Q: Dr Web Flashback Virus checker accurate?
Does anyone have any info about how accurate the Flashback checker from Dr Web is? http://public.dev.drweb.com/april
When I enter my Hardware UUID into the tool I get the following response:
probably infected by Backdoor.Flashback.39 !
Timestamp of the first access: 2012-04-03 21:27:19
Timestamp of the last access: 2012-04-06 17:48:52
However when I follow the instructions from the F-Secure website to locate and remove the virus (http://community.f-secure.com/t5/Protection/Flashback-Mac-OS-X-Remover/m-p/10887 #M2223) using Terminal, I get the files "do not exist" reponses.
I haven't experienced any issues with my computer but figured I'd check to be certain, and now I'm not sure how to proceed.
MacBook Pro, Mac OS X (10.6.8)
Posted on Apr 7, 2012 10:14 AM
Try running these commands courtesy of X423424X The formatting here is breaking one of the lines. Be sure to copy/paste it in.
Here's what I am suggesting as a rudimentary test for some of the known strains of the flashback trojans. Open a terminal window and copy/paste each of the following lines hitting return after each one and note the results:
defaults read ~/.MacOSX/environment
defaults read /Applications/Safari.app/Contents/Info LSEnvironment
ls -la ~/Library/LaunchAgents
grep "/Users/$USER/\..*" ~/Library/LaunchAgents/* | grep -v "/Users/$USER/\.Trash"
For the two defaults command if you get anything other than a "does not exist" error message post the results since you are almost certainly infected.
The third command, ls, just lists the contents of your LaunchAgents, if any. That's additional info to be used in conjuntion with the last grep command. If the grep shows any results then that too may indicate infection and again post its results.
And these two as well.
defaults read /Applications/Firefox.app/Contents/Info LSEnvironment
defaults read /Applications/Safari.app/Contents/Info LSEnvironment
Posted on Apr 7, 2012 2:33 PM