Check whether your Mac is infected with the Trojan Flashback

Amy Swan By Amy Swan, 9th May 2012 | Follow this author | RSS Feed | Short URL http://nut.bz/13n179j_/
Posted in Wikinut>Guides>Technology>Computer Software

Hundreds of thousands of Mac users around the world are infected with a nasty Trojan. Are you one of them? Make fast or this is the case through the following steps.

Detailed instructions for prevention and elimination

Hundreds of thousands of Mac users around the world are infected with a nasty Trojan. Are you one of them? Make fast or this is the case through the following steps.

According to latest reports, the number of Mac OS X machines infected with a variant of the so-called Trojan Flashback now risen to over 600,000. According to the Russian Dr.Web antivirus firm are a few hundred of the infections even from Cupertino, Apple's headquarters in the United States.

Fortunately, there is indeed a way to see if you are infected. The first thing you should check is whether you have installed Java from Oracle, because the attackers from entering through a leak in this program. Even if this is not the case, then the following steps by the loop.

A direct way to verify that you have on board Flashback, via the OS X Terminal. This program can be found by the Finder menu, point to Programs (Applications) to go and then the Utilities folder (Utilties) to open. Open Terminal and then enter the following command:

defaults read / Applications / Safari.app / Contents / Info LSEnvironment

Search now for the next line that comes into the picture, because the evidence is that the trojan is detected Flashback: DYLD_INSERT_LIBRARIES

Appears not and instead you get the following error message picture, you do not have to worry: "The domain / default pair of (/ Applications / Safari.app / Contents / Info, LSEnvironment) does not exist"

If this error does not appear, we recommend you to visit the website of F-Secure to go where the security company in detail describes how the Flashback trojan can come off.

But wait: we're not done yet. Copy the following command in the Terminal window to perform a final check:

defaults read ~ / .MacOSX / environment DYLD_INSERT_LIBRARIES

If you now again an error message (see above) you, you definitely are not infected: "The domain / default pair of (/ Users / joe / .MacOSX / environment, DYLD_INSERT_LIBRARIES) does not exist"

Finally, make sure that you are sure the latest security update from Apple installed, conscious that the Java-leak repairs. We recommend you also for the security of a Mac antivirus application installed. Avast! Example has a free version you can try.

Tags

Apple, F-Secure, Flashback, Mac Os X, Malware, Practical, Removal, Terminal, Trojan

Meet the author

author avatar Amy Swan
Love And Respect Your Parents. Because Every Success Is Based In The Prays Of Your Parents.

Share this page

moderator Peter B. Giblett moderated this page.
If you have any complaints about this content, please let us know

Comments

Add a comment
Username
Can't login?
Password