Apple Users
Related: About this forumTalking point: The '600,000 Mac' infections are JAVA exploits.
Last edited Sat Apr 7, 2012, 03:24 PM - Edit history (1)
'OSX is no more secure than Windows'? Nope. This not about Macs (or PC's) it's a problem with JAVA.
JAVA is not OSX. JAVA is not included in current Mac installations. Since Apple handed back maintenance of JAVA to Oracle, Larry Ellison owns it.
How to fix it.
If JAVA is installed on your Mac, the usual software update will nix it. "BackDoor.Flashback.39" are rogue JAVA applets. The update kills them.
Note: "BackDoor.Flashback.39" affects Mac and Windows JAVA equally. Windows users have more difficult path to go.
Reboot Windows in Safe Mode.
Use Dr.Web® scanner of free curing utility Dr.Web® CureIT! to scan local drives.
The Cure action should be applied for all infected files.
Restore registry from the backup copy.
As per usual, the trojan embeds itself in the monstrosity that is The Windows Registry.
The steps above advertises one virus vendor. Dr. Web. Any vendor would do.
The JAVA update is available on OSX Software Update now. Get it, or download
JAVA (10.6) http://support.apple.com/kb/HT5056
JAVA (10.7) http://support.apple.com/kb/DL1515
denem
(11,045 posts)Last edited Sat Apr 7, 2012, 03:28 PM - Edit history (1)
http://reviews.cnet.com/8301-13727_7-57410096-263/how-to-remove-the-flashback-malware-from-os-x/I.ll' keep you posted/
Update: The terminal approach appears to be unnecessary. Apple's software update restores the compromised apps & libraries.
freshwest
(53,661 posts)Yet it's not on my list of updates when I checked.
My NoScript blocks virtually all Java on Firefox.
Any suggestions other than using Terminal?
I don't feel confident doing anything with it.
denem
(11,045 posts)Updates. (These may already be installed)
JAVA (10.6) http://support.apple.com/kb/HT5056
JAVA (10.7) http://support.apple.com/kb/DL1515
freshwest
(53,661 posts)Which I hope will get me updated. But I even had to tell NoScript to allow Apple to come through, LOL.
Stinky The Clown
(68,464 posts)denem
(11,045 posts)It's a simple test to check if you have any botnet.
Stinky The Clown
(68,464 posts)denem
(11,045 posts)emulatorloo
(45,571 posts)A-Long-Little-Doggie
(1,011 posts)Reading entries on apple.com I see that I am not the only one having this issue. Are there any alternatives sites that I can use to check for this bot?