The ModMyTM Family of Sites:
ModMyMotoModMyiModMyGphone





 
 
Register or Connect with Facebook

Discuss AppStore Apps | Browse / Search Cydia | MMi Cydia Stats




  Apple, iPhone & iPad Forums, Mods, Guides, News, Themes, Downloads, and more! | ModMyi.com > iPhone > iPhone News
Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 11-25-2009, 03:53 AM
nickhesson's Avatar
MMi Staff Writer
 
Join Date: Jun 2009
Device + Firmware: iPhone 3G 3.1.2 JB w/ PwnageTool
Operating System: Mac OS X Snow Leopard, Windows 7, Windows XP
Location: Calgary
Posts: 232
Thanks: 7
Thanked 147 Times in 60 Posts
Send a message via AIM to nickhesson Send a message via MSN to nickhesson Send a message via Skype™ to nickhesson
Got Worms? How to Clean your Infected iPhone

Click the image to open in full size.

Recently we covered an article about the new iPhone worm that has been going around which affects users with OpenSSH installed and have not changed the default password. It started off innocent and escalated to something more threatening.

While there is of course the ability to change your password, some of you might not be so lucky and worms could be crawling your iPhone. Do not fret, as today I bring you some options for cleaning your iPhone. While not all of these options will bring you success, at least you'll know what your options are.

You'll need to download a copy of MobileTerminal from Cydia before hand, so if you don't already have that, go grab it now.

There are three worms currently going around, and of course lucky for us, each one requires a different fix.

Open MobileTerminal and use these commands to delete the unwanted files. These commands are case-sensitive.

1. The ikee/Rick Astley worm

This crude worm is non-threatening but unfortunately very ugly to look at.

In order to fix this ridiculous worm, we'll need to start up MobileTerminal and get into the root account directory. You will be required to enter a password. If you haven't changed it yet, the password is "alpine." Enter the following into MobileTerminal pressing enter after each command.

Quote:
su root

rm /bin/poc-bbot

rm /bin/sshpass

rm /var/log/youcanbeclosertogod.jpg

rm /var/mobile/LockBackground.jpg

rm /System/Library/LaunchDaemons/com.ikey.bbot.plist

rm /var/lock/bbot.lock
If your phone stll has the picture of Rick Astley, unfortunately it can get tricky and messy, but you will need to remove these files as well to get rid of Rick.

Quote:
rm /usr/libexec/cydia/startup

rm /usr/libexec/cydia/startup.so

rm /usr/libexec/cydia/startup-helper

rm /System/Library/LaunchDaemons/com.saurik.Cydia.Startup.plist
The downfall to removing these last few files will require you to reinstall Cydia unfortunately.

2. iPhone/Privacy A:

This bad boy likes to grab your personal information and send it to whomever it wishes

Slimy one this one is. In order to remove this stinky worm, you'll need to use an AntiVirus program. Intego's VirusBarrier X5 works great on the Mac and will catch it no problem. Unfortunately those on a PC don't get any useful tips on what virus program will detect this, but if you know, feel free to share your tip!

Of course you could also do a restore and that would solve your problem, but doing so you may lose personal information. Of course if you go this route, and install OpenSSH again, please for the love of god change your password.


3. The Third Worm (Insert Snappy Virus Name):

This one is a bit more rare and pertains more to your location.
It copies personal data from your iPhone and also redirects online banking customers of a Dutch bank to a phishing web site.

Unfortunately I have no good news for you if your looking for a quick fix on this one. You'll need to do a full restore to remove this pesky bugger. And of course the same applies, if you Jailbreak again, please for the love of god change your password!

UPDATE: A user in the replies has noted the following:
Quote:
I read somewhere a couple of days ago (you'd have to google for it to confirm this) that the worm that redirects you to a fake bank website also changes your root password to "ohsh1t" (but the 1 is really an i, you get the idea). I don't know if this is the worm you have, but I'm just trying to help out...
If you have any other tips for removing these worms, please share your experiences. I have yet to even talk to someone who has been affected by one of these, so no true experiences to share.

Thanks to iSmashiPhone for the de-worming tips.

Check out our previous coverage on these Worms:

Malicious Worm Takes Aim at Jailbroken iPhones
Malware Allows Access to Jailbroken iPhones
Aussie Worm Rickrolls Jailbroken iPhones

Last edited by nickhesson; 11-25-2009 at 05:27 PM..
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
The Following User Says Thank You to nickhesson For This Useful Post:
evilgeniusmojo (11-25-2009)
  #2  
Old 11-25-2009, 04:03 AM
metaljay's Avatar
iPhone? More like MyPhone
 
Join Date: Nov 2007
Device + Firmware: iPhone 3GS 32GB 4.0 ;)
Operating System: MBP 10.6.X + Windows 7
Location: England
Posts: 226
Thanks: 8
Thanked 5 Times in 5 Posts

could you not install the 'iphone firewall' i forgot the name on cyida, and block all outgoing connections lol???
surely this would stop the worm in its tracks
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #3  
Old 11-25-2009, 04:13 AM
nickhesson's Avatar
MMi Staff Writer
 
Join Date: Jun 2009
Device + Firmware: iPhone 3G 3.1.2 JB w/ PwnageTool
Operating System: Mac OS X Snow Leopard, Windows 7, Windows XP
Location: Calgary
Posts: 232
Thanks: 7
Thanked 147 Times in 60 Posts
Send a message via AIM to nickhesson Send a message via MSN to nickhesson Send a message via Skype™ to nickhesson

Quote:
Originally Posted by metaljay View Post
could you not install the 'iphone firewall' i forgot the name on cyida, and block all outgoing connections lol???
surely this would stop the worm in its tracks
Actually, that would probably work. However, If I ever got the worm, I would want it out of my system for sure, not just masking it.

And Firewall IP would be a $2.49 fix, when you could just fix it for free That is if you didn't already have Firewall IP
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #4  
Old 11-25-2009, 04:54 AM
What's Jailbreak?
 
Join Date: Nov 2009
Device + Firmware: 3.1
Posts: 2
Thanks: 0
Thanked 0 Times in 0 Posts

How do I change my password? I just got the Iphone and a buddy set up everything for me(blackrain, cydia, *********, etc)

Thanx

jus found it in the forums but whats the old password?

OOps. I got it. Didnt see it above. Great forum

Last edited by dklst; 11-25-2009 at 04:54 AM.. Reason: Automerged Doublepost
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #5  
Old 11-25-2009, 05:01 AM
nickhesson's Avatar
MMi Staff Writer
 
Join Date: Jun 2009
Device + Firmware: iPhone 3G 3.1.2 JB w/ PwnageTool
Operating System: Mac OS X Snow Leopard, Windows 7, Windows XP
Location: Calgary
Posts: 232
Thanks: 7
Thanked 147 Times in 60 Posts
Send a message via AIM to nickhesson Send a message via MSN to nickhesson Send a message via Skype™ to nickhesson

Quote:
Originally Posted by dklst View Post
How do I change my password? I just got the Iphone and a buddy set up everything for me(blackrain, cydia, *********, etc)

Thanx

jus found it in the forums but whats the old password?

OOps. I got it. Didnt see it above. Great forum
default password is alpine

Last edited by nickhesson; 11-25-2009 at 12:58 PM..
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #6  
Old 11-25-2009, 05:47 AM
Green Apple
 
Join Date: Jul 2009
Posts: 53
Thanks: 0
Thanked 11 Times in 6 Posts

what i want to know is how can i tell if i have the 2nd and 3rd worm?
the first one is pretty easy to detect - but those two...
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #7  
Old 11-25-2009, 07:52 AM
What's Jailbreak?
 
Join Date: Jan 2008
Posts: 13
Thanks: 1
Thanked 0 Times in 0 Posts

can i get that worm i didn't install that open SSH?
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #8  
Old 11-25-2009, 08:16 AM
mgebara's Avatar
Green Apple
 
Join Date: Dec 2007
Device + Firmware: Motorola STAR-TAC
Operating System: Mac OS9
Posts: 42
Thanks: 1
Thanked 4 Times in 3 Posts

Quote:
Originally Posted by pdogg626 View Post
can i get that worm i didn't install that open SSH?
Nope you're good since the worms need ssh to get into your phone.
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #9  
Old 11-25-2009, 09:03 AM
What's Jailbreak?
 
Join Date: Nov 2009
Posts: 2
Thanks: 0
Thanked 0 Times in 0 Posts

how do you change the default password? This increase in malicious software is starting to freak me out. I hate restoring my phone.
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #10  
Old 11-25-2009, 09:59 AM
What's Jailbreak?
 
Join Date: Nov 2009
Posts: 15
Thanks: 2
Thanked 0 Times in 0 Posts

Quote:
Originally Posted by -=viper=- View Post
what i want to know is how can i tell if i have the 2nd and 3rd worm?
the first one is pretty easy to detect - but those two...
x2 i would like to know this as well...
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #11  
Old 11-25-2009, 10:12 AM
What's Jailbreak?
 
Join Date: Jul 2009
Operating System: mac
Posts: 4
Thanks: 0
Thanked 0 Times in 0 Posts

no, its alpine, not apline
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #12  
Old 11-25-2009, 10:36 AM
hollow0's Avatar
iPhoneaholic
 
Join Date: Jun 2008
Device + Firmware: iPhone 3G[S] 32gig Sexy White OS 3.1 pwnage
Operating System: OS X SL / Windows 7 Pro, XP Pro
Location: Tampa, FL
Posts: 453
Thanks: 22
Thanked 21 Times in 20 Posts

thank goodness i've already changed my password. It's the first thing i did after installing it!
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #13  
Old 11-25-2009, 10:41 AM
What's Jailbreak?
 
Join Date: Jul 2009
Operating System: mac
Posts: 4
Thanks: 0
Thanked 0 Times in 0 Posts

i was talking to nickhesson
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #14  
Old 11-25-2009, 10:43 AM
iPhone? More like MyPhone
 
Join Date: Jan 2008
Posts: 229
Thanks: 7
Thanked 7 Times in 7 Posts

How do you change your password?
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #15  
Old 11-25-2009, 10:46 AM
What's Jailbreak?
 
Join Date: Jul 2009
Operating System: mac
Posts: 4
Thanks: 0
Thanked 0 Times in 0 Posts

look at the article up page
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
Reply

  Apple, iPhone & iPad Forums, Mods, Guides, News, Themes, Downloads, and more! | ModMyi.com > iPhone > iPhone News

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Go to Top
ModMyI

All times are GMT -6. The time now is 11:03 AM. Powered by vBulletin® Version 3.8.4
If you need Dedicated Server Hosting, you should check out SingleHop. | Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.0
Copyright © 2007-10 by ModMy, LLC. All rights reserved.

iPhone News / iPhone Forums / Apple News / Apple Forums / iPad News / iPad Forums / Cydia Hosting /
RSS / Contact Us / / Top