Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Software - Troubleshooting and Discussion > Mac OS X > did I thwart this attack?

did I thwart this attack?
Thread Tools
Dedicated MacNNer
Join Date: May 2005
Status: Offline
Reply With Quote
Jun 10, 2009, 10:01 PM
 
I suspected that I downloaded one of the mac trojans that exist. I think I thwarted the attack, but I wanted to be sure:

A disk image downloaded and mounted, and then the typical installer screen popped up. I quit the installer screen before I was prompted for anything. I did not enter in a password.

I checked for any unusual processes running...nothing found.

I checked the console and searched for the time when this occurred. There was no mention of an Installer. I just see .dotmacsyncclient, applelaunchd, and a 'connection failed' error for Safari.

I checked these both before and after a restart of my computer. Currently I am running a VirusBarrier X5 scan with definitions from 05/05/09. It is at 56% and nothing found yet.

Is there anything else I should check?
PB12 / 1.5 / 80 / 1.25 / SD
     
cgc
Mac Elite
Join Date: Mar 2003
Location: Virginia
Status: Offline
Reply With Quote
Jun 10, 2009, 10:09 PM
 
Do you expect the virus to be named "EvilVirusDoingBadThingsToYourMac.app"? I'd name a virus something that looks like it belongs.

I'd recommend installing Little Snitch or another two-way firewall and monitor outgoing connections...
     
Posting Junkie
Join Date: Dec 2000
Status: Offline
Reply With Quote
Jun 10, 2009, 10:50 PM
 
Wouldn't you want to run the virus scan with more recent definitions than last month's?

Ticking sound coming from a .pkg package? Don't let the .bom go off! Inspect it first with Pacifist. Macworld - five mice!
     
Moderator
Join Date: Dec 2000
Location: Polwaristan
Status: Offline
Reply With Quote
Jun 11, 2009, 12:22 AM
 
Your first mistake was allowing the DMG to auto-mount.
     
Clinically Insane
Join Date: Nov 1999
Location: 888500128, C3, 2nd soft.
Status: Offline
Reply With Quote
Jun 11, 2009, 02:22 AM
 
Originally Posted by warra View Post
A disk image downloaded and mounted, and then the typical installer screen popped up. I quit the installer screen before I was prompted for anything. I did not enter in a password.
End of story.

Everyone lives happily ever after.
     
JKT
Professional Poster
Join Date: Jan 2002
Location: London, UK
Status: Offline
Reply With Quote
Jun 11, 2009, 03:10 AM
 
Turn off Open "safe" files after downloading and its equivalent in every browser you use. The world's most stupid, yet still active by default, option.
     
warra  (op)
Dedicated MacNNer
Join Date: May 2005
Status: Offline
Reply With Quote
Jun 11, 2009, 08:36 AM
 
Originally Posted by CharlesS View Post
Wouldn't you want to run the virus scan with more recent definitions than last month's?
I just downloaded the trial edition of VirusBarrier. it wouldn't let me install the latest definitions.


I turned off that option in Safari, and did the same for Firefox.

Thanks everyone.
PB12 / 1.5 / 80 / 1.25 / SD
     
warra  (op)
Dedicated MacNNer
Join Date: May 2005
Status: Offline
Reply With Quote
Jun 11, 2009, 04:09 PM
 
could something like this affect the iphone (2.2)? of course...no disk images, but any trojans or viruses?
PB12 / 1.5 / 80 / 1.25 / SD
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 01:49 PM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2