Apple Event: May 7th at 7 am PT

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Flashback trojan

How do i find out if i have flashback trojan. Simple explanation please

iMac, Mac OS X (10.6.8)

Posted on Apr 5, 2012 12:42 PM

Reply
Question marked as Best reply

Posted on Apr 5, 2012 1:16 PM

If you install the java Update from auto Update it Will be removed if you do

30 replies

Apr 6, 2012 8:30 PM in response to Deb7000000

Sorry I'm not sure what I'm looking at either. How does this look for the third and fourth commands?


alex-johnsons-MacBook-Pro:~ alexjohnson$ ls -la ~/Library/LaunchAgents

total 32

drwxr-xr-x 6 alexjohnson staff 204 Sep 10 2011 .

drwx------+ 35 alexjohnson staff 1190 Apr 6 21:50 ..

-rw-r--r-- 1 alexjohnson staff 572 Apr 14 2011 com.apple.FTMonitor.plist

-rw-r--r-- 1 alexjohnson staff 411 Feb 10 2011 com.apple.imagent.plist

-rw-r--r-- 1 alexjohnson staff 447 Feb 10 2011 com.apple.marcoagent.plist

-rw-r--r-- 1 alexjohnson staff 808 Sep 10 2011 com.google.keystone.agent.plist

alex-johnsons-MacBook-Pro:~ alexjohnson$ grep "/Users/" ~/Library/LaunchAgents/*/Users/alexjohnson/Library/LaunchAgents/com.google.keys tone.agent.plist: <string>/Users/alexjohnson/Library/Google/GoogleSoftwareUpdate/GoogleSoftwareUp date.bundle/Contents/Resources/GoogleSoftwareUpdateAgent.app/Contents/MacOS/Goog leSoftwareUpdateAgent</string>

Apr 6, 2012 9:33 PM in response to afromar

I had revised the fourht command to the following later in this thread because the original grep was showing too much:


grep "/Users/$USER/\..*" ~/Library/LaunchAgents/*


This one produces a lot less for its results. In your case it woudn't have produced anything. I don't see what these are looking for in your list.

Apr 7, 2012 10:05 AM in response to X423424X

Thanks for all of the help so far - much appreciated.


For the last grep command, when you say "shouldn't have produced anything," can we expect a "does not exist" return or is there really nothing at all?


Ex:

ray-imac-3:~ leah$ grep "/Users/$USER/\..*" ~/Library/LaunchAgents/*

ray-imac-3:~ leah$


Also, I received the following for the third command. I'm not entirely sure what I'm looking at, so any help is fantastic.


ray-imac-3:~ leah$ ls -la ~/Library/LaunchAgents

total 40

drwx------ 7 leah staff 238 Apr 6 13:57 .

drwx------@ 50 leah staff 1700 Dec 13 09:21 ..

-rw-r--r-- 1 leah staff 589 Nov 8 2009 com.adobe.ARM.32fc92aadecf45c6150edfbd059d518c174248ca67bf63e4a9386b86.plist

-rw-r--r-- 1 leah staff 618 Nov 9 07:29 com.apple.AddressBook.ScheduledSync.PHXCardDAVSource.A2BC506E-6C89-4202-A8BF-6A 6976DF5E23.plist

-rw-r--r-- 1 leah staff 425 Feb 1 08:36 com.apple.FolderActions.enabled.plist

-rw-r--r-- 1 leah staff 517 Apr 6 13:57 com.apple.FolderActions.folders.plist

-rw------- 1 leah staff 813 Sep 19 2010 com.apple.SafariBookmarksSyncer.plist


Thanks!

Apr 7, 2012 12:24 PM in response to mikelberry

mikelberry wrote:


Thanks for all of the help so far - much appreciated.


For the last grep command, when you say "shouldn't have produced anything," can we expect a "does not exist" return or is there really nothing at all?


Ex:

ray-imac-3:~ leah$ grep "/Users/$USER/\..*" ~/Library/LaunchAgents/*

ray-imac-3:~ leah$


Exactly what I said, it had no results so it didn't find what it was looking for, thus it looks ok.

Mar 15, 2013 5:09 PM in response to X423424X

Does this one look clean.

My antivirus is going crazy about the com.valvesoftware.steamclean.plist



2013-03-15 20:04:28.028 defaults[296:707]

Domain /Users/jackson/.MacOSX/environment does not exist

Jacksons-MacBook-Pro:~ jackson$ defaults read /Applications/Safari.app/Contents/Info LSEnvironment

ls -la ~/Library/LaunchAgents

grep "/Users/" ~/Library/LaunchAgents/*

2013-03-15 20:04:28.050 defaults[297:707]

The domain/default pair of (/Applications/Safari.app/Contents/Info, LSEnvironment) does not exist

Jacksons-MacBook-Pro:~ jackson$ ls -la ~/Library/LaunchAgents

total 24

drwxr-xr-x 4 jackson staff 136 Mar 15 19:59 .

drwx------@ 51 jackson staff 1734 Mar 10 11:34 ..

-rw-r--r--@ 1 jackson staff 6148 Mar 15 19:56 .DS_Store

-rw-r--r-- 1 jackson staff 767 Mar 15 19:59 com.valvesoftware.steamclean.plist

Jacksons-MacBook-Pro:~ jackson$ grep "/Users/" ~/Library/LaunchAgents/*

<string>/Users/jackson/Library/Application Support/Steam/SteamApps/steamclean</string>

<string>/Users/jackson/Library/Application Support/Steam/SteamApps/steamclean</string>

<string>/Users/jackson/Library/Application Support/Steam/SteamApps</string>

Mar 15, 2013 11:57 PM in response to CaesarCalad

First, this tread is almost a year old and the methods outlined here no longer reflect the correct way to remove subject malware.

CaesarCalad wrote:


Does this one look clean.

My antivirus is going crazy about the com.valvesoftware.steamclean.plist

What antivirus and I'm guessing the infection name is something similar to Trojan.flashback?


What OS X are you using? Are you on an intel Mac, as this forum seems to indicate?


The appropriate way to clean up the Flashback malware is to use Software Update with OS X 10.6.8 and above until all updates are installed.


If you have you are already up-to-date then download and run this Flashback Removal Tool.


Then check to make sure that none of the following is still present on your hard drive:


/Users/jackson/Library/LaunchAgents/com.valvesoftware.steamclean.plist

/Users/jackson/Library/Applications Support/Steam (a folder)


If they are still there, drag them to the trash and empty it.


If you are running OS X 10.7 or above your Library folder will be invisible. In order to access it you will need to hold the Option key down and select "Library" from the Finder's "Go" menu.

Sep 12, 2013 8:11 AM in response to CaesarCalad

Sorry for digging up an older tread, but I came here from Google and I don't want others to be misinformed if they read that Steam or "steamclean" is bad.


"steamclean" is a part of the very popular gaming platform/store Steam from Valve, which has a very good reputation. I'm using Steam myself, and many of my friends do (not only on OS X, but on Windows and Linux too), no one has ever encountered a problem related to security (the app itself isn't the most stable on OS X).


Link for further information: http://store.steampowered.com/

Flashback trojan

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.