My very first Mac virus: fake Flip4Mac?

I just received this in my mailbox:


That really, really looks like a virus infiltration attempt. Which is amazing, because although I’ve seen many of those, they always end in a .exe or some such Windows extension. This is the first I’ve seen targeted for Mac.

A quick google reveals that Flip4Mac, which is an actual legit Mac application for viewing Windows Media files, has a vulnerability … but nothing that suggests that there is a virus out there masquerading as Flip4Mac, or Flip4Mac components.

Sounds new. Anyone else seen it yet?

  • That’s pretty weird. Did you unzip it? What’s inside? Or…is that a risky move.
    One thing’s for sure, Telestream doesn’t send Flip4Mac to people via email, unless you’re dealing with their support on and issue and they do that as a process of troubleshooting, or something.
    If you find out more, let us know.

  • I didn’t unzip it … but my buddy Dave Boone told me he was feeling adventurous and wanted to. So I just forwarded it to him, and he’s going to do some forensics on it.

    It’ll be interested to get the results.

  • Just got this email from David Boone, my adventurous (and extremely smart) friend:

    Interesting. It’s simply the Flip4Mac components copied out of /Library/Quicktime and placed into the zip file. I installed the exact same version (from VersionTracker) and compared the files using md5; they were all identical.

    In any case, it’s not a virus (unless the copy from VersionTracker was also infected I suppose), and all us Mac people can continue to stick their nose up at those silly Windows users 😀

    – Dave

  • Wattaminute, I just now got that you didn’t know what Flip4Mac was! Uh, it’s the only way you’ll be able to see Windows Media files in a Microsoftian–approved way from now, is all it is.

    Still, I’d never install anything from a .zip file that wasn’t from the original source.

    On another aside, since Flip4Mac uses the Apple installer, you’ll be missing out on the package receipt if you install it that way. That means if you install the plugin that way, you’ll mess up file permissions on your computer, and that can lead to wonkiness. And you all know how little people like the wonkiness.

    They don’t. They don’t like the wonkiness.

  • Oh, thanks, but I did know that (check out my second-last paragraph). When I got the email, though, I figured that someone was piggybacking on Flip4Mac to distribute a virus of some sort.

  • the term virus can actuaIIy be misIeading because what a program does, if it does something that is not mentioned in its terms of use then perhaps it can be considered a virus based one one’s opinion, however if a program is crated specificIy to damage one’s computer or system, then perhaps it can “CLEARLY” be cIassified as a virus.

  • …unzipping the file could not be harmful, but opening any of the included files then could. Even though there hasn’t yet been a successful attempt at writing an OSX virus, one should always be careful with attachments. If someone you don’t know sends you some weird files, trash them. If someone you do know does so, ask them first what it is.

    Just like in real life…