Trojan-Downloader:OSX/Flashback.I

Has anyone heard of this? Supposedly a sophisticated malware that installs itself several ways and downloads "sniffed" user IDs and passwords to a remote site. This is the link for the news article: http://www.zdnet.com/blog/security/over-600000-macs-infected-with-flashback-troj an/11345


I have a MAC OS X 10.7.3 iMAC and a MAC OS X 10.6.8 laptop.


Supposedly it exploits the JAVA plug-in on any MAC OS X platform.

I have disabled my JAVA plugins and my questions are:

1. How to detect any malware on my machines?

2. How to get rid of it?

3. And if I should change all my online passwords that have the poteential for exploitation?


I am NOT an advanced user but I can follow directions well.


Thanks!

iMac, Mac OS X (10.7.3)

Posted on Apr 5, 2012 5:53 AM

Reply
14 replies

Apr 5, 2012 6:27 AM in response to dianthe

According to this (from Sam) - it's been around for a while and is very LOW risk..


http://www.symantec.com/security_response/writeup.jsp?docid=2011-093016-1216-99


At first I thought the current flurry of news articles looked like a hoax, as some link to instructions on how to go into Terminal and "fix" it - I would not trust any online instructions on how to find/fix anything unless they come from Apple or an extremely reliable source.


Furthermore - if it was a real issue, Apple would release a software update addressing it IMHO.

Apr 6, 2012 1:12 AM in response to dianthe

The malware does require you have an older and unpatched version of Java installed, and then as with other malware requires you visit a malicious Web site (generally done when clicking spam links, or when browsing underground, ****, or warez sites).


This is one of the more prominent malware threats for OS X so far, but is still overall a relatively minor issue. However, a few people have reported finding it on their systems.


The fact is Java's security hole was unpatched in OS X for a while, and was exploited by malware that ended up taking advantage of a number of systems. Overall this is a very small percentage of the Mac install base, but is still a sizeable number.


There are several ways to detect and remove it, though it does somewhat depend on the variant you have encountered. Here is an article that covers some of this: http://reviews.cnet.com/8301-13727_7-57410096-263/how-to-remove-the-flashback-ma lware-from-os-x/

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Trojan-Downloader:OSX/Flashback.I

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.