Author Topic: YAT: Yet Another Trojan  (Read 1644 times)

Offline Xairbusdriver

  • Administrator
  • TS Addict
  • *****
  • Posts: 26388
  • 27" iMac (mid-17), Big Sur, Mac mini, Catalina
    • View Profile
    • Mid-South Weather
YAT: Yet Another Trojan
« on: February 20, 2013, 09:09:52 PM »
Intego reports another Trojan attack <Pint-Sized Backdoor for OS X Discovered> that creates some files that run other scripts in a secure (encrypted) shell. Here is a list of files that it creates and where you can easily look for them.
    com.apple.cocoa.plist
    cupsd (Mach-O binary)
    com.apple.cupsd.plist
    com.apple.cups.plist
    com.apple.env.plist
Look for these files in:
    ~/Library/LaunchAgents
    System/Library/LaunchAgents
    System/Library/LaunchDaemons
    Library/LaunchAgents
    Library/LaunchDaemons
If any are found, gather them into a folder, compress the folder and move it to your Desktop. You will be asked for your Admin password. Restart the Mac. Check those locations again. Don't provide your Admin password when you don't understand why it is being asked for. wink.gif
THERE ARE TWO TYPES OF COUNTRIES
Those that use metric = #1 Measurement system
And the United States = The Banana system
CAUTION! Childhood vaccinations cause adults! :yes:

Offline krissel

  • Administrator
  • TS Addict
  • *****
  • Posts: 14736
    • View Profile
YAT: Yet Another Trojan
« Reply #1 on: February 21, 2013, 12:26:54 AM »
iClean.  smile.gif


A Techsurvivors founder

Offline dolphin

  • TS Addict
  • *****
  • Posts: 2769
    • View Profile
    • http://dolphin13.com/designsbyroy/
YAT: Yet Another Trojan
« Reply #2 on: February 22, 2013, 11:06:17 PM »
iClean too!!! thumbup.gif
"If it aint broke; don't fixit"
Roy

Offline LR827

  • TS Addict
  • *****
  • Posts: 1840
  • Let's take care of each other
    • View Profile
    • http://www.deardrroth.com/
YAT: Yet Another Trojan
« Reply #3 on: February 24, 2013, 08:50:19 AM »
Thanks, that was very helpful. I didn't find any of the listed files, but the emotional security is great.
Lorraine

Offline Xairbusdriver

  • Administrator
  • TS Addict
  • *****
  • Posts: 26388
  • 27" iMac (mid-17), Big Sur, Mac mini, Catalina
    • View Profile
    • Mid-South Weather
YAT: Yet Another Trojan
« Reply #4 on: March 01, 2013, 06:44:23 PM »
This one affects people who play Minecraft (which requires Java) AND who want to control other player's access to the game. In other words, evil people who like to play with known security risking software. Surely none of those at TS. nono.gif But you can pass along the link to the info if you have any evil friends! wink.gifBasically, this malware is loaded when a Minecraft player decides to cheat and/or wants to control who can play the game by taking gaining Moderator authority. It will, in reality, send the player's info (passwords, etc.) to the malware creators. I'm sure those nice people are simply trying to keep everyone honest; they will surely report the people who download the malware to the Admins at Minecraft... rolleyes.gif laughhard.gif
THERE ARE TWO TYPES OF COUNTRIES
Those that use metric = #1 Measurement system
And the United States = The Banana system
CAUTION! Childhood vaccinations cause adults! :yes: