PDA

View Full Version : HEUR: Trojan.OSX.Vsrch.a


WizardEQ
06-21-2014, 02:45 PM
I've hit a wall on my attempts to install EQ on my macbook.

My '00 desktop finally kicked the bucket, so I don't have access to EQ anymore. In an attempt to install it on my Macbook, I came across this nasty trojan that has taken control of all my systems. I am no expert on macs; I could do work-arounds on my pc well enough.

I've run Sophos which didn't even detect the Trojan. Then I installed AVG which was just a "cleaner" complete garbage. Then I paid for Kaspersky, which only removed 22/28 of the trojans. There are 6 left which I can't get rid off.

Does anyone have experience with removing Trojans in system files on a mac? I don't even know how to get to them, like on the pc. I know there are going to be corrupt .dll files now, but I have absolutely no clue what to do. Any advice would be welcomed.

JayN
06-21-2014, 02:47 PM
reinstalling after being hijacked is your best bet or youll be running some hacked up bullshit with all sorts of problems and errors

phacemeltar
06-21-2014, 02:54 PM
doesnt mac come with customer care or something?

leewong
06-21-2014, 03:25 PM
1. Format the hard drive
2. Reinstall your OS
3. Install EQ and enjoy

If you have data you want backed up:
1. Before formatting, make a new partition on your hard drive and move the files you want backed up there.
2. Format the OS partition only and reinstall the OS
3. Move files back over to the OS partition and expand that partition over the one you were backing files up to.

Bardalicious
06-21-2014, 04:00 PM
Why are there more and more of these virus posts popping up? Is one of the client torrents infected now or something?

Thulack
06-21-2014, 05:12 PM
Why are there more and more of these virus posts popping up? Is one of the client torrents infected now or something?

People do other things on their computers other then play EQ. Surely if they have downloaded EQ from torrent they torrent other things. Maybe the watch porn or visit other sites that give them the viruses.

Ambrotos
06-21-2014, 05:54 PM
There is a torrent download that has a virus/Trojan. Just look for the oldest torrent and use that.

WizardEQ
06-21-2014, 06:37 PM
Ah, thanks Ambrotos. I've never used a torrent except to download EQ. I didn't notice all the versions and just clicked on the first (or most recent one).

I'll retry with the oldest one.

Bardalicious
06-21-2014, 06:43 PM
People do other things on their computers other then play EQ. Surely if they have downloaded EQ from torrent they torrent other things. Maybe the watch porn or visit other sites that give them the viruses.

Thanks for your needless input. As you see by the following 2 posts after you, the answer was yes.

Thulack
06-21-2014, 07:16 PM
Thanks for your needless input. As you see by the following 2 posts after you, the answer was yes.

well 2 posts in this section in last 4 months about viruses i wouldnt call popping up more and more. You would think there would be tons of posts about it if a copy on there that was widely downloaded had a virus. So yes i will eat my words on this one but not regret saying it.

Derubael
06-21-2014, 08:07 PM
There is a torrent download that has a virus/Trojan. Just look for the oldest torrent and use that.

If there's a legitimate Trojan (and not just a false positive, though there shouldn't be on a non-cracked game like EQ), if enough people report the torrent as malicious it will get taken down.

Derubael
06-21-2014, 08:07 PM
Oh, and in response to your Trojan question, OP, best solution is to restart. If you don't already know what you're doing you're going to end up screwing up more than you fix if you go in and try to remove these yourself :D

WizardEQ
06-21-2014, 10:41 PM
Well, good news! I finally was able to download the correct torrent AND get EQ up and running on my macbook.

Bad news, the little shit is still bouncing around my webpages. I've done some more research and it evidently is not technically a virus, more like adware, which is so shitty when I open pages. I have chinese wives now popping up on my google page.

I have never had an issue with my macbooks and any sort of adware/virus/spyware. I guess eventually I can bring it to my admin and have them do a full reinstall.

Derubael
06-21-2014, 10:43 PM
https://www.malwarebytes.org/

should still be pretty good at removing malware.

http://www.lavasoft.com/products/ad_aware_free.php

for ad-ware

WizardEQ
06-21-2014, 10:46 PM
If there's a legitimate Trojan (and not just a false positive, though there shouldn't be on a non-cracked game like EQ), if enough people report the torrent as malicious it will get taken down.

It is legit malware hidden in a trojan (maybe I made that up, but it is some sort of malicious program that causes popups and redirects now on my mac). It was from the 2013 torrent. I've since download the 2007 one, and got EQ to install seamlessly.

Bardalicious
06-21-2014, 10:48 PM
Was it from the CaseyEQ uploader on the bay?

Tasslehofp99
06-21-2014, 11:22 PM
I've used ESET online scanner for shit like that pretty successfully in the past.


Have you tried that?

Ambrotos
06-22-2014, 12:15 AM
I wouldn't trust anything from CaseyEQ in or outside of game.

WizardEQ
06-22-2014, 01:12 AM
I wouldn't trust anything from CaseyEQ in or outside of game.


Yes, it was the CaseyEQ one.

WizardEQ
06-22-2014, 11:35 AM
I'm looking for a mac expert who can close backdoors. The trojan reconfigured my browsers to create fake addresses through a backdoor, which needs to be eliminated.

India
06-22-2014, 01:56 PM
Ugh, good luck getting it taken care of :(

Sirken
06-22-2014, 02:14 PM
this:
1. Format the hard drive
2. Reinstall your OS
3. Install EQ and enjoy

If you have data you want backed up:
1. Before formatting, make a new partition on your hard drive and move the files you want backed up there.
2. Format the OS partition only and reinstall the OS
3. Move files back over to the OS partition and expand that partition over the one you were backing files up to.

and also this:
There is a torrent download that has a virus/Trojan. Just look for the oldest torrent and use that.

and finally:
I wouldn't trust anything from CaseyEQ in or outside of game.

Smedy
06-22-2014, 02:41 PM
LOL you clearly didn't get the backdoor from casey's files unless someone else intercepted the torrent and recreated it, i highly doubt case would spread viruses

Pretty sure you got it from when you were browsing for the torrent, many ad-sites pirate site uses are constantly getting hijacked with javascript exploits that will inject into your browser unless updated

i wouldn't tell you to get an antivirus just get noscript and deal with the pain of having to manually approve every script that runs in your browser, but on the other hand, you'll be 100% secure (unless you allow viruses ofcourse)