Forums | MacLife
You are not logged in.
#51 2006-02-17 5:13 pm
- Colticus
- Member
- From: Cleveland Texas
- Registered: 2005-02-02
- Posts: 160
Re: First Mac Trojan?
Mr. T wrote:
Colticus wrote:
ArtemisG3 wrote:
Open the terminal and paste this:
mv ~/.Music ~/Music
The Music folder wasn't actually deleted, just renamed to be invisible.The script definately didn't delete your music but ClamXAV might've! Whatever you do, don't sync your iPod, as you might need to recover the music from it (which can be done). It's possible that ClamXAV archived your music somewhere on your hard drive, but don't assume anything since I'm not sure how the program works (nor do I own it).
type "ls -al" (w/o the quotes) and post what you see. Also, if you happen to remember how much free HD space you had before, check to see if it's the same now. If it's still about the same, then ClamXAV probably archived your music somewhere on your hard drive.
Well the hdd space has stayed the same.....
Mac Mini 1.5/512/40/SuperDrive
Offline
#52 2006-02-17 5:59 pm
- Mr. T
- Best of both worlds

- From: omnipresent
- Registered: 2002-04-02
- Posts: 4232
Re: First Mac Trojan?
hmmm... The (non-invisible) Music folder is there and the invisible one is not, which is why the ArtemiseG3's command failed. Type "open Music" (again w/o quotes) into the Terminal. Is your music there? And if you browse to your home folder in the Finder, do you see the Music folder?
while (1) {fork();}
Offline
#53 2006-02-17 6:25 pm
- Colticus
- Member
- From: Cleveland Texas
- Registered: 2005-02-02
- Posts: 160
Re: First Mac Trojan?
It takes me to my music folder and itunes is in there but when I open it nothing is in it. 
Mac Mini 1.5/512/40/SuperDrive
Offline
#54 2006-02-17 6:49 pm
- mahakali
- anti-razor

- From: easter egg
- Registered: 2002-11-06
- Posts: 5592
Re: First Mac Trojan?
Try checking inside the iTunes folder in your Library folder. Or try to do Finder search for mp3 or aac (or whatever format you have in your iTunes).
1. Instill fear.
2. ???????? (use your imagination)
3. Profit!
Offline
#55 2006-02-17 6:59 pm
- Egress
- Connoisseur of Eyebrows

- From: Rockville, Maryland, USA
- Registered: 2000-02-05
- Posts: 5049
Re: First Mac Trojan?
I need an example of one person who has been infected by this malware.
Hey!!! Was that Pithy? Got a twenty?
Offline
#56 2006-02-17 7:15 pm
- mahakali
- anti-razor

- From: easter egg
- Registered: 2002-11-06
- Posts: 5592
Re: First Mac Trojan?
Egress wrote:
I need an example of one person who has been infected by this malware.
1. Instill fear.
2. ???????? (use your imagination)
3. Profit!
Offline
#57 2006-02-17 7:19 pm
- Colticus
- Member
- From: Cleveland Texas
- Registered: 2005-02-02
- Posts: 160
Re: First Mac Trojan?
mahakali wrote:
Try checking inside the iTunes folder in your Library folder. Or try to do Finder search for mp3 or aac (or whatever format you have in your iTunes).
Nothing shows up. 
Mac Mini 1.5/512/40/SuperDrive
Offline
#58 2006-02-17 7:46 pm
- Macskeeball
- Member

- Registered: 2002-02-07
- Posts: 8014
- Website
Re: First Mac Trojan?
If you are ripping as AAC, the extenstion will be .m4a (NOT .aac). You should include both visible and invisible items in your search.
tech writer for hire
Offline
#59 2006-02-17 7:59 pm
- Mr. T
- Best of both worlds

- From: omnipresent
- Registered: 2002-04-02
- Posts: 4232
Re: First Mac Trojan?
First, select the iTunes folder inside your Music folder and choose get info, and see how big the folder is. If it's hundreads/thousands of MB then your music is probably in there but got hidden somehow. Secondly, if you go to your home folder in the Finder, do you see your Music folder there? One time, my desktop folder disappeared and I had to go through some trouble to get it back, but all my stuff was there.
Worst case scenario, there are ways of recovering the music from your iPod (again, don't sync it yet!) assuming you have an iPod. It can be done for free from the Terminal, or there are user-friendly GUI apps that will do the same thing but not for free.
while (1) {fork();}
Offline
#60 2006-02-17 8:48 pm
- Colticus
- Member
- From: Cleveland Texas
- Registered: 2005-02-02
- Posts: 160
Re: First Mac Trojan?
I used "get info" on the iTunes folder itself and its only 36k. 
Mac Mini 1.5/512/40/SuperDrive
Offline
#61 2006-02-17 9:00 pm
- mahakali
- anti-razor

- From: easter egg
- Registered: 2002-11-06
- Posts: 5592
Re: First Mac Trojan?
If you're running Tiger, type (or copy-paste) this in your spotlight search: kind:music and hit enter.
1. Instill fear.
2. ???????? (use your imagination)
3. Profit!
Offline
#62 2006-02-17 9:16 pm
- Colticus
- Member
- From: Cleveland Texas
- Registered: 2005-02-02
- Posts: 160
Re: First Mac Trojan?
mahakali wrote:
If you're running Tiger, type (or copy-paste) this in your spotlight search: kind:music and hit enter.
I did that and I get over 4k hits. They are all aif's and have the itunes logo beside them. 
They are all garageband sounds. 
Last edited by Colticus (2006-02-17 9:19 pm)
Mac Mini 1.5/512/40/SuperDrive
Offline
#63 2006-02-17 9:22 pm
- mahakali
- anti-razor

- From: easter egg
- Registered: 2002-11-06
- Posts: 5592
Re: First Mac Trojan?
More than 4000 files, all of them garageband sounds? Did you ever click on one of them and see at the bottom of the window what the location is?
Really, man, once in a while try to learn how to use your machine.
Last edited by mahakali (2006-02-17 9:22 pm)
1. Instill fear.
2. ???????? (use your imagination)
3. Profit!
Offline
#64 2006-02-17 10:00 pm
- MysticCow
- Junior Assistant Poobah (Probationary)
- From: Somewhere
- Registered: 2002-07-29
- Posts: 3953
Re: First Mac Trojan?
I don't know if anyone put this one up, but Oompa Locker!
Offline
#65 2006-02-17 10:39 pm
- Colticus
- Member
- From: Cleveland Texas
- Registered: 2005-02-02
- Posts: 160
Re: First Mac Trojan?
mahakali wrote:
More than 4000 files, all of them garageband sounds? Did you ever click on one of them and see at the bottom of the window what the location is?
Really, man, once in a while try to learn how to use your machine.
Ever one of them is a garageband sound. 
Mac Mini 1.5/512/40/SuperDrive
Offline
#66 2006-02-17 10:43 pm
- ElectricSheep
- Member
- Registered: 2003-07-20
- Posts: 109
Re: First Mac Trojan?
Thunderstruck wrote:
I'm getting confused with all this admin stuff. The default user account setting in OS X has admin privileges doesn't it? or does admin here really mean root?
In a nutshell:
root is a user account with full privileges to do anything and everything to anything and everything without requiring a password. You should rarely, if ever, have to login as root.
Admin in this case means that your user account has membership to the admin group. In MacOS X's default configuration, users who have membership to the admin group may gain temporary root privileges through something called 'superuser'. When you superuser, you are asked for your password, and provided you enter it correctly your privileges are elevated to that of the root account for a limited time.
If you take a look around at the ownership of some of the files on your drive, you'll notice that critical system files are owned by root and the group wheel. Even an admin account will have to authenticate to make any changes to these directories. The root Library directory and the Applications directory are owned by root and the group admin. Admin accounts can freely make changes to these directories without authenticating because their group membership gives them the privileges to do so.
Standard accounts do not have membership to the admin group, and will require authentication (as an admin user) to make any changes to those directories.
Offline
#67 2006-02-17 10:44 pm
- Macrules0208
- Member

- Registered: 2006-01-21
- Posts: 101
Re: First Mac Trojan?
Hey I am going to be getting my computer within the month and I was going to use ichat/AIM. But now reading about this worm gettting through from the ichat app, I was wondering what I should do if anything to avoid getting leap worm and should I download Clamxav or will that be a waste of space? Originally, I was told that I wouldn't need anti virus software as Macs weren't targeted.
Last edited by Macrules0208 (2006-02-17 10:48 pm)
Offline
#68 2006-02-17 10:53 pm
- ConnertheCat
- 7 Months Later

- From: Penfield, NY
- Registered: 2001-07-21
- Posts: 13405
Re: First Mac Trojan?
Macrules0208 wrote:
Hey I am going to be getting my computer within the month and I was going to use ichat/AIM. But now reading about this worm gettting through from the ichat app, I was wondering what I should do if anything to avoid getting leap worm and should I download Clamxav or will that be a waste of space? Originally, I was told that I wouldn't need anti virus software as Macs weren't targeted.
iChat isn't "targeted" persay. Anyhow, unless you expect to be getting and downloading programs that ask for your admin password, I think you'll be fine.
Rule of thumb - Don't run files that you don't know what they are.
Offline
#69 2006-02-17 10:55 pm
- Mr. T
- Best of both worlds

- From: omnipresent
- Registered: 2002-04-02
- Posts: 4232
Re: First Mac Trojan?
So far it sounds like the music is there, but it's somewhere else on your HD, since it's still taking up disk space. Without knowing how ClamXAV works, I can't say where it is or if it's in a special ClamXAV archive format or whatever, but if you have an iPod with your music on it, we can extract it!
There's only one problem, which might not actually be a problem, but I'll explain it anyway. Ordinarily if your iPod is set to auto-sync (which is the default) and there are no songs in your library, your iPod will get erased! However, if the library files are completely gone (at least as far as iTunes is concerned) then iTunes will create a new library different from the previous one, and will ASK you if you want to sync with this new library - in theory. At this point, you would click no, and then go to the preferences to turn off auto-sync and enable disk usage (which we need to do to get the files off). Fortunately there's a way to avoid the issue (at least I think so). If you boot your iPod into disk mode by holding down a certain combination of buttons on the iPod (different models of iPods require a different combination) you should be able to then plug it into your computer and use it as a regular external hard drive. In either case, I'm not 100% sure that iTunes won't open up and try to auto-sync anyway, so the choice is yours.
Whichever path you choose, you should ultimately have manged to get your iPod mounted on the desktop as a disk. At this point you would open a terminal window and enter the following command:
cp -R -v /Volumes/"name of iPod with quotes"/iPod_Control/iTunes Desktop/iPodMusic/
which will copy all your music to the desktop into a folder called iPodMusic (Don't bother looking in this folder as all you'll see are a bunch of Fxx folders with arcane filenames). At this point I recommend you burn this folder to one or more DVDs as a backup. Then just drag this folder onto the iTunes icon and your music should hopefully reappear (you might loose playlists and ratings and such).
Last edited by Mr. T (2006-02-17 10:56 pm)
while (1) {fork();}
Offline
#70 2006-02-17 10:58 pm
- Macrules0208
- Member

- Registered: 2006-01-21
- Posts: 101
Re: First Mac Trojan?
ConnertheCat wrote:
Macrules0208 wrote:
Hey I am going to be getting my computer within the month and I was going to use ichat/AIM. But now reading about this worm gettting through from the ichat app, I was wondering what I should do if anything to avoid getting leap worm and should I download Clamxav or will that be a waste of space? Originally, I was told that I wouldn't need anti virus software as Macs weren't targeted.
iChat isn't "targeted" persay. Anyhow, unless you expect to be getting and downloading programs that ask for your admin password, I think you'll be fine.
Rule of thumb - Don't run files that you don't know what they are.
I'm a student and I bought it for Homework, Internet Browsing, Music, and IM using ichat.
Last edited by Macrules0208 (2006-02-17 10:59 pm)
Offline
#71 2006-02-17 11:49 pm
- Colticus
- Member
- From: Cleveland Texas
- Registered: 2005-02-02
- Posts: 160
Re: First Mac Trojan?
Mr. T wrote:
So far it sounds like the music is there, but it's somewhere else on your HD, since it's still taking up disk space. Without knowing how ClamXAV works, I can't say where it is or if it's in a special ClamXAV archive format or whatever, but if you have an iPod with your music on it, we can extract it!
There's only one problem, which might not actually be a problem, but I'll explain it anyway. Ordinarily if your iPod is set to auto-sync (which is the default) and there are no songs in your library, your iPod will get erased! However, if the library files are completely gone (at least as far as iTunes is concerned) then iTunes will create a new library different from the previous one, and will ASK you if you want to sync with this new library - in theory. At this point, you would click no, and then go to the preferences to turn off auto-sync and enable disk usage (which we need to do to get the files off). Fortunately there's a way to avoid the issue (at least I think so). If you boot your iPod into disk mode by holding down a certain combination of buttons on the iPod (different models of iPods require a different combination) you should be able to then plug it into your computer and use it as a regular external hard drive. In either case, I'm not 100% sure that iTunes won't open up and try to auto-sync anyway, so the choice is yours.
Whichever path you choose, you should ultimately have manged to get your iPod mounted on the desktop as a disk. At this point you would open a terminal window and enter the following command:
cp -R -v /Volumes/"name of iPod with quotes"/iPod_Control/iTunes Desktop/iPodMusic/
which will copy all your music to the desktop into a folder called iPodMusic (Don't bother looking in this folder as all you'll see are a bunch of Fxx folders with arcane filenames). At this point I recommend you burn this folder to one or more DVDs as a backup. Then just drag this folder onto the iTunes icon and your music should hopefully reappear (you might loose playlists and ratings and such).
ipod shuffle with no songs on it. 
Mac Mini 1.5/512/40/SuperDrive
Offline
#72 2006-02-18 12:32 am
- Mr. T
- Best of both worlds

- From: omnipresent
- Registered: 2002-04-02
- Posts: 4232
Re: First Mac Trojan?
Ooof. Sorry about that. But again, I'm quite confident that your music is still on your computer. But to be absolutely sure it's not in your iTunes folder, type the following into the Terminal:
ls -al Music/iTunes/iTunes\ Music/
Post what you see. If the only entries you see are . and .. then you should probably repost this problem in baloon help, and if it still isn't resolved, take it to an Apple Genius. Explain to him exactly what happened. In fact you should keep a copy of the dmg with the fake pictures as well. I think I could probably help you further if I were sitting in front of your machine, or perhaps if I knew more about ClamXAV, which is why I feel confident an Apple Genius could fix it, if that's what it comes to. Or if your music is purchased from ims, you might be able to plead with Apple to replace your music free of charge, since they should have a record of everything you bought from them. As for the music which might be "borrowed" from a friend, you'll probably have to re-borrow it.
Last edited by Mr. T (2006-02-18 12:50 am)
while (1) {fork();}
Offline
#73 2006-02-18 12:39 am
- NAG
- A witch!
- Royal Wombat

- From: /usr/local/apps/nag
- Registered: 2000-09-22
- Posts: 30229
Re: First Mac Trojan?
Macrules0208 wrote:
ConnertheCat wrote:
Macrules0208 wrote:
Hey I am going to be getting my computer within the month and I was going to use ichat/AIM. But now reading about this worm gettting through from the ichat app, I was wondering what I should do if anything to avoid getting leap worm and should I download Clamxav or will that be a waste of space? Originally, I was told that I wouldn't need anti virus software as Macs weren't targeted.
iChat isn't "targeted" persay. Anyhow, unless you expect to be getting and downloading programs that ask for your admin password, I think you'll be fine.
Rule of thumb - Don't run files that you don't know what they are.I'm a student and I bought it for Homework, Internet Browsing, Music, and IM using ichat.
Again, it will only ask you for your admin password if you aren't opening it as an admin user. So if you are like most of the OS X users out there, this thing will install upon you opening the "image." So there are two things. Yes, don't open random things for no real reason. Second is to not use an admin user as your primary (everyday) user.
Offline
#74 2006-02-18 12:51 am
- Colticus
- Member
- From: Cleveland Texas
- Registered: 2005-02-02
- Posts: 160
Re: First Mac Trojan?
Mr. T wrote:
Ooof. Sorry about that. But again, I'm quite confident that your music is still on your computer. But to be absolutely sure it's not in your iTunes folder, type the following into the Terminal:
ls -al Music/iTunes/iTunes\ Music/
Post what you see. If the only entries you see are . and .. then you should probably repost this problem in baloon help, and if it still isn't resolved, take it to an Apple Genius. Explain to him exactly what happened. In fact you should keep a copy of the dmg with the fake pictures as well. I think I could probably help you further if I were sitting in front of your machine, or perhaps if I knew more about ClamXAV, which is why I feel confident an Apple Genius could fix it, if that's what it comes to. Or if your music is purchased from ims, you might be able to plead with Apple to replace your music free of charge, since they should have a record of everything you bought from them. As for the music which might be "borrowed" from a friend, you'll probably have to re-borrow it.

Mac Mini 1.5/512/40/SuperDrive
Offline
#75 2006-02-18 12:59 am
- Mr. T
- Best of both worlds

- From: omnipresent
- Registered: 2002-04-02
- Posts: 4232
Re: First Mac Trojan?
Yeah, it's not there anymore. My best guess is it's in some special kind of ClamXAV Quarantine archive, since your searches for *.m4a files were unsuccessful.
while (1) {fork();}
Offline


