Anti-virus

Soldato
Joined
22 Oct 2005
Posts
2,802
Location
Moving...
Hi guys, I think my gf may have a virus on her mac. I know it's doubtful but I want to double check. I've had a quick search through this forum section and the only mention I can find is ClamXav, is this the best going? It's only to going to be a one-off scan just to check she doesn't intend on keeping it running the whole time.

Thanks for any advice.

*edit* - needs to be free as well if possible!
 
Soldato
Joined
17 Oct 2002
Posts
3,103
I just put it on (just out of interest really) and tried selecting the drive, but it said you cannot scan the whole drive. After looking on the site tho you can.
7a. How can I scan my entire hard drive?

When you click "Choose what to scan...", select your hard drive but don't click "OK" yet. What you have to do is hold down the command key (the one with the Apple symbol) and then select everything you see in there. Then click "OK" and continue as normal.
 
Soldato
OP
Joined
22 Oct 2005
Posts
2,802
Location
Moving...
Clam is good. Why do you think that there is a virus?

Well I did some work on her mac the other day on microsoft word, saved it onto my usb stick, plugged it back into my PC (using windows XP) and nod32 said there was an virus in the word document I just made. It wasn't just my computer that throws up the virus notification, it's happened before on other PC's with different anti-virus software. I've tried formatting the stick, and scanning it but thats clean to.
 
Soldato
Joined
12 Aug 2004
Posts
6,105
Well I did some work on her mac the other day on microsoft word, saved it onto my usb stick, plugged it back into my PC (using windows XP) and nod32 said there was an virus in the word document I just made. It wasn't just my computer that throws up the virus notification, it's happened before on other PC's with different anti-virus software. I've tried formatting the stick, and scanning it but thats clean to.

Right see where you are coming from. Well get Clam installed and scan the hard drive. That should nail it. This is the first time I have seen a virus showing up on a Mac.
 
Soldato
Joined
6 Jun 2006
Posts
6,012
Location
Kent
And I'm kind of hoping, that its down to MS word.

Sounds to me like the Mac is acting as a nest for the virus, which is then spreading via files transferred to other machines.

For this reason, and this reason alone, I recommend using AV on a Mac in a corporate environment, especially if you're using it at home and at work.
 
Soldato
Joined
17 Jan 2007
Posts
8,944
Location
Manchester
Just to clarify...

You created the Word Doc on the Mac or did you just work on it? If you just worked on it, where did the original file come from?

What version of MS Word for Mac are you using - 2004 or 2008?
 
Soldato
OP
Joined
22 Oct 2005
Posts
2,802
Location
Moving...
Just to clarify...

You created the Word Doc on the Mac or did you just work on it? If you just worked on it, where did the original file come from?
I think the first couple of times it happened I created the document on the mac, but this latest issue happened when working on an existing document -one that I created on windows.

What version of MS Word for Mac are you using - 2004 or 2008?
2004.

I'm running the virus check now but it's not finished yet! I'll update when its finished.
 
Soldato
OP
Joined
22 Oct 2005
Posts
2,802
Location
Moving...
The virus check has finally completed. Below is a copy of the findings:

/Users/spa/.Trash/Final Report.doc: W97M.Walker FOUND
/Users/spa/.Trash/Final Report1.doc: W97M.Walker FOUND
/Users/spa/Desktop/S.doc: W97M.Walker FOUND
/Users/spa/Desktop/work/general uni/union work app form.doc: W97M.Walker FOUND
/Users/spa/Desktop/work/part 3/cms/brief.doc: W97M.Walker FOUND
/Users/spa/Desktop/work/part 3/cms/cms assignment 1: W97M.Walker FOUND
/Users/spa/Desktop/work/part 3/dissertation/BA_brief_2007_8.doc: W97M.Walker FOUND
/Users/spa/Desktop/work/part 3/dissertation/dissertation proposal 2.doc: W97M.Walker FOUND
/Users/spa/Desktop/work/part 3/dissertation/Key Stage 1 Pictograms.doc: W97M.Walker FOUND
/Users/spa/Desktop/work/part 3/dissertation/Rcher.doc: W97M.Walker FOUND
/Users/spa/Desktop/work/part 3/fraiser project/Civilisation / Chapter1.doc: W97M.Walker FOUND
/Users/spa/Desktop/work/part 3/general/small timetable.doc: W97M.Walker FOUND
/Users/spa/Desktop/work/part 3/information wall/info wall layouts/9am-1.doc: W97M.Walker FOUND
/Users/spa/Desktop/work/part 3/self directed study/brief.doc: W97M.Walker FOUND
/Users/spa/Desktop/work/part 3/self directed study/sds olympic info.doc: W97M.Walker FOUND
/Users/spa/Desktop/work/part 3/series design /waves - the oceanides.doc: W97M.Walker FOUND
/Users/spa/Documents/Microsoft User Data/Normal: W97M.Walker FOUND
/Users/spa/Documents/Speed Download 4/intcodec-v6.541.exe: Trojan.Downloader.Zlob-1208 FOUND
----------- SCAN SUMMARY -----------
Known viruses: 213732
Engine version: 0.92
Scanned directories: 91669
Scanned files: 331193
Infected files: 18
Data scanned: 48772.03 MB
Time: 25927.857 sec (432 m 7 s)

ClamXav v1.1.0 - ClamAV 0.92/5837/Sat Feb 16 17:14:09 2008 - ClamXav

Couple of things I've noticed. All of them bar one are word documents, and this walker virus is something to do with macros. 90% of the word documents above were not created on the mac, they were either mine from my PC (I've scanned my PC btw -its clean), or from lecturers/other students she doesn't know whether the documents would be created in windows or a OSX.

The other virus is a trojan downloader but it's a .exe - I take it thats not a problem because mac's cant execute .exe's, or am I mistaken? (I know sod all about macs and OSX!)

One final question. It says that it has found these 18 files, but it hasn't said that it has cleaned/deleted them. Has it actually done anything or do you have to manually delete them?

Thanks very much.
 
Soldato
Joined
12 Aug 2004
Posts
6,105
Ouch, sounds like your Mac was harbouring PC viruses that wont affect the Mac but could infect any computer you transferred files to.

It should move the files into quarantine, where they can do no damage. They aren't actually deleted.
 
Soldato
OP
Joined
22 Oct 2005
Posts
2,802
Location
Moving...
Well I've just looked up the files, they are still on the mac, they havent been moved anywhere. I havn't opened them or anything though. Is there any way I can "clean" them because some of them are quite important so I dont really want to delete them.

Thanks.
 
Soldato
OP
Joined
22 Oct 2005
Posts
2,802
Location
Moving...
http://www.f-secure.com/v-descs/sattelit.shtml

It is actually an old virus which it works on Win 95 + 98 only. Does that rings any bells?

Yea I had a look at that, I thought I was either reading it wrongly, or reading about a different type of virus. I know that she and I havn't touched windows 95/98 for a good 7 or 8 years now lol. But yes that does seem to be roughly what is happening - I dont think EVERY file that is opened/created is being infected though.

The only thing I'm worried about now is that if she starts working on new work, all this new work will be corrupted by this stuff. How can I clean the system completely?

Thanks again.
 
Last edited:
Soldato
Joined
22 Jan 2005
Posts
2,825
Location
N Ireland
Yea I had a look at that, I thought I was either reading it wrongly, or reading about a different type of virus. I know that she and I havn't touched windows 95/98 for a good 7 or 8 years now lol. But yes that does seem to be roughly what is happening - I dont think EVERY file that is opened/created is being infected though.

The only thing I'm worried about now is that if she starts working on new work, all this new work will be corrupted by this stuff. How can I clean the system completely?

Thanks again.
Ok, it is window virus and I am not sure if it can be spread to other documents in Mac.

The link I posted, says something about the global template in MS Word, I'm not sure what it is. I am under the impression is that if you open the template you use with other documents, then you still have virus there.

To find out, try creating a new document, random typing it, save it as and close it and then scan this file to see if it has a virus or not.
 
Soldato
OP
Joined
22 Oct 2005
Posts
2,802
Location
Moving...
Thanks barnettgs. I've just spotted that one of those files listed as a virus in the list above (/Users/spa/Documents/Microsoft User Data/Normal: W97M.Walker FOUND) is actually a template file. I've since deleted that file so I'm hoping that might the troublesome one. I'll try what you mentioned soon but I'm going to back up all important work before I do anything else.

Thanks again.
 
Soldato
Joined
17 Jan 2007
Posts
8,944
Location
Manchester
I find it very strange that an old virus would be able to infect the template system on the Macintosh side of things. Like barnettgs said: Are you 100% sure that if you create a new file in Office 2004 it is infected?
 
Soldato
OP
Joined
22 Oct 2005
Posts
2,802
Location
Moving...
I find it very strange that an old virus would be able to infect the template system on the Macintosh side of things. Like barnettgs said: Are you 100% sure that if you create a new file in Office 2004 it is infected?
Definately, although in the majority of cases it seems to be existing documents that have been edited are the ones infected.

I have deleted the dodgy looking template file, and since then I have made a new word document, saved it onto my stick and checked it with my AV and its clean so I may be onto something! I ran the virus check again last night and all it found were the infected documents. If I open these infected documents is the virus likely to spread or should it be ok because of got rid of the dodgy template file?

Thanks again.
 
Soldato
Joined
12 Aug 2004
Posts
6,105
Definately, although in the majority of cases it seems to be existing documents that have been edited are the ones infected.

I have deleted the dodgy looking template file, and since then I have made a new word document, saved it onto my stick and checked it with my AV and its clean so I may be onto something! I ran the virus check again last night and all it found were the infected documents. If I open these infected documents is the virus likely to spread or should it be ok because of got rid of the dodgy template file?

Thanks again.

Sounds like the template was the problem. I would have thought you should be ok to open the documents. Save it again in a new place and delete the old infected file.
 
Back
Top Bottom