Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

iWork '09 trojan infects at least 20,000 machines
Engadget.com ^ | 1/22/09 | Joseph L Flatley

Posted on 01/22/2009 2:50:02 PM PST by dangerdoc

Quite a number of no-googniks who thought they'd safe a few bucks by downloading a pirated version of iWork 09 have gotten more than they'd bargained for, in the form of a Trojan Horse called OSX.Trojan.IServices.A This guy installs itself in the computer's startup as root, and once in place can connect to a remote server and broadcast its location, allowing malicious users to take charge of the machine remotely. An since it has root access to the OS, the trojan can not only install additional components but can also modify existing apps, making this thing extremely difficult to remove.

(Excerpt) Read more at engadget.com ...


TOPICS: News/Current Events
KEYWORDS: apple
Navigation: use the links below to view more comments.
first previous 1-2021-4041-43 next last
To: dangerdoc

I’ve been battling that damned Antivirus 2009 infection on my home computers for a couple weeks now. I feel your pain.


21 posted on 01/22/2009 4:57:13 PM PST by Non-Sequitur
[ Post Reply | Private Reply | To 1 | View Replies]

To: ghostrider
Does this only apply to downloaded executable programs, or does it also apply to picture downloads - like from YouTube & picture files?

I think attachments to pics or videos would fall under "virus" rather than "trojan horse," which is what is at issue here.

However, I believe one bad-guy tactic is to trick people into downloading executables in the form of a particular "codec" that ostensibly decodes a type of video or picture file that has just been downloaded.

22 posted on 01/22/2009 4:59:09 PM PST by r9etb
[ Post Reply | Private Reply | To 18 | View Replies]

To: Non-Sequitur
I’ve been battling that damned Antivirus 2009 infection on my home computers for a couple weeks now. I feel your pain.

fdisk
format
re-install

"I say we take off and nuke the site from orbit; it's the only way to be really sure" - Aliens

23 posted on 01/22/2009 5:01:53 PM PST by AFreeBird
[ Post Reply | Private Reply | To 21 | View Replies]

To: Non-Sequitur
I’ve been battling that damned Antivirus 2009 infection on my home computers for a couple weeks now. I feel your pain.

Your problem is that the infection in question invades your registry. I have been able to fix it using Malwarebyte's anti-malware software -- free download.

24 posted on 01/22/2009 5:02:00 PM PST by r9etb
[ Post Reply | Private Reply | To 21 | View Replies]

To: r9etb; ghostrider
I think attachments to pics or videos would fall under "virus" rather than "trojan horse," which is what is at issue here.

Not accurate. Virus/Trojans are executable programs, they have different functions, but they both follow similar protocols for basic operation (enter system, execute, hide, replicate, and do its primary function). Now whether or not it will execute and detach when viewed, and how far it can go, is another matter depending on the target system and applications used. But attaching one to a jpg isn't a problem.

25 posted on 01/22/2009 5:13:20 PM PST by AFreeBird
[ Post Reply | Private Reply | To 22 | View Replies]

To: r9etb

I’ve got Malewarebytes and AVG now. And I’ve been working with some friends who are a lot more technically savvy than I am. From what they’ve told me the Antivirus 2009 is worse than previous versions. Removing it trashes system files; in my case it manifested itself by causing the computer to restart at odd moments, sometimes as many as a dozen times in less than half an hour. In the end we’ve had to backup my files and reload Windows. So now I’ve got to reload all my programs like iTunes and MS Office and just about ever other application I’ve got. It’s a real bastard of a virus, let me tell you. If I could get my hands on the SOB who invented it...


26 posted on 01/22/2009 5:13:28 PM PST by Non-Sequitur
[ Post Reply | Private Reply | To 24 | View Replies]

To: Non-Sequitur

Once you get everything restored, do another full backup. Saves time for the next time. A lot less to rebuild.


27 posted on 01/22/2009 5:21:38 PM PST by AFreeBird
[ Post Reply | Private Reply | To 26 | View Replies]

To: 1234; 50mm; 6SJ7; Abundy; Action-America; acoulterfan; aristotleman; af_vet_rr; Aggie Mama; ...
WARNING! Pirate version of iWork09 has trojan embedded... PING!


Mac Security Ping!

If you want on or off the Mac Ping List, Freepmail me.

28 posted on 01/22/2009 7:06:30 PM PST by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: antiRepublicrat
Idiots downloading infested pirated apps ping.

No amount of system security can prevent an idiot from installing malware himself if the idiot has administrator access.

29 posted on 01/22/2009 7:09:09 PM PST by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE!)
[ Post Reply | Private Reply | To 6 | View Replies]

To: tacticalogic
Once a trojan is in place on your computer, they can remotely access it and program it to do whatever they want. Send spam, launch an attack against other computers, search for anything on your computer that looks like a credit card number

Is it true that even the best anti-virus programs are only catching around 70% of the stuff out there?

30 posted on 01/22/2009 7:17:44 PM PST by GOPJ ("A consensus of 100 scientists is undone by one fact." - - Einstein (take that Al Gore))
[ Post Reply | Private Reply | To 10 | View Replies]

To: GOPJ
Is it true that even the best anti-virus programs are only catching around 70% of the stuff out there?

That's hard to say, but I'd consider it unlikely. The best AV programs are catching pretty much everything they know about they've had at least a few days to work on. It's pretty hard to speculate about how much is out there that nobody knows about, but 30% seems arbitrary and way too high.

31 posted on 01/22/2009 7:25:02 PM PST by tacticalogic ("Oh bother!" said Pooh, as he chambered his last round.)
[ Post Reply | Private Reply | To 30 | View Replies]

To: ClearBlueSky

Follow the money.


32 posted on 01/22/2009 7:34:43 PM PST by gost2
[ Post Reply | Private Reply | To 4 | View Replies]

To: Swordmaker; antiRepublicrat
>> Idiots downloading infested pirated apps ping.

> No amount of system security can prevent an idiot from installing malware himself if the idiot has administrator access.

No kidding.

Let's see,..
I'll just download this hacked software and run it, and then
I'll surf some porn and click on all the links, and then
I'll buy some cheap drugs from a website in a foreign language, and then
I'll give my passwords to this website that says my bank account is frozen,
and then I'll blame it all on the hackers of course!

I once got a shirt with the following tag:

"This shirt is made from flame-retardant materials.
It will not support combustion.
HOWEVER
PLEASE DO NOT SET YOUR SHIRT ON FIRE!"
People who download and run pirated software make me want to shout at them: "DO NOT SET YOUR SHIRT ON FIRE!"
33 posted on 01/22/2009 9:36:48 PM PST by dayglored (Listen, strange women lying in ponds distributing swords is no basis for a system of government!)
[ Post Reply | Private Reply | To 29 | View Replies]

To: dangerdoc
Quite a number of no-googniks who thought they'd safe a few bucks by downloading a pirated version of iWork 09 have gotten more than they'd bargained for, in the form of a Trojan Horse

You play stupid games, you get stupid prizes.

34 posted on 01/23/2009 6:16:02 AM PST by cowboyway ("The beauty of the Second Amendment is you won't need it until they try to take it away"--Jefferson)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dangerdoc

From the sound of this, it’s not self-propagating. At least it’s only the stupid and people too damned cheap to pay for their stuff that are getting hit.


35 posted on 01/23/2009 6:48:46 AM PST by zeugma (Will it be nukes or aliens? Time will tell.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: kalee

I believe these people work for the anti virus people and are payed by them to create the bugs. That way the companies can stay in business.


36 posted on 01/23/2009 8:45:13 AM PST by nnn0jeh
[ Post Reply | Private Reply | To 16 | View Replies]

To: tacticalogic

Thanks - that’s comforting.


37 posted on 01/23/2009 9:07:13 AM PST by GOPJ ("A consensus of 100 scientists is undone by one fact." - - Einstein (take that Al Gore))
[ Post Reply | Private Reply | To 31 | View Replies]

To: dangerdoc

bfl


38 posted on 01/23/2009 9:12:40 AM PST by Skooz (Gabba Gabba we accept you we accept you one of us Gabba Gabba we accept you we accept you one of us)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dangerdoc

bfl


39 posted on 01/23/2009 9:12:48 AM PST by Skooz (Gabba Gabba we accept you we accept you one of us Gabba Gabba we accept you we accept you one of us)
[ Post Reply | Private Reply | To 1 | View Replies]

To: antiRepublicrat

You said — “Idiots downloading infested pirated apps ping.”

There’s only one version of iWork 09 that Apple puts out. They are all 30-day fully working copies. You simply add a user “registration” into the entry field on the software and you turn it into a “long-term” working copy.

That’s all it is. There is no pirated copy. It doesn’t exist because Apple gives away *for free* the only copy they make — you then add the “number” in the appropriate field, after you’ve already downloaded it.

I downloaded the iWork 09 copy from Apple and put it up on BitTorrent for other Apple Macintosh users. They had a lot on there either getting it from Apple or from BitTorrent.

Either way, it was no big deal..., as it’s free in the first place...


40 posted on 01/29/2009 12:15:39 PM PST by Star Traveler
[ Post Reply | Private Reply | To 6 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-43 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson