Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

OSX popup about malware?

I just updated my MacBook Pro (which I check for updates about 2-3 times a week, plus the automatic alerts) and it updated Java. Almost immediately after, I got this:


It says "Malware was found and removed from computer. The "OSX.FlashBack.iv" malware was found and removed." It then gives you the option to "Report malware to Apple to protect other users," to click on the question mark for help (which goes no where..opens up "Help" with no information displayed" and to click OK.


does anyone know anything about this? should I be concerned? I can find almost nothing about OSX.FlashBack.iv online, or anything about the the prompt itself. is this an actual Apple prompt?


any help would be greatly appreciated!



User uploaded file

MacBook Pro (15-inch Early 2008), Mac OS X (10.5.5)

Posted on Apr 19, 2012 5:59 PM

Reply
19 replies

Apr 20, 2012 4:32 AM in response to bud300

If you think you had it on your computer, then I would go round to every service I use online and change the passwords.

I'm not sure if that is too paranoid or not. You might search the various security sites and blogs to see what they say about what it was collecting and if there are other mitigation steps to follow in the aftermath.


There are a few people here who follow the security stuff heavily and they may chime in on the topic. However, that may be a good idea to start your own post that may be valuable to lots of people. Start it with a topic like, "What to do now if I had the Flashback Trojan?"

Apr 20, 2012 4:51 AM in response to bud300

Those commands do not detect all variants of Flashback. Your machine is clean now, and the update will have locked down Java so that you'll be safer from any other not-yet-discovered Java exploits in the future. But, as Barney mentioned, it is not well documented what information this malware actually gathered. So you'd be wise to change passwords, as he recommended, as well as keeping a close eye on your credit cards and bank accounts, and any other financial accounts you may have (PayPal, Amazon, etc).

Apr 20, 2012 5:51 PM in response to chaminade0408

chaminade0408 wrote:


thanks for all the info/help!! I wish Apple or a major computer security company would give a more comprehensive and detailed explanation of what this malware does and what are the best things that we can do to protect ourselves now

I don't think Apple knows anything about what it does and about the only company I've heard from about this was Intego back in February Flashback Mac Trojan Horse Infections Increasing with New Variant toward the end of the article. They are also the one that have said Twitter is being used for communicating between computer bots and Command & Control Servers. But I've only heard of one user reporting fraudulent Credit Card activity after being infected.


BTW, you might want to change your profile info. It doesn't appear you are still running OS X 10.5.5 on the machine being discussed here.

May 10, 2012 10:08 PM in response to dudelar

dudelar wrote:


what i don't understand is this, a few weeks back when this virus was announced,

Flashback was announced last Fall. Malware yes. Virus no.

i scanned my comptuer and it was clean.

Scanned with what? Most of the scanning software was running two to three weeks behind the introduction of new variants.

i installed the security update and all was good. i installed the new security update and got this pop-up. how is it that i had the flashback if i followed all of the instructions originally? a little frustrated

Hard to say as I don't really know what security update you installed when. If you used Software Update to do this (which is what I keep advising) then you can give us details by going to System Preferences->Software Update->Installed tab and it will tell you exactly what you installed and when. I only know of three updates from Apple associated with this malware.


One for OS X 10.6.8

One for OS X 10.7.3 with Java installed

One for OS X 10.7.x without Java installed


and you should only have been told to install one of them. Perhaps you installed the wrong one first and it didn't work?


To add to my confusion your profile says you are using a "powermac g5, Mac OS X (10.4.11)" which not only won't run any of these updates, it isn't even capable of being infected by Flashback.

OSX popup about malware?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.