apr 1, 2008, 02:43 AM
 
Originally Posted by Horsepoo!!! View Post
That trojan requires an admin password I believe. This is something your nephew/niece wouldn't be able to install...but you would be able to install it.
Thank you Horsepoo!!! for your input!
You may be interested to know - along with all you other guys - that my nephew has confessed!! Like many of his ilk he said he only did it as a joke ......
Well he would wouldn't he?!!
He also said that when the 'package' was being downloaded, VirusBarrier alerted him to the fact that there was a virus and that the admin password window flashed up three times - he panicked but he managed to get rid of that by hitting the 'Repair' button in VirusBarrier a few times...
The .dmg file appeared on the desktop so he trashed it and emptied the trash!(how thoughtful) In fact, it appears that the package 'Could not be Installed.' Good old Intego and VirusBarrier X4!
TETENAL and turtle777- thank you for the links, the Terminal fix contained therin worked, so everything is now OK. And to Hal Itosis, thank you for your input - the links make interesting reading!
Meanwhile .... For Sale - 1 Nephew with a slightly flawed sense of humour - going cheap ...
Any takers?
best
voicebox
"If you don't like the heat, don't go in the kitchen!"
17" Core2duo MacBook Pro 2.4Ghz 4Gb/160HD Snow Leopard 10.6.8 || 15" PowerBook 1Gz 1Gb/120 HD Tiger 10.4.11|| 24" iMac 3.06Gz 4Gb/1TB HD Lion 10.7.2
     
Addicted to MacNN
Join Date: Oct 2001
Location: Automatic
Status: Offline
Reply With Quote
Apr 1, 2008, 11:11 AM
 


"That plane's dustin' crops where there ain't no crops."
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 05:24 AM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2