Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Apple Update Software downloads Win32/herz trojan virus
Self | March 29, 2016 | Self

Posted on 03/29/2016 2:42:37 PM PDT by CedarDave

Running Windows 7. Plugged in my iphone to download some work photos, and an update from Apple popped up to update itunes and video software. I started the download and my AVG business antivirus detected the win32/herz virus and deleted it. Checking on the name and it appears to be a particularly nasty virus.

If any Apple fans on here know how to notify Apple, I'll be glad to send the URL link. It starts with swcdn.apple.com/... and seems to be a legitimate link.


TOPICS: Computers/Internet
KEYWORDS: apple; applesoftware; itunes; win7; windows7
Navigation: use the links below to view more comments.
first 1-2021-34 next last

1 posted on 03/29/2016 2:42:37 PM PDT by CedarDave
[ Post Reply | Private Reply | View Replies]

To: CedarDave

Shades of “Back Door”!


2 posted on 03/29/2016 2:48:18 PM PDT by DiogenesLamp ("of parents owing allegiance to no other sovereignty.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: CedarDave

Are you sure you’re really connecting to swcdn.apple.com? DNS poisoning attacks are common these days. Do you have the actual IP address you connected to?


3 posted on 03/29/2016 2:49:45 PM PDT by proxy_user
[ Post Reply | Private Reply | To 1 | View Replies]

To: CedarDave; Swordmaker

He’ll know a bit more about the Apple side


4 posted on 03/29/2016 2:51:16 PM PDT by Svartalfiar
[ Post Reply | Private Reply | To 1 | View Replies]

To: CedarDave

This can be a false alarm.

I don’t like it use the Apple update. I just download and re-run the whole iTunes installer. Once I did an update and the CD drive became in-accessable.

www.virustotal.com will scan any file against two dozen anti virus programs. Then in doubt, use that.


5 posted on 03/29/2016 2:52:00 PM PDT by doomtrooper99 (Mr Truman, you did not finish the job)
[ Post Reply | Private Reply | To 1 | View Replies]

To: CedarDave

False positive from AVG, I expect.


6 posted on 03/29/2016 2:52:56 PM PDT by The KG9 Kid
[ Post Reply | Private Reply | To 1 | View Replies]

To: proxy_user

Here is what I get:

> swcdn.apple.com
Server: google-public-dns-a.google.com
Address: 8.8.8.8

Non-authoritative answer:
Name: swcdn.g.aaplimg.com
Address: 17.253.15.202
Aliases: swcdn.apple.com
swcdn.apple.com.akadns.net

I am using the Google public DNS servers, so that should be a clean lookup.


7 posted on 03/29/2016 2:52:57 PM PDT by proxy_user
[ Post Reply | Private Reply | To 3 | View Replies]

To: proxy_user

I’m sorry; I don’t understand your response. Is the address legit or not?


8 posted on 03/29/2016 3:01:33 PM PDT by CedarDave (Extremist Muslims want to kill you; moderate Muslims want extremist Muslims to kill you.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: proxy_user

Good catch on the actual IP address. Could be a nasty redirect. The address looks like a valid Apple software CDN.


9 posted on 03/29/2016 3:02:45 PM PDT by LoneStar42
[ Post Reply | Private Reply | To 7 | View Replies]

To: doomtrooper99

CD drive inaccessible?? Wow!

Are you saying I should delete my Apple programs for Windows and then download fresh directly from Apple?


10 posted on 03/29/2016 3:04:00 PM PDT by CedarDave (Extremist Muslims want to kill you; moderate Muslims want extremist Muslims to kill you.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: LoneStar42
More of the address (w/o the 25+ digits/letters):

swcdn.apple.com/content/downloads/17/00/031 ... /applesoftware.msi

11 posted on 03/29/2016 3:09:53 PM PDT by CedarDave (Extremist Muslims want to kill you; moderate Muslims want extremist Muslims to kill you.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: LoneStar42

If you computer is connecting to 17.253.15.202, then you are good. But is that where it is really connecting to? Do you get the same IP when you look up the address?


12 posted on 03/29/2016 3:29:55 PM PDT by proxy_user
[ Post Reply | Private Reply | To 9 | View Replies]

To: CedarDave

There are updates to iTunes available, but It should not have any viruses attached to it. It is a digitally signed software from Apple. That is a correct domain associated with Apple Canada. Are you in Canada? If not, you should not be downloading from there, but from a USA Apple source to get the right download file.


13 posted on 03/29/2016 3:53:22 PM PDT by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue..)
[ Post Reply | Private Reply | To 1 | View Replies]

To: CedarDave

FBI/NSA getting even! : )


14 posted on 03/29/2016 4:22:03 PM PDT by minnesota_bound
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Thanks for the response. I’m located in southeastern New Mexico.

When I plugged in my iPhone that is the link address that popped up.

Do you believe I got a false positive with AVG (the program “secured” the link by blocking the URL from downloading)?

Do you recommend my uninstalling all Apple software* and reinstalling from the Apple location?

* Currently installed with today’s date -
Apple support application (32 bit)
Apple support application (64 bit)
Apple mobile device support
Apple software update
iTunes

Installed with January update:
Quicktime 7

Any suggestions appreciated.


15 posted on 03/29/2016 4:57:50 PM PDT by CedarDave (Extremist Muslims want to kill you; moderate Muslims want extremist Muslims to kill you.)
[ Post Reply | Private Reply | To 13 | View Replies]

To: CedarDave

That .MSI bothers me. MSI = Microsoft Installer. It is not a typical extension for Apple. I’d use any link I could find for Apple to share that information with them.


16 posted on 03/29/2016 5:05:16 PM PDT by LoneStar42
[ Post Reply | Private Reply | To 11 | View Replies]

To: proxy_user

Just got a post from CedarDave. The rest of the string ended with .MSI. That indicates Microsoft installer. Not a good sign from an Apple site. I suggested he send the string to Apple.


17 posted on 03/29/2016 5:09:54 PM PDT by LoneStar42
[ Post Reply | Private Reply | To 12 | View Replies]

To: LoneStar42

I’m installing an iTunes update on a Win 7 machine. If not that type of extension, what should it be?


18 posted on 03/29/2016 5:30:10 PM PDT by CedarDave (Extremist Muslims want to kill you; moderate Muslims want extremist Muslims to kill you.)
[ Post Reply | Private Reply | To 16 | View Replies]

To: LoneStar42

I am not too sure of the architecture, since I don’t use Apple products.

As I follow the conversation, he plugged an iPhone into a Windows computer and got what purported to be a software update from Apple. If this software update is for iTunes on a Windows PC, isn’t a .msi file what your would expect? I don’t see why plugging in an iPhone would activate a request to update Windows software, however.


19 posted on 03/29/2016 5:35:39 PM PDT by proxy_user
[ Post Reply | Private Reply | To 17 | View Replies]

To: proxy_user
I don’t see why plugging in an iPhone would activate a request to update Windows software, however.

Plugging in the iPhone activated a request to up date the itunes software for a PC.

20 posted on 03/29/2016 5:37:51 PM PDT by CedarDave (Extremist Muslims want to kill you; moderate Muslims want extremist Muslims to kill you.)
[ Post Reply | Private Reply | To 19 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-34 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson