Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

think my laptop has a virus

..really slow.

MacBook Pro (15-inch Late 2008), Mac OS X (10.5.8)

Posted on Jun 26, 2012 9:24 PM

Reply
12 replies

Jun 27, 2012 4:24 AM in response to deborah60

You can check for Flashback trojan infection with the tool at: https://github.com/jils/FlashbackChecker/wiki


Further Flashback trojan information at: https://discussions.apple.com/docs/DOC-3271


Once you have checked that you do not have a Flashback trojan infection I advise first backing up to an external disk or DVD. The main things to backup are users' Home folders because they normally contain 90% of data. Better still backup the whole disk with Carbon Copy Cloner from: http://www.bombich.com/


After this I would use the free AppleJack disk utility:


  1. Backup all data to an external disk if you have not done so recently
  2. Get AppleJack from: http://sourceforge.net/projects/applejack/
  3. Install AppleJack
  4. Boot holding cmd S until you see text
  5. Do nothing until the text stops
  6. Type: applejack AUTO shutdown
  7. Hit return


Depending upon disk size etc it can take an hour or more. AppleJack will fill the screen with serious looking diagnostics - most can be ignored.


Reboot and test after the Mac has shut down. First boot will take longer than usual as caches are rebuilt.


Good luck.

Jun 27, 2012 4:32 AM in response to Neville Hillyer

You can check for Flashback trojan infection with the tool at:https://github.com/jils/FlashbackChecker/wiki


I would not recommend downloading some malware checking tool from a random stranger's github page. Apple has released updates for Mac OS X 10.5 and up, available through Software Update, that can detect and remove Flashback. There's no reason to use anything else. Besides which, there's no reason to think Flashback in this case, just because the computer is slow. That is not one of the typical symptoms of a Flashback infection.


After this I would use the free AppleJack disk utility


I also would not recommend using AppleJack. There's really no reason for it. With a few simple instructions, you can do the same things in single-user mode without it, and even then, that's the less-preferred way to go about doing system repairs. It is better to use the tools on your Mac OS X install disk, or recovery mode on a system running Mac OS X 10.7 (Lion).

Jun 27, 2012 5:17 AM in response to thomas_r.

I would not recommend downloading some malware checking tool from a random stranger's github page.


Good point although the link came from a reliable source. Here is an F-secure checker: http://www.f-secure.com/weblog/archives/00002346.html


Apple has released updates for Mac OS X 10.5 and up, available through Software Update, that can detect and remove Flashback.


My understanding is that with some old OSs they do little more than disable some Java.


I also would not recommend using AppleJack. There's really no reason for it. With a few simple instructions, you can do the same things in single-user mode without it - -


It is simple, reliable, effective and does more than the average user could do via single user mode. I am not the only experienced user here to use it regularly and recommend it - I advise that you try it.

Jun 27, 2012 5:32 AM in response to Neville Hillyer

Regarding Flashback and 10.5, see:


http://support.apple.com/kb/HT5273


As for AppleJack, yes, it makes it easier for inexperienced users to run diagnostics in single-user mode. But, as I said, single-user mode is not the preferred way of doing those things, especially for (but not limited to) inexperienced users. The better way to do stuff like repair the hard drive in 10.6 and earlier is to start up from the Mac OS X install disk and run Disk Utility from there.

Jun 27, 2012 6:44 AM in response to thomas_r.

None of the Apple Flashback utilities appear to work in detection mode and give users feedback.


Those listed at http://support.apple.com/downloads/#flashback do not work on PPC Macs. It is foolish to think that PPC Macs will never be infected by this trojan.


I stand by my Applejack advice. Perhaps you can say in which way you think install disks are better - I suspect they do not do as much. AppleJack, used as instructed, repairs the boot volume, repairs permissions and does a deep clean. It might be worth remembering that thousands of legitimate OS X users do not have easy access to install disks. Apple sells multiple licenses to many organisations with only one set of disks.

Jun 27, 2012 9:51 AM in response to Neville Hillyer

Since the Flashback malware never, since September of last year, included any PPC code, and since the threat is over at this point (the hackers have moved on after, apparently, being unable to actually collect their ill-gotten gains), I think it's safe to say PPC Macs are completely safe from Flashback at this point.


As for Applejack, the only thing that it does that is necessary to do from single-user mode is the file system check. I suppose if you are unable to type "fsck -fy" (as per the instructions given when you boot into single-user mode) Applejack would be useful. The rest of the stuff it does can be more easily done by other software without rebooting in single-user mode, and is almost never responsible for failure to start up.

think my laptop has a virus

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.