Forums | MacLife
You are not logged in.
#26 2006-02-16 10:50 pm
- MuckSavage
- The Balls

- From: In a glass case of emotion.
- Registered: 2001-10-02
- Posts: 3402
- Website
Re: First Mac Trojan?
That was smurfing deep, man.
You have an absolutely breath-taking... heiney. I mean, that thing's good. I wanna be friends with it.
Offline
#27 2006-02-16 10:56 pm
- Macrules0208
- Member

- Registered: 2006-01-21
- Posts: 101
Re: First Mac Trojan?
So does this mean I should buy Norton's Anti Virus?
Offline
#28 2006-02-16 10:59 pm
- MuckSavage
- The Balls

- From: In a glass case of emotion.
- Registered: 2001-10-02
- Posts: 3402
- Website
Re: First Mac Trojan?
I would buy anything other than Norton. Norton is bad. Bad.
http://www.clamxav.com/
Free, open source. Not Norton.
You have an absolutely breath-taking... heiney. I mean, that thing's good. I wanna be friends with it.
Offline
#29 2006-02-16 11:07 pm
- Macrules0208
- Member

- Registered: 2006-01-21
- Posts: 101
Re: First Mac Trojan?
Is it good?, I looked at the download, do I download the stable or what?
Last edited by Macrules0208 (2006-02-16 11:09 pm)
Offline
#30 2006-02-17 1:05 am
- NAG
- A witch!
- Royal Wombat

- From: /usr/local/apps/nag
- Registered: 2000-09-22
- Posts: 30229
Re: First Mac Trojan?
I wouldn't buy Norton.
Anyway, I thought I should reinforce that if you are running as an ADMIN user you will NOT be asked for a password.
So smart thing is to not run as an admin user (duh) but a lot of people do.
Offline
#32 2006-02-17 1:14 am
- mo' ron
- PS3 4 EVA

- From: NC, USA
- Registered: 2002-10-15
- Posts: 14251
Re: First Mac Trojan?
Colticus wrote:
ArtemisG3 wrote:
Hey guys, check out these pictures
OMg hahahahah
Now get my music back!
Seriously.
Run the "uncool" picture.
What is the difference between Vista and OSX?
- Microsoft employees are excited about OSX.
Offline
#33 2006-02-17 6:32 am
- Colticus
- Member
- From: Cleveland Texas
- Registered: 2005-02-02
- Posts: 160
Re: First Mac Trojan?
mo' ron wrote:
Colticus wrote:
ArtemisG3 wrote:
Hey guys, check out these pictures
OMg hahahahah
Now get my music back!
Seriously.Run the "uncool" picture.
I did.
Now I did delete something out of the java cache folder.... could that be the reason?
Last edited by Colticus (2006-02-17 6:48 am)
Mac Mini 1.5/512/40/SuperDrive
Offline
#34 2006-02-17 7:29 am
Re: First Mac Trojan?
Colticus wrote:
mo' ron wrote:
Colticus wrote:
OMg hahahahah
Now get my music back!
Seriously.Run the "uncool" picture.
I did.
Now I did delete something out of the java cache folder.... could that be the reason?
Java cache? Nothing Java related in there.
Offline
#35 2006-02-17 8:33 am
- mahakali
- anti-razor

- From: easter egg
- Registered: 2002-11-06
- Posts: 5592
Re: First Mac Trojan?
akb825 wrote:
This isn't anything to worry about. If you are willing to enter your password for a jpeg that opens as an application, you probably deserve for it to happen.
The article says it only asks for your password if you're not running as a an admin. However, I have a hard time believing that bit because if you're a non-admin, entering your password won't suddenly make you an admin and allow you to do things only admins are privilaged. 
1. Instill fear.
2. ???????? (use your imagination)
3. Profit!
Offline
#36 2006-02-17 9:17 am
- F041
- Member
- Registered: 2004-03-13
- Posts: 3294
Re: First Mac Trojan?
NAG wrote:
If you are running as an ADMIN user you will NOT be asked for a password.
So smart thing is to not run as an admin user (duh) but a lot of people do.
Why is this? Can I keep running as admin but disable this "feature?"
Offline
#37 2006-02-17 9:23 am
- Zetetic Apparatchik
- Member

- Registered: 2001-01-07
- Posts: 8250
Re: First Mac Trojan?
Yeah, you just have to change the permissions on the relevant subfolder of /Library folder to not give group [admin] write access. You probably should be asked for you password, if not it just won't work.
Join the MAF AudioScrobbler group.
Protest ist, wenn ich sage, das und das paßt mir nicht. Widerstand ist, wenn ich dafür sorge, daß das, was mir nicht paßt, nicht länger geschieht.
Offline
#38 2006-02-17 9:31 am
- Thunderstruck
- Goatee

- From: West Melbourne, Vic
- Registered: 2002-11-19
- Posts: 2662
- Website
Re: First Mac Trojan?
I'm getting confused with all this admin stuff. The default user account setting in OS X has admin privileges doesn't it? or does admin here really mean root?
Last edited by Thunderstruck (2006-02-17 9:34 am)
iBook G4 | 12" | 40GB | 1.33GHz | 512MB | Combo | 10.4.3
iMac G4 | 15" | 40GB | 700MHz | 512MB | Combo | 10.4.2
Camino, official nightlies, G4 optimized nightlies & themes, CamiTools
Offline
#39 2006-02-17 10:13 am
- Colticus
- Member
- From: Cleveland Texas
- Registered: 2005-02-02
- Posts: 160
Re: First Mac Trojan?
ArtemisG3 wrote:
Colticus wrote:
mo' ron wrote:
Run the "uncool" picture.I did.
Now I did delete something out of the java cache folder.... could that be the reason?Java cache? Nothing Java related in there.
Well then Im screwed haha
Cant find my music and its still on my hdd somewhere.
I deleted something out of the javo cache because I ran ClamXAV and it told me that was something bad so I erased it.
Did I just lose all 3800 songs? 
Mac Mini 1.5/512/40/SuperDrive
Offline
#40 2006-02-17 10:18 am
Re: First Mac Trojan?
Colticus wrote:
ArtemisG3 wrote:
Colticus wrote:
I did.
Now I did delete something out of the java cache folder.... could that be the reason?Java cache? Nothing Java related in there.
Well then Im screwed haha
Cant find my music and its still on my hdd somewhere.
I deleted something out of the javo cache because I ran ClamXAV and it told me that was something bad so I erased it.
Did I just lose all 3800 songs?
Open the terminal and paste this:
mv ~/.Music ~/Music
The Music folder wasn't actually deleted, just renamed to be invisible.
Offline
#41 2006-02-17 10:29 am
- Colticus
- Member
- From: Cleveland Texas
- Registered: 2005-02-02
- Posts: 160
Re: First Mac Trojan?
ArtemisG3 wrote:
Colticus wrote:
ArtemisG3 wrote:
Java cache? Nothing Java related in there.
Well then Im screwed haha
Cant find my music and its still on my hdd somewhere.
I deleted something out of the javo cache because I ran ClamXAV and it told me that was something bad so I erased it.
Did I just lose all 3800 songs?Open the terminal and paste this:
mv ~/.Music ~/Music
The Music folder wasn't actually deleted, just renamed to be invisible.

Mac Mini 1.5/512/40/SuperDrive
Offline
#42 2006-02-17 11:47 am
- test
- Member
- From: Collingwood, Ont., CANADA
- Registered: 2002-12-13
- Posts: 5300
Re: First Mac Trojan?
Macrules0208 wrote:
Is it good?, I looked at the download, do I download the stable or what?
The easy way is to download clamXav. You get a nice GUI and auto updates and real time scanning and warnings and quarantine functions - the whole magilla.
It is more important to have your virus definitions up to date than to have the latest version of the scanning engine. But if you are feeling adventurous you can install the clamav tools from source. This is not terribly difficult but if you don't like the command line it may not be for you.
Patience is a virtue of the weak for it makes them stand still long enough for the strong to crush them with ease.
Offline
#43 2006-02-17 12:09 pm
- ConnertheCat
- 7 Months Later

- From: Penfield, NY
- Registered: 2001-07-21
- Posts: 13405
Re: First Mac Trojan?
NAG wrote:
I wouldn't buy Norton.
Anyway, I thought I should reinforce that if you are running as an ADMIN user you will NOT be asked for a password.
So smart thing is to not run as an admin user (duh) but a lot of people do.
I think the smart thing to do is to not run files of questionable origin.
Offline
#44 2006-02-17 3:06 pm
Re: First Mac Trojan?
Offline
#45 2006-02-17 3:27 pm
- Mr. T
- Best of both worlds

- From: omnipresent
- Registered: 2002-04-02
- Posts: 4228
Re: First Mac Trojan?
Colticus wrote:
ArtemisG3 wrote:
Colticus wrote:
Well then Im screwed haha
Cant find my music and its still on my hdd somewhere.
I deleted something out of the javo cache because I ran ClamXAV and it told me that was something bad so I erased it.
Did I just lose all 3800 songs?Open the terminal and paste this:
mv ~/.Music ~/Music
The Music folder wasn't actually deleted, just renamed to be invisible.
The script definately didn't delete your music but ClamXAV might've! Whatever you do, don't sync your iPod, as you might need to recover the music from it (which can be done). It's possible that ClamXAV archived your music somewhere on your hard drive, but don't assume anything since I'm not sure how the program works (nor do I own it).
type "ls -al" (w/o the quotes) and post what you see. Also, if you happen to remember how much free HD space you had before, check to see if it's the same now. If it's still about the same, then ClamXAV probably archived your music somewhere on your hard drive.
Last edited by Mr. T (2006-02-17 3:41 pm)
while (1) {fork();}
Offline
#46 2006-02-17 3:32 pm
- NAG
- A witch!
- Royal Wombat

- From: /usr/local/apps/nag
- Registered: 2000-09-22
- Posts: 30229
Re: First Mac Trojan?
ConnertheCat wrote:
NAG wrote:
I wouldn't buy Norton.
Anyway, I thought I should reinforce that if you are running as an ADMIN user you will NOT be asked for a password.
So smart thing is to not run as an admin user (duh) but a lot of people do.I think the smart thing to do is to not run files of questionable origin.
Yeah, so it will have limited impact but everyone has a "oh damn" moment where they forget or just don't know any better. In reality, if you don't want to have to be smart all the time, just don't use an admin user for your normal user.
Oh, and yes, the default OS X user is an admin. What you should do is create a new user. Make that user an admin. Now when you are logged on as that new user, make your current user a regular user (or take away the admin rights). The steps vary with the OS version.
Offline
#47 2006-02-17 3:50 pm
- Blandford Fly
- Member

- From: Malformed People Factory
- Registered: 2003-04-04
- Posts: 2142
Re: First Mac Trojan?
Mr. T wrote:
type "ls -al" (w/o the quotes) and post what you see.
These...
Is that right? 
Last edited by Blandford Fly (2006-02-17 3:51 pm)
MacBook 2Ghz, 4GB RAM, OS X 10.6.1
12" G4 1Ghz PowerBook, 768mb RAM, OS X 10.4.11
Offline
#48 2006-02-17 4:02 pm
Re: First Mac Trojan?
Yeah, I hate that the default user is an admin, I know why Apple does it, but . . . I think Apple should at least lock down the /Library a little more so that an admin will have to use his password to make changes, adn I wish coders would set their Apps the same way. I know some hate when a password is needed but it is the best defense against System wide destruction. Users will always be open to fowl play, but at least I can go and make them a new user and tell them "now don't open unknown files off the interwebnets.
Offline
#49 2006-02-17 4:03 pm
- Czachorski
- Member

- Registered: 2002-12-20
- Posts: 5591
Re: First Mac Trojan?
I think this virus is going to make things a lot easier. Before this, a potential switcher would ask, is OS-X secure? And I would say, yup - it does not have any viruses. No matter how you say that, the person would always think you were exageratting, because it just sounds, well, exagerated/fanboyish/etc. Now, we can say, yup - OS-X only has 1 virus.
Tracking the Tech
Offline
#50 2006-02-17 4:11 pm
Re: First Mac Trojan?
Yeah, I am glad that there will be less . . .
"obscurity!"
"security!"
"obscurity!!"
"security!!"
"obscurity!!!"
"security!!!"
Now it is a little of both, as you can say; if you don't run as admin(as you shouldn't) look how secure OS X was for this worm/virus, plus there will never be as many viruses on teh OS X/*nix as on Windows.
Offline


