The First Mac Virus? (A New OS X Trojan)

Indyan

Adept
Have a look at this thread at Macrumours.
On the evening of the 13th, an unknown user posted an external link to a file on MacRumors Forums claiming to be the latest Leopard Mac OS X 10.5 screenshots. The file was named "latestpics.tgz"

The resultant file decompresses into what appears to be a standard JPEG icon in Mac OS X but is actually a compiled Unix executable in disguise. An initial disassembly (from original discussion thread) reveals evidence that the application is virus-like or was designed to give that impression. Routines listed include:

_infect:
_infectApps:
_installHooks:
_copySelf:

The exact consequences of the application are unclear, but according to the users that originally executed the application have noted that it appeared to self propogate:

If anyone remembers last night, when lasthope spread that picture that opened in terminal. I just turned on my other computer and it said it had an incoming file, from my computer, which was the latest pics file. Any help. I have already secure deleted it off of my harddrive, but how do i know that it will not come back.
Andrew Welch who had done some of the initial disassembly is posting updates to this thread.

According to the initial investigation, the application uses Spotlight to find the other applications on the infected machine and subsequently inserts a stub of code into each application executable.

Update: It appears that there is some debate about the classification of this application, and as it does require user activation, it appears to fall into the Trojan classification, rather than self-propogating through any particular vulnerability in OS X.
Source
 
Microsoft recently made a change to the licence agreement saying that a new motherboard is equal to a new computer, hence you need to purchase a new Windows licence.

Here is what Microsoft has to say:

“An upgrade of the motherboard is considered to result in a “new personal computer” to which Microsoft® OEM operating system software cannot be transferred from another computer. If the motherboard is upgraded or replaced for reasons other than a defect, then a new computer has been created and the license of new operating system software is required.”

The reason Microsoft gave for this term is that “Microsoft needed to have one base component “left standing” that would still define that original PC. Since the motherboard contains the CPU and is the “heart and soul” of the PC, when the motherboard is replaced (for reasons other than defect) a new PC is essentially created.”

Microsoft sent a memo to its OEM partners asking them to enforce this new policy, every time they upgrade a computer for a client.
Source
 
Back
Top