Apple Event: May 7th at 7 am PT

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

"What to do now if I had the Flashback Trojan?"

I just did a software update (was overdue) that included the java security fix, and was immediately informed that the "OSX.FlashBack.iv" malware was found and removed.



Does anyone happen to know how serious a threat the malware presents, how to assess any potential damage it may have done, and what I might do to minimize any after-the-fact damage?

iMac, Mac OS X (10.6.8), 27", 3.2GHz Core i3-4GB RAM-1TB HDD

Posted on Apr 27, 2012 12:55 AM

Reply
22 replies

May 3, 2012 10:19 AM in response to Maxwell’s Demon

Maxwell’s Demon wrote:


Ummm...I just noticed your reference to "MRT." It took me a little while to realize that it's an abbreviation for "Malware Removal Tool." Is "MRT" a standard acronym?

For sure MRT is the name of the process that Apple runs during the check and remove process, but to the best of my knowledge, they have never said that it stands for Malware Removal Tool. It has been widely assumed by some users and the media.

Also, since Java is not, by default, installed in Lion, that suggests that Apple feels that it's both an unnecessary and perhaps undesirable piece of software. If so, why doesn't Apple simply say so, and recommend that SL users (such as myself) uninstall it from their systems? (And if so, where is it located—I can't find it in my apps and utilities folders—and how does one uninstall it?)

I think it was probably based more on the transition of responsibility from Apple to Oracle that it wasn't included in Lion, but it could well be a little of both.


As noondaywitch indicated, it's a PITA to remove, although I have started seeing some advise on how to do that, they aren't consistent in what they say and I don't feel comfortable recommending things that I haven't tested. To me turning it off accomplishes the same thing, except freeing up space on the Hard Drive and it also guards against having to re-install it if and when you find you need it for something.

May 3, 2012 11:18 AM in response to noondaywitch

noondaywitch wrote:


It doesn't need other applications; Java applets can be run directly on the Mac (or PC) if so selected in the preference pane.


Can you give me an example of such an applet?


There are few websites actually using Java content these days. Unfortunately of the ones that do, it's usually banking sites! (at least in the US. I'm not aware of any European banks which do this).


Well, I'll guess I'll find out the next time I log in to my bank account!😁 (I have a couple...the primary one appears not to.)

May 3, 2012 11:22 AM in response to MadMacs0

MadMacs0 wrote:



Maxwell’s Demon wrote:


I've disabled it in Safari. What other apps do I have to be concerned about (which would make "turning it off completely" more advisable)?


If you use any other browser apps, you should disable those, as well. If you turn it off completely any app that requires it will undoubtedly let you know you need to turn it back on.

Occasionally, I use Firefox; the only other browser I have (which I very, very rarely use) is Opera. Neither appears to enable the disabling of Java.

May 3, 2012 3:30 PM in response to Maxwell’s Demon

Maxwell’s Demon wrote:


Occasionally, I use Firefox; the only other browser I have (which I very, very rarely use) is Opera. Neither appears to enable the disabling of Java.

Firefox: How to turn off Java applets


Opera probably isn't loading a Java plug-in. To check type "opera:plugins" without the quotes in the address box, hit return and see if it's listed.

May 3, 2012 3:41 PM in response to Maxwell’s Demon

Maxwell’s Demon wrote:


MadMacs0 wrote:


...

...


I think it was probably based more on the transition of responsibility from Apple to Oracle that it wasn't included in Lion, but it could well be a little of both.


Huh? Responsibility for what?

http://www.apple.com/pr/library/2010/11/12Oracle-and-Apple-Announce-OpenJDK-Proj ect-for-Mac-OS-X.html


and


https://blogs.oracle.com/henrik/entry/oracle_jdk_and_javafx_sdk

May 3, 2012 5:18 PM in response to MadMacs0

MadMacs0 wrote:


Maxwell’s Demon wrote:


Occasionally, I use Firefox; the only other browser I have (which I very, very rarely use) is Opera. Neither appears to enable the disabling of Java.

Firefox: How to turn off Java applets


Opera probably isn't loading a Java plug-in. To check type "opera:plugins" without the quotes in the address box, hit return and see if it's listed.


Actually, both load Java plugins! I disabled them.


Many thanks.

"What to do now if I had the Flashback Trojan?"

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.