Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News Editorials & Other Articles General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search
 

denem

(11,045 posts)
Thu Apr 5, 2012, 02:02 PM Apr 2012

Talking point: The '600,000 Mac' infections are JAVA exploits.

Last edited Sat Apr 7, 2012, 03:24 PM - Edit history (1)

'OSX is no more secure than Windows'? Nope. This not about Macs (or PC's) it's a problem with JAVA.

JAVA is not OSX. JAVA is not included in current Mac installations. Since Apple handed back maintenance of JAVA to Oracle, Larry Ellison owns it.

How to fix it.
If JAVA is installed on your Mac, the usual software update will nix it. "BackDoor.Flashback.39" are rogue JAVA applets. The update kills them.

Note: "BackDoor.Flashback.39" affects Mac and Windows JAVA equally. Windows users have more difficult path to go.

Reboot Windows in Safe Mode.
Use Dr.Web® scanner of free curing utility Dr.Web® CureIT! to scan local drives.
The “Cure” action should be applied for all infected files.
Restore registry from the backup copy.

As per usual, the trojan embeds itself in the monstrosity that is The Windows Registry.
The steps above advertises one virus vendor. Dr. Web. Any vendor would do.

The JAVA update is available on OSX Software Update now. Get it, or download

JAVA (10.6) http://support.apple.com/kb/HT5056

JAVA (10.7) http://support.apple.com/kb/DL1515

10 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Talking point: The '600,000 Mac' infections are JAVA exploits. (Original Post) denem Apr 2012 OP
Update: Looks like there's more to it than that. denem Apr 2012 #1
I update, but one thread says this fix came out this Wednesday. freshwest Apr 2012 #2
(Apple Support) To check if you've got it (or others) denem Apr 2012 #3
Thanks! I can't use those but am looking into these at this link: freshwest Apr 2012 #5
I just did a 66 MB Java update before I saw this Stinky The Clown Apr 2012 #4
(Apple support) go to http://botnetchecker.com/ denem Apr 2012 #6
Thanks. It gave me a clean bill of health. Stinky The Clown Apr 2012 #7
Me too. denem Apr 2012 #8
Same here, clean as a whistle. emulatorloo Apr 2012 #9
When I try to go to botnetchecker I get redirected to uscity.net A-Long-Little-Doggie Apr 2012 #10
 

denem

(11,045 posts)
1. Update: Looks like there's more to it than that.
Thu Apr 5, 2012, 06:03 PM
Apr 2012

Last edited Sat Apr 7, 2012, 03:28 PM - Edit history (1)

http://reviews.cnet.com/8301-13727_7-57410096-263/how-to-remove-the-flashback-malware-from-os-x/
I.ll' keep you posted/

Update: The terminal approach appears to be unnecessary. Apple's software update restores the compromised apps & libraries.

freshwest

(53,661 posts)
2. I update, but one thread says this fix came out this Wednesday.
Thu Apr 5, 2012, 06:27 PM
Apr 2012

Yet it's not on my list of updates when I checked.

My NoScript blocks virtually all Java on Firefox.

Any suggestions other than using Terminal?

I don't feel confident doing anything with it.


freshwest

(53,661 posts)
5. Thanks! I can't use those but am looking into these at this link:
Thu Apr 5, 2012, 06:49 PM
Apr 2012
http://support.apple.com/downloads/#osx%2010.5%20security%20update

Which I hope will get me updated. But I even had to tell NoScript to allow Apple to come through, LOL.

 

denem

(11,045 posts)
6. (Apple support) go to http://botnetchecker.com/
Thu Apr 5, 2012, 07:00 PM
Apr 2012

It's a simple test to check if you have any botnet.

A-Long-Little-Doggie

(1,011 posts)
10. When I try to go to botnetchecker I get redirected to uscity.net
Sun Apr 22, 2012, 09:14 AM
Apr 2012

Reading entries on apple.com I see that I am not the only one having this issue. Are there any alternatives sites that I can use to check for this bot?

Latest Discussions»Culture Forums»Apple Users»Talking point: The '600,0...