On Tuesday, February 10, 2004, at 03:20 PM, PCI PowerMacs wrote:
Re: Auto-Start WORMs and other viruses
This was an interesting thread....
Well Bruce, I was pretty much of the same mind set as you concerning viruses and my mac - until this morning.
I was under the impression that the auto start virus was only able to infect pre OSX systems anyways - the whole "DB" / desktop print spooler files thing.
Wasn't it created before OSX even hit the scene?
Well apparently some little %%$%^! has been quite busy lately.
I've spent the greater part of today repairing the damage from what may appear to be a variant of this virus? Actually I have no clue what it was.
It came through an email and neither Nortons, Virex or Disinfect caught it during delivery. Came in that typical message marked: mail daemon , undeliverable, fatal errors. Was using the OSX mail app. Normally I would have just trashed it, but the wife was using the comp last night and I figured I would check it out, she's not all that computer savy - real bad idea. Opened it, looked at it, didn't recognize any of the addy's, so I deleted it. Within minutes files started disappearing from the desktop, the apple menu froze, my entire user/admin folder was deleted, started getting errors that I didn't have privileges / access, and then my HD partition with 10.2.8 disappeared. It wouldn't respond to any mouse, keyboard or even a force crash, only thing left to do - against better judgment - was to pull the plug out of the wall. Total time lapse, maybe 5 to 10 minutes.
I was able to boot into 9.2.2 after several attempts - it resides on a different drive, Ran NIV, Virex, and Disinfectant on the OSX drive - didn't seem to infect any other drive or OS, appears to be OSX specific (unix?). I then booted using an OSX boot disk I had made with DiskWarrior on it. I have one of the new G4/800 sonnet cards in this B&W and sonnet says I can't do this without first reinstalling the original zif and removing the firmware update, whatever. DW said their was way to much damage to the drive, the files, the directories, the nodes, etc. DW was then able to recover all of the deleted file (including the original suspect email) and rebuild the drive to perfection - God bless Disk Warrior! Like I said, I have no idea what it was. But I know how I got it and what it did. Is this something new? or a Unix thing? I used to run a HL server a couple of years back and it got hit with sevendust C - my fault I wasn't running protection and someone purposely uploaded it. This incident very closely resembled my sevendust C experience - 2 hard drives went down and I lost a large number of files due to corruption. Thankfully I had it all burned on disk (still have a copy of the SD C also). To sum it all up; I was lucky - this time - I caught it as it was happening, but my attitude concerning Macs and viruses is changing. There will always be some bored, spiteful, malicious, #^$^$!, out there. Beware. Claiming we're impervious to attack makes us a target.
-T-
-- PCI-PowerMacs is sponsored by <http://lowendmac.com/> and...
Small Dog Electronics http://www.smalldog.com | Refurbished Drives | -- Sonnet & PowerLogix Upgrades - start at $169 | & CDRWs on Sale! |
Support Low End Mac <http://lowendmac.com/lists/support.html>
PCI-PowerMacs list info: <http://lowendmac.com/lists/pci-powermacs.shtml> --> AOL users, remove "mailto:" Send list messages to: <mailto:[EMAIL PROTECTED]> To unsubscribe, email: <mailto:[EMAIL PROTECTED]> For digest mode, email: <mailto:[EMAIL PROTECTED]> Subscription questions: <mailto:[EMAIL PROTECTED]> Archive:<http://www.mail-archive.com/pci-powermacs%40mail.maclaunch.com/>
Using a Mac? Free email & more at Applelinks! http://www.applelinks.com
