Topic:   Possible Malware affecting GM and METAL apps?   (Read 5640 times)


0 Members and 1 Guest are viewing this topic.

jeremymaharg


  • GMG Newbie

  • *


  • Posts: 52

  • Jeremymaharg Software
Possible Malware affecting GM and METAL apps?
« on: June 14, 2009, 03:55:40 AM »
Recently, I have encountered errors on my OSX 10.5 iMac when attempting to run anything made in GameMaker. I checked some of the files remotely through my OS9 Mac, and noticed that a large number of apps were modified around 6-13-09 at 11:43-45 PM. The strange thing is that most of these were apps made in GM or METAL (or are GM and METAL), with the occasional unrelated app.

The list of affected apps on my system are:
Quote
Epicus
Spy Mission 0.3 Classic
FotA Preview Carbon
AstroBlaster
GM Toolkit Carbon
Metal
Flame of the Angel Preview
Metal
astroblaster MODDED
Real Life 1.0
Runtime
Spy Mission Carbon
Reallife RPG (Carbon)
GameMaker v3993
Runtime
GM Toolkit Carbon
Quest of Magic
Space Game
Spy Mission 0.3 Carbon
GM Carbonizer v1.1b2
GM Toolkit Carbon
Flame of the Angel Preview
MacLorem 2.0
Supa Pong
ToD Clock 1.1
StarEdit
GameMaker v3994
Reallife RPG (Classic)
GMhttp v1.0 OS X
GameMaker.app
GameMaker v3994 Demo
TAG .app
DREAMING v103
GMOnline v1.3.2
PMO! 3D
Labyrinth
Flame of the Angel 0.7 Carbon
GM Toolkit Carbon
GM Toolkit Carbon
Spy Mission Classic
Story Maker
fwdmov.app
GameMaker v390 Carbon
GM Toolkit Carbon
KEYDOWN CODE FINDER
PasswordLock.app
BinkCarbonPlayer
Gridz
GameMaker v399
Register Online.app
VCDGear

The only non-GM or non-METAL apps on this list are StarEdit (Starcraft), MacLorem (filler text generator), VCDGear (a VCD utility, and BinkCarbonPlayer (a video player). All of these files are all over my hard drive, not in one place.
Space Can Suck was also among the affected apps, but I deleted it right away because something about its behavior in particular made me suspect it may be a stronger threat (attempts to Get Info on it cause the info window to close itself, and the version number was a bunch of garbage characters).

I mght also mention that I recently downloaded, tried, and deleted a demo of LEGO Star Wars for Mac, just in case it may be related to this...

EDIT:
Here's a crash log from an attempt to run a GM game:
Code: [Select]
Process:         Flame of the Angel 0.7 Carbon [893]
Path:            /GAMES/GM Games/Flame of the Angel 0.7/Flame of the Angel 0.7 Carbon
Identifier:      Flame of the Angel 0.7 Carbon
Version:         ??? (32768)
Code Type:       PPC (Translated)
Parent Process:  launchd [863]

Date/Time:       2009-06-14 01:54:14.802 -0500
OS Version:      Mac OS X 10.5.7 (9J61)
Report Version:  6
Anonymous UUID:  1B60132B-00E9-4349-A06D-48C0E886A357

Exception Type:  EXC_CRASH (SIGTRAP)
Exception Codes: 0x0000000000000000, 0x0000000000000000
Crashed Thread:  0

Thread 0 Crashed:
0   ???                          
0x8019d402 0 + 2149176322
1   translate                    
0xb80b6b00 0xb8000000 + 748288
2   translate                    
0xb80b7007 0xb8000000 + 749575
3   translate                    
0xb80d49c0 0xb8000000 + 870848
4   translate                    
0xb813ce79 spin_lock_wrapper + 1981
5   translate                    
0xb8011b64 0xb8000000 + 72548

Thread 1:
0   ???                          
0x800bc286 0 + 2148254342
1   ???                          
0x800c3a7c 0 + 2148285052
2   translate                    
0xb818b6ea CallPPCFunctionAtAddressInt + 202886
3   ???                          
0x800ed155 0 + 2148454741
4   ???                          
0x800ed012 0 + 2148454418

Thread 0 crashed with X86 Thread State (32-bit):
  eax: 0x00000000  ebx: 0xb80b6c78  ecx: 0xb7fff9ac  edx: 0x8019d402
  edi: 0xb8208980  esi: 0x00000005  ebp: 0xb7fff9d8  esp: 0xb7fff9ac
   ss: 0x0000001f  efl: 0x00000246  eip: 0x8019d402   cs: 0x00000007
   ds: 0x0000001f   es: 0x0000001f   fs: 0x00000000   gs: 0x00000037
  cr2: 0x81564000

Binary Images:
0xb8000000 - 0xb81d7fe7  translate ??? (???) /usr/libexec/oah/translate

Translated Code Information:
NO CRASH REPORT
« Last Edit: June 14, 2009, 04:22:00 AM by jeremymaharg »
[url=http://

Al Staffieri


  • GMG-er

  • **

  • no avatar

  • Posts: 452

  • I love GameMaker
Re: Possible Malware affecting GM and METAL apps?
« Reply #1 on: June 14, 2009, 06:42:29 AM »
I wonder if you have some virus that's affecting all non universal binary apps. If you can email me your copy of either GameMaker v3993 or 3994 I'll check it against my version and see if there's anything different.

GMG Mike


  • Administrator

  • GMG-er

  • *****

  • no avatar

  • Posts: 536
    • mikerichardson.name
Re: Possible Malware affecting GM and METAL apps?
« Reply #2 on: June 14, 2009, 08:40:27 AM »
It would appear you have some sort of general malware.

GM Carbonizer, GM Toolkit et. al are made in REALbasic. GameMaker and compiled games are made in FutureBASIC.


jeremymaharg


  • GMG Newbie

  • *


  • Posts: 52

  • Jeremymaharg Software
Re: Possible Malware affecting GM and METAL apps?
« Reply #3 on: June 14, 2009, 11:47:14 AM »
Quote
I wonder if you have some virus that's affecting all non universal binary apps. If you can email me your copy of either GameMaker v3993 or 3994 I'll check it against my version and see if there's anything different.
I emailed you a copy of it.
It appears to have modified the data fork as I mention in the email. I tried copying the last two lines and pasting them into the message as text, but it doesn't appear to have made it into the message...
[url=http://

Telstar5


  • GMG-er

  • **


  • Posts: 371

  • The sun is up, the sky is blue...
Re: Possible Malware affecting GM and METAL apps?
« Reply #4 on: June 14, 2009, 01:33:24 PM »
Oh dear.

It sounds to me like SevenDust, because those are all OS 9 applications.

Good luck trying to rid yourself of that; it took me about two years to get my system totally clean.
« Last Edit: June 14, 2009, 01:33:54 PM by Telstar5 »


jeremymaharg


  • GMG Newbie

  • *


  • Posts: 52

  • Jeremymaharg Software
Re: Possible Malware affecting GM and METAL apps?
« Reply #5 on: June 14, 2009, 01:38:51 PM »
Quote
Oh dear.

It sounds to me like SevenDust, because those are all OS 9 applications.

Good luck trying to rid yourself of that; it took me about two years to get my system totally clean.
Actually, I have had a SevenDust infection before. The characteristics of this one aren't the same as a SevenDust infection.
[url=http://

Telstar5


  • GMG-er

  • **


  • Posts: 371

  • The sun is up, the sky is blue...
Re: Possible Malware affecting GM and METAL apps?
« Reply #6 on: June 14, 2009, 01:59:05 PM »
That's odd.

Unless you've been naughty and gone to any porn sites. Hot off the BBC only two days ago:

http://news.bbc.co.uk/1/hi/technology/8096822.stm


jeremymaharg


  • GMG Newbie

  • *


  • Posts: 52

  • Jeremymaharg Software
Re: Possible Malware affecting GM and METAL apps?
« Reply #7 on: June 14, 2009, 02:05:33 PM »
Quote
That's odd.

Unless you've been naughty and gone to any porn sites. Hot off the BBC only two days ago:

http://news.bbc.co.uk/1/hi/technology/8096822.stm
I noticed this problem right after I finished trying out a demo of LEGO Star Wars, so I think that game was the cause of this problem.
[url=http://

GMG Mike


  • Administrator

  • GMG-er

  • *****

  • no avatar

  • Posts: 536
    • mikerichardson.name
Re: Possible Malware affecting GM and METAL apps?
« Reply #8 on: June 15, 2009, 01:55:40 PM »
Quote
Oh dear.

It sounds to me like SevenDust, because those are all OS 9 applications.

Good luck trying to rid yourself of that; it took me about two years to get my system totally clean.


No. Most of those were Carbon programs. However, none were Carbon Mach-O programs, so whatever it is seems to only be infecting Carbon PEF programs.

jeremymaharg


  • GMG Newbie

  • *


  • Posts: 52

  • Jeremymaharg Software
Re: Possible Malware affecting GM and METAL apps?
« Reply #9 on: June 15, 2009, 04:42:15 PM »
I might add that I later found out that SilverCreator 1.6a9 was also infected, it just didn't show up on the list.
[url=http://

GMG Mike


  • Administrator

  • GMG-er

  • *****

  • no avatar

  • Posts: 536
    • mikerichardson.name
Re: Possible Malware affecting GM and METAL apps?
« Reply #10 on: June 17, 2009, 12:35:31 AM »
Quote
I might add that I later found out that SilverCreator 1.6a9 was also infected, it just didn't show up on the list.

That's weird. It is a Carbon Mach-O app. Totally different inside.