• This forum is for posting news stories or links from rumor sites. When you start a thread, please include a link to the site you're referencing.

    THIS IS NOT A FORUM TO ASK "WHAT IF?" TYPE QUESTIONS.

    THIS IS NOT A FORUM FOR ASKING QUESTIONS ABOUT HOW TO USE YOUR MAC OR SOFTWARE.

    This is a NEWS and RUMORS forum as the name implies. If your thread is neither of those things, then please find the appropriate forum to ask your question.

    If you don't have a link to a news story, do not post the thread here.

    If you don't follow these rules, then your post may be deleted.

Flashback trojan reportedly controls half a million Macs and counting

Joined
Sep 3, 2010
Messages
622
Reaction score
13
Points
18
Location
Charlotte, NC
Your Mac's Specs
mid-2010 Mac Mini OS 10.12.6 Sierra, 2.66 GHz C2D, 8GB RAM, 30 in. Cinema Display
Thanks Doug...Sorry, but I did freakout...but for good reason...although results showed I'm healthy and clean. I have the skills to remedy an infection, I just didn't want to deal with the hassle and I have a lot to lose if someone were to gain access to what's in the box that Carroll Meryl is holding.
 

RavingMac

Well-known member
Staff member
Moderator
Joined
Jan 7, 2008
Messages
8,303
Reaction score
242
Points
63
Location
In Denial
Your Mac's Specs
16Gb Mac Mini 2018, 15" MacBook Pro 2012 1 TB SSD
Well, my MBP is clean . . . now to test the others. :)
 
Joined
Sep 21, 2011
Messages
726
Reaction score
28
Points
28
Location
London, Londonshire, England.
Your Mac's Specs
13" Late 2011 MBP,iPad '3' 32gb,iPhone4 32gb
I'm clean!

So is my Mac! ;)
 

dtravis7


Retired Staff
Joined
Jan 4, 2005
Messages
30,133
Reaction score
703
Points
113
Location
Modesto, Ca.
Your Mac's Specs
MacMini M-1 MacOS Monterey, iMac 2010 27"Quad I7 , MBPLate2011, iPad Pro10.5", iPhoneSE
All MAC here clean! :D
 

RavingMac

Well-known member
Staff member
Moderator
Joined
Jan 7, 2008
Messages
8,303
Reaction score
242
Points
63
Location
In Denial
Your Mac's Specs
16Gb Mac Mini 2018, 15" MacBook Pro 2012 1 TB SSD
Three for three . . . all clean. :)
 
Joined
Jun 22, 2008
Messages
3,343
Reaction score
213
Points
63
Location
Forest Hills, NYC
Your Mac's Specs
15-inch Early 2008; Processor 2.4 GHz Intel Core 2 Duo; Memory 4 GB 667 MHz DDR2 SDRAM; 10.7.5
Well, Dogbreath.. (I really like calling someone that) the thing is that I don't think anyone has actually seen or experienced the consequences of said "infection", so one shouldn't assume what the outcome would be. That said, everyone and their mom should be backing up their data (not just via Time Machine) redundantly, and on a regular basis.

Which reminds me, I need to buy a new external!

Doug
 

RavingMac

Well-known member
Staff member
Moderator
Joined
Jan 7, 2008
Messages
8,303
Reaction score
242
Points
63
Location
In Denial
Your Mac's Specs
16Gb Mac Mini 2018, 15" MacBook Pro 2012 1 TB SSD
Well, Dogbreath.. (I really like calling someone that) the thing is that I don't think anyone has actually seen or experienced the consequences of said "infection", so one shouldn't assume what the outcome would be. That said, everyone and their mom should be backing up their data (not just via Time Machine) redundantly, and on a regular basis.

Which reminds me, I need to buy a new external!

Doug

I was just going to post the question, "Has anybody on this Forum seen the infection, or even know someone who has?"

Just curious now.
 
Joined
Jan 13, 2007
Messages
4,773
Reaction score
166
Points
63
Location
Central New York
Your Mac's Specs
15in i7 MacBook Pro, 8GB RAM, 120GB SSD, 500GB HD
I did the check, just for the heck of it. Didn't really need to since I have Little Snitch installed. Came back clean.
 
Joined
Apr 26, 2008
Messages
2,963
Reaction score
120
Points
63
Location
Belgium
Your Mac's Specs
iPad Pro 12.9 latest iOS
I was just going to post the question, "Has anybody on this Forum seen the infection, or even know someone who has?"

Just curious now.

That is why I posted earlier on that the results of the malware are not clear and as far as I can tell, there are no results.
That is why I called this a proof of concept ... a step by step approach and see how far they can get.
That is also why the articles in the press and magazines made me smile ..... 600000 infections ... right .... what does that mean then ..... how many of those actually yielded any results .... and where does the 600000 comes from ?
Is someone counting numbers ?

In my mind, there is not so much to worry about, only that people now understand that the OS X platform is not only on the radar, it is now also a chosen target.

A few simple behaviors will keep the risk level actually low. ( The vulnerabilities are outside of our control )

Cheers ... McBie
 
Joined
Dec 5, 2010
Messages
50
Reaction score
0
Points
6
Im clean.Just told me files do not exist but did not say anything like domain/default pair of does not exist
 

vansmith

Senior Member
Joined
Oct 19, 2008
Messages
19,924
Reaction score
559
Points
113
Location
Queensland
Your Mac's Specs
Mini (2014, 2018, 2020), MBA (2020), iPad Pro (2018), iPhone 13 Pro Max, Watch (S6)
I think I may have noticed a flaw in the F-Secure article (here). I noticed that in the Ars article (here) covering the malware, they check the Safari and Firefox app bundles which made me think that this malware modifies the app bundle for the browser used by the user and not necessarily Safari itself. I never use Safari so I imagine that checking the Safari app bundle is utterly useless if this is the case.

Does anyone know if the malware modifies Safari and/or Firefox regardless or does it modify the browser used when the malware was installed on the machine?
 

RavingMac

Well-known member
Staff member
Moderator
Joined
Jan 7, 2008
Messages
8,303
Reaction score
242
Points
63
Location
In Denial
Your Mac's Specs
16Gb Mac Mini 2018, 15" MacBook Pro 2012 1 TB SSD
Okay, I just checked Firefox on all three Macs (my browser of choice) and still clean. :)
 
Joined
Dec 5, 2010
Messages
50
Reaction score
0
Points
6
Did you type in a different command in terminal to check firefox or just the two that have already been listed in this thread?
 
Joined
Jul 18, 2009
Messages
473
Reaction score
8
Points
18
Your Mac's Specs
Macbook Pro 13"
I am clean, but I have to now check up on the less wary Mac users that I know. I have a feeling I know someone who caught this--same person that caught the Mac Defender or whatever it was called.
 

vansmith

Senior Member
Joined
Oct 19, 2008
Messages
19,924
Reaction score
559
Points
113
Location
Queensland
Your Mac's Specs
Mini (2014, 2018, 2020), MBA (2020), iPad Pro (2018), iPhone 13 Pro Max, Watch (S6)
Did you type in a different command in terminal to check firefox or just the two that have already been listed in this thread?
Replace:
Code:
defaults read /Applications/Safari.app/Contents/Info LSEnvironment
in the steps above to check your machine with the following:
Code:
defaults read /Applications/Firefox.app/Contents/Info LSEnvironment
 
Joined
Mar 4, 2012
Messages
12
Reaction score
0
Points
1
All the comments I am sure make sense to sophisticated MAC users. I am a new MACBookPro user. There is no way I can make sense of any of the comments above. How will I know if my MACBook has been infected? I have no idea how to use the terminal or what not.

Many of us are not expert MAC users.
 
Joined
Mar 4, 2012
Messages
12
Reaction score
0
Points
1
Terminal

How does one use the terminal? I opened it up, and it says:

Last login: Sun Apr 8 01:44:07 on ttys000
MYName-MacBook-Pro:~ mynames$ ..



Now what do I do?


I also see members writing that they checked their browsers, ie Firefox. How would I do that?

Do you think it might be better for me to call Apple and talk to a tech?
 
Joined
Nov 24, 2011
Messages
89
Reaction score
0
Points
6
Your Mac's Specs
20" iMac, Late 2007, 2.4GHz (Dual Core), 1GB RAM, Radeon 2600HD OSX 10.6.8
All the comments I am sure make sense to sophisticated MAC users. I am a new MACBookPro user. There is no way I can make sense of any of the comments above. How will I know if my MACBook has been infected? I have no idea how to use the terminal or what not.

Many of us are not expert MAC users.
It is kind of like one of those make your own adventure books, if you follow the article here
To run commands in Terminal, open up Terminal (Applications/Utilities or a Spotlight search) and then it is merely a case of copying and pasting. So first we run
Code:
defaults read /Applications/Safari.app/Contents/Info LSEnvironment
by using cmd+c and then cmd+v into Terminal.
If you get an error message, you can skip straight to step 8 (Hope that you get one).
All you have to do is follow the instructions on the websitr linked.

I use Terminal all the time but I must admit to you that I understand very little.

You should be clean if you don't willy-nilly put in the admin password for everything that asks for it however if you do find you are infected, ask here for a walkthrough if you need.
 

Shop Amazon


Shop for your Apple, Mac, iPhone and other computer products on Amazon.
We are a participant in the Amazon Services LLC Associates Program, an affiliate program designed to provide a means for us to earn fees by linking to Amazon and affiliated sites.
Top