Home
Reviews
Forums
New Games
Podcast
• submit tip •
  #1  
Old 04-09-2012, 10:39 AM
CygnetSeven's Avatar
CygnetSeven CygnetSeven is offline
Moderator
iPhone 5, iOS 6.x
 
Join Date: Feb 2010
Location: Planet 10 (by way of the 8th dimension)
Posts: 4,790
Default Flashback Virus For Mac Users

This article is copied from Forbes:

With the Flashback malware now estimated to have control of some 1 percent of Macs, owners are understandably panicked by the idea that their computer could be part of the biggest botnets in history.

That 1 percent number isn’t hype or pulled out of the air either. Ed Bott over on ZDNet does the math:

With 600,000 infections in a user base of 60-70 million, that means roughly 1% of all Macs worldwide have been hit by this thing, which is capable of downloading additional malware at will.

That is a huge percentage, an is testament to how fast this malware spread and how quiet it has been compared to previous examples of Mac malware such as Mac Defender (which spawned fake security dialog boxes and demands for cash).

Compare this to Conficker, the single largest Windows-based infection, which at its peak in 2009 hit some 7 million PCs, or some 0.7 percent of the total Windows user base.

Yesterday I posted a link to the Finnish security site F-Secure, which offered users a way to check if their Mac was infected. Problem with these instructions was that they were too complicated for the average user to follow. They involved using Terminal and typing a lot of commands.

Fine for power users, but not for the average Mac users.

Fortunately, now there’s an easier way to scan your system for Flashback. Called FlashbackChecker, it is a small tool that you download, extract and run. It WILL NOT remove Flashback, but it will tell you if you are infected or not. If your system is clean, then as long as you’ve applied all the updates for your Mac, you’re safe.

Note: You need to run this checker tool on all user accounts on your Mac.

But what if you’re infected? Given you seem to have a 1 in 100 chance of having this nasty on your system sniffing passwords, you need to be ready for that possibility. If you are unlucky then you have two options open to you.

The first is the manual removal method as outlined by F-Secure. If you didn’t like the Terminal method for checking to see if your Mac was infected with Flashback, you’re definitely not going to like this. It’s multi-step and quite involved.

Alternatively, you could download and install the 30-day trial of the Mac antivirus program VirusBarrier X6 from Intego or the free Sophos Anti-Virus for Mac Home Edition which should clean up your system for you. After it’s done the job, you might want to consider leaving the antivirus program on your system so you’re covered when it comes to future threats. Because, after all, future threats are likely.

If you have a Mac, I strongly suggest that you check if it’s infected with Flashback, because this malware is real, is nasty, and is on your system to grab usernames and passwords. Check your system, deal with any problems, make sure your patches are applied, and get on with your life.

Link for FlashbackChecker: https://github.com/jils/FlashbackChecker/wiki

Manual Removal of Flashback: http://www.f-secure.com/v-descs/troj...shback_k.shtml

Virus Barrier X6 from Intego: http://www.intego.com/virusbarrier

Sophos Anti Virus for Mac: http://www.sophos.com/en-us/products...e-edition.aspx

Note: I ran FlashbackChecker this morning and I was clean, I updated Java immediately. Hopefully all you will have the same results but I thought this info should be posted. Good luck!
Reply With Quote
  #2  
Old 04-09-2012, 03:44 PM
Rasec Noir Rasec Noir is offline
Member
iPad 2, iOS 5.x
 
Join Date: Jan 2012
Location: Porto, Portugal
Posts: 45
Send a message via Skype™ to Rasec Noir
Default

Thanks for the info. ^^
I tried on my imac and it gave negative.
Reply With Quote
  #3  
Old 04-09-2012, 05:02 PM
Spamcan Spamcan is offline
Senior Member
iPhone 4S, iOS 5.x
 
Join Date: Jan 2010
Location: The distant future year 1999
Posts: 1,003
Default

My system is clean but I'm not thrilled that I might have to run persistent anti-virus software on my Mac like some filthy Windows user if this trend continues.
Reply With Quote
  #4  
Old 04-09-2012, 05:14 PM
squarezero squarezero is offline
Moderator
 
Join Date: Dec 2008
Location: Salem, Massachusetts, USA
Posts: 10,478
Default

Quote:
Originally Posted by Spamcan View Post
My system is clean but I'm not thrilled that I might have to run persistent anti-virus software on my Mac like some filthy Windows user if this trend continues.
As some have suggested, turning off Java and using Chrome when you need to look at a Flash site might be enough for now. I also checked this morning and my Mac was clean.
Reply With Quote
  #5  
Old 04-10-2012, 12:06 AM
Spamcan Spamcan is offline
Senior Member
iPhone 4S, iOS 5.x
 
Join Date: Jan 2010
Location: The distant future year 1999
Posts: 1,003
Default

Quote:
Originally Posted by squarezero View Post
As some have suggested, turning off Java and using Chrome when you need to look at a Flash site might be enough for now. I also checked this morning and my Mac was clean.
This isn't the first Mac virus to make the rounds recently it's simply the first that can install itself without somehow tricking the user into entering their account password. If the Mac becomes an active target for viri then in the long run installing anti-virus software will become necessity. In the past five years I've run a virus scan on my iMac three times and have never been infected, that's a huge difference from the compulsive weekly scan I used to do as a Windows user.
Reply With Quote
  #6  
Old 04-10-2012, 03:43 PM
Teknikal Teknikal is offline
Senior Member
iPod Touch (3rd Gen), iOS 5.x
 
Join Date: Oct 2010
Location: Belfast N Ireland
Posts: 1,768
Default

Just read Apple legally tried to get the site shut down of the researchers who actually found this thing. So instead of trying to fix the problem they are just trying to bury it and making enemies of people who tried to help them.
Reply With Quote
  #7  
Old 04-10-2012, 04:38 PM
pluto6 pluto6 is offline
Senior Member
iPhone 4, OS 4.x
 
Join Date: Jun 2009
Posts: 4,223
Default

As Apple and Macs become more popular, this is going to happen more. It's not that OS is better, it's just not targeted nearly as often. I've relegated myself to installing NAV much as I hate to, but I've had ID theft once, and like any crime, being a victim once, is one too many times.
Reply With Quote
  #8  
Old 04-10-2012, 05:10 PM
x999x x999x is offline
Senior Member
iPhone 3G, OS 3.x
 
Join Date: Oct 2009
Posts: 598
Default

Just make Macs more expensive and we'll go back to the gated community we once loved, you know, before hackers could afford them <3
Reply With Quote
  #9  
Old 04-11-2012, 01:31 PM
Watabou Watabou is offline
Senior Member
iPhone 5, iOS 6.x
 
Join Date: Dec 2008
Posts: 707
Default

Quote:
Originally Posted by Spamcan View Post
This isn't the first Mac virus to make the rounds recently it's simply the first that can install itself without somehow tricking the user into entering their account password. If the Mac becomes an active target for viri then in the long run installing anti-virus software will become necessity. In the past five years I've run a virus scan on my iMac three times and have never been infected, that's a huge difference from the compulsive weekly scan I used to do as a Windows user.

I'd like to clear some misconceptions. This is not a virus. It is a trojan. Trojan ≠ virus. A virus won't even ask for your password or anything. It will install by itself, run by itself and do what it needs to without admin privileges. At this point in time, no such program for a mac exists.

Sure trojans are becoming more frequent for macs but you just have to be careful what you download and what you give permission to. I wouldn't run a anti-virus software yet. It will just slow down your mac and will ruin the experience more than anything.


Also, a word of warning: AVOID Sophos. That software has been shown to actually increase vulnerability since it runs with root privalages. More information about that here: http://forums.macrumors.com/showpost...0&postcount=31

If you WANT to use an antivirus software, use ClamXav, since that doesn't use root privileges.

Last edited by Watabou; 04-11-2012 at 04:20 PM..
Reply With Quote
  #10  
Old 04-11-2012, 02:09 PM
crunc crunc is offline
👮 Spam Police 🚓
iPhone 4
 
Join Date: Aug 2008
Posts: 3,616
Default

Does this malware require you to give permission for it to be installed, or does it install without that due to the flaw in Java? Apple released an update to Java which closed a security flaw, so my presumption was that it was using that flaw to install itself. Not true?
Reply With Quote

Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


iPhone Game Reviews | iPhone Apps

All times are GMT -5. The time now is 12:28 AM.