Is your Mac infected?
MarkR
Registered Users Posts: 2,099 Major grins
I'm sure I'm going to take flack for this-- but if you are running a Mac OSX device, do yourself a huge favor right now and follow these two instructions, then come back and read further:
1. Do a software update and install the latest Java patch.
2. Install an AV solution on your Mac. (Avast and ClamXAV are free.)
There is a nasty new Trojan variant called Flashback/K that will install without an admin password. All you have to do is go to a site that has been compromised to get it. It currently has infected at least 600,000 macs, (and counting!) the vast majority in the United States and Canada.
It will not install if you have AV software installed and running on your mac: VirusBarrier, iAntiVirus, avast!, ClamXAV.
If you think you may be infected, you can go here for instructions on manually detecting and removing the Trojan.
1. Do a software update and install the latest Java patch.
2. Install an AV solution on your Mac. (Avast and ClamXAV are free.)
There is a nasty new Trojan variant called Flashback/K that will install without an admin password. All you have to do is go to a site that has been compromised to get it. It currently has infected at least 600,000 macs, (and counting!) the vast majority in the United States and Canada.
It will not install if you have AV software installed and running on your mac: VirusBarrier, iAntiVirus, avast!, ClamXAV.
If you think you may be infected, you can go here for instructions on manually detecting and removing the Trojan.
0
Comments
I will look into it on my wife's Mac tonight.
Also Sophos.
Based on my experience with AV in PC-land I was reluctant to install Mac OSX AV software for a long time but Sophos is very unobtrusive.
Apple sent out updates last night. Both my Macs were updated with a full reboot. But better safe then sorry, so thanks for posting for those that did not get the updates right away, or ignored them
Digi-Scapes | Facebook | Twitter | Pinterest
Nikon D800 & D850 | Nikkor 70-200 f2.8 VR II | Nikkor 16-35 f/4 | Nikon TC-20E-III | Nikkor 70-300mm VR | Nikkor 50mm f1.8 | Nikon 24-120mm f/4G ED VR | Micro-Nikkor 105mm f/2.8G
This will be changing the more popular Macs become. As usual, practive safe computing :ivar
Digi-Scapes | Facebook | Twitter | Pinterest
Nikon D800 & D850 | Nikkor 70-200 f2.8 VR II | Nikkor 16-35 f/4 | Nikon TC-20E-III | Nikkor 70-300mm VR | Nikkor 50mm f1.8 | Nikon 24-120mm f/4G ED VR | Micro-Nikkor 105mm f/2.8G
If you read Avast EULA you can see that you pay them by giving them the authority to download anything from your machine their software thinks is potentially infected (including emails, programs, files).
Will have a loog at Sophos now ..
― Edward Weston
Portland, Oregon Photographer Pete Springer
website blog instagram facebook g+
Did find a discussion of AV for the iOS here: https://discussions.apple.com/thread/3162148?start=0&tstart=0
MarkR, why are you sure you would take flack for this post? What am I missing?
I have in the past advocated that Mac users install an AV solution on their devices.
The usual results are either denial or even outrage. Of course, it doesn't help that Apple has in the past spoken with a bit of a forked tongue-- the "Get A Mac" campaign strongly suggested that malwares were a PC-only problem, while Apple silently mandated Norton AV on all macs behind the Genius Bar.
Forum for Canadian shooters: www.canphoto.net
With good reason. Things have changed now, I think Sophos Home Edition is good and free. And there's reason to install it now.
But a couple of years ago those apps were doing more harm than good. I forget the particulars (I think it was Norton, but I'm unsure), but there was one anti-virus app that caused damage, and this at a time when there were no viruses in the wild, whatsoever. I wouldn't have advised installing those apps at that time, either. They were a greater risk than the malware they were intended to protect you from.
And for the record, this thing still isn't a virus, it's a Trojan Horse. Virus is losing it's specificity and becoming a generic for malware, because I guess grandma never heard of malware.
Dgrin FAQ | Me | Workshops
Disagreement isn't _necessarily_ "flak".
I do think it is interesting that this trojan looked for AV software - and not the other way around (unless I have read faulty reports of exactly what happened).
Are there any AV installations that identified it ahead of time?
My view is that AV software is insufficient by itself, and really far less significant than being careful where you go, and what you click on.
Macs are not invincible, but neither is their security advantage solely a matter of having fewer installations in use.
Edit: Oh, and while we are talking about security, maybe a good move would be to disable Java.
{all of the above spoken in a friendly tone, with no flak intended }
Chooka chooka hoo la ley
Looka looka koo la ley
I just installed PS on my new machine. The installation required Java.
Dgrin FAQ | Me | Workshops
Interesting! Is this on a Mac?
Maybe the answer is to have two browsers installed. One for every-day use which has Java disabled, and the other with it enabled for when you are quite consciously doing something that requires it.
Chooka chooka hoo la ley
Looka looka koo la ley
Yes. A Mac. It was probably the Akamai installer that required it?
Dgrin FAQ | Me | Workshops
http://www.forbes.com/sites/adriankingsleyhughes/2012/04/07/an-easy-way-to-check-your-mac-for-the-flashback-malware/?partner=yahootix
Digi-Scapes | Facebook | Twitter | Pinterest
Nikon D800 & D850 | Nikkor 70-200 f2.8 VR II | Nikkor 16-35 f/4 | Nikon TC-20E-III | Nikkor 70-300mm VR | Nikkor 50mm f1.8 | Nikon 24-120mm f/4G ED VR | Micro-Nikkor 105mm f/2.8G
Thanks for this link!
― Edward Weston
The delivery mechanism, rather than the actual installer, I would think (but I will not claim to know). If the file were available by itself (and just required a serial number and/or registration) or via the Mac App store there would be no need for Java.
Chooka chooka hoo la ley
Looka looka koo la ley
Dgrin FAQ | Me | Workshops