Mac Attack! Virus/Spyware/Hack?

Soldato
Joined
10 Jul 2008
Posts
8,315
Hi guys, help much appreciated on this one sorry for long post.

I'm currently helping my friend with a problem he has had on his MacBook. The situation is this; he uses it for ALL of his work/coursework for Uni and had a load of saved files in some folders. He's asked me if I can have a look at it because all of his files have dissappeared, the internet "goes funny" and he thinks he has a virus.
He's in a complete state about this as thinks he is going to fail his course as has no backups - the usual situation when things go bad ;)

Ok, so first thoughts from me were "shame I know nothing about macs but hopefully I'll pick it up" and "I thought the whole point in Macs were that nobody had exploited them yet with viri and/or spyware etc" or atleast that it was rare to pick anything up?
The thing that kicked all of this off about a week ago was that he clicked on one of those "there is spyware/virus on your computer, would you like to clean/disinfect now CLICK HERE". He went and clicked on the message and then folowed the instructions to "clean" his machine. Yep, so he basically infected it with spyware, but he said that when this was happening it was saying it was for Windows XP, so I'm not sure what has happened here. Basically he now has some sort of spyware/virus on the machine.

I had a look at the mac and I cannot see these supposed files anywhere, and it really does look like they are gone for good. I noticed that the built in mac scan said there were some viruses, but have been cleaned. The machine behaves fairly normally in terms of performance and use, apart from when you get to Internet Exporer. Quite often during navigation to a site, you will not end up at the site you wanted to go to and will be redirected to some movie trailer site, an ebay ad about macs, some random IP will flahs up in the url on a redirect. Its basically a typical looking spyware/malware situation but on a mac.
Now.....with windows XP I would be looking in msconfig for things that run at bootup, add/remove programs for removing said program, running spybot search and destroy, virus check etc. What is the best way of looking at this problem on a mac?
Currently as a matter or urgency and priority I have removed the hard disk drive from the Mac and I have hooked it up to my XP machine using MacDrive so I can view the file system on the disk. I am now running "getdataback" utility to scan and try to salvage any recently deleted files. What kind of a virus/spyware would remove a load of files under the users profile? These were just folders on the users desktop that had a load of stuff in. Is it possible all this occured when he was wirelessly connected to an internet and someone hacked because of this spyware that he installed?

Any advice with this would be much appreciated. It's a MacBook white mac...errr.....can't say much else about it. Bougth about a year ago.

Cheers
 
google searching "files disappear from mac desktop" gives several hits, but no mentions of viruses.

http://discussions.apple.com/thread.jspa?threadID=1334005&tstart=3044 for instance - though probably no use to you.

Good luck! And tell your mate to BACK UP BACK UP BACK UP!!

Is he using Internet Explorer? Is he using XP on the MacBook? Did he have MacDrive installed in the XP partittion? If so then a standard XP virus would have access to his mac files...
 
Last edited:
Sorry I should have made it more clear, no he does NOT have XP installed on the MAc, just normal mac OS. It is me that has installed Macdrive on my XP laptop and am trying to recover data off of it. I have tried using getdataback utility, and it took like 4 hours to scan the drive and I could see it working away finding things and then when it got to step 2 where you select a file system, it can't find any, despite that it could originally find all the info on the Mac hard disk. So I think this is because it is a mac drive it does not work. I probably should install the equivalent getdataback kind of utility on the actual Mac and try it on there really.
Right now I am using file scavenger instead to see if I have any more joy with that. Then I will put the disk back in the mac to see if I can attempt recovery on that, but normally I think it is best to load the drive you are trying to recover from as a slave and not the actual OS drive like it would be in the mac.
 
Go look in the Applications folder.. delete everything that isn't essential.

Go in to System Preferences > Users > Login items.. then take off anything that is starting up on boot.

Smack your friend around the head for being a complete tool.
 
Go look in the Applications folder.. delete everything that isn't essential.

Go in to System Preferences > Users > Login items.. then take off anything that is starting up on boot.

Smack your friend around the head for being a complete tool.

:p

Amen sister!
 
I think maybe the loss of the files might not even be to do with this spyware. The disk seems to have some bad sectors during scans for files with recovery programs so maybe they have dissappeared due to disk issues. They would all be in users/nopassword/desktop/XfoldernameX
But whenever I try to recover anything it locks up. The best I have got is some files recovered but the program (file scavenger) is only shareware so will only recover files under 64kb :( and all of those are in a massive long list of which half dont even open. Majority are OS files.
I think it might be worth trying to run such recovery programs on the actual mac installing them on an external drive to run from.
 
Just for future ref, the piece of spyware was common amongst macs after a google search and scouting about on some mac forums. It was a dns redirector trojan, that only took effect during search engine results. The results from a search would be redirected to dodgey sites. There is a particular tool to remove this you can download. As for the missing files, I tried various recovery tools and programs with both the hdd as a slave and whilst booted up in OS X on that drive, and I couldn't get anything. Not sure if it was even related to the spyware.
Cheers
 
Back
Top Bottom