New Trojan Disables Mac Malware Definition Updates

| News

Flashback Trojan for the MacA new Trojan horse application for the Mac is in the wild and masquerading as an installer for the Adobe Flash Player. If the bogus installer app is run, it will disable the automatic malware definition updater that helps detect malicious applications when they’re downloaded from the Internet.

The security research company F-Secure is calling the new malware app Trojan-Downloader:OSX/Flashback.C, or Flashback. Once installed, the application disables OS X’s malware definition updater, which leaves victims vulnerable to other potential malware apps since it won’t recognize newer attacks embedded in apps.

The easiest way to avoid this Trojan app is to download the Flash installer only from Adobe’s Web site. Like other Trojans, Flashback must be downloaded and installed since it can’t “push” itself out to computers.

Trojans and other malware applications are fairly easy to avoid simply by avoiding downloads from Web sites you aren’t familiar with or don’t trust. For anyone that falls victim to Flashback, however, F-Secure has instructions available for removing the Trojan.

Sign Up for the Newsletter

Join the TMO Express Daily Newsletter to get the latest Mac headlines in your e-mail every weekday.

7 Comments Leave Your Own

Roadster

The F-Secure website says to “Scan the whole system and take note of the detected files”.  Can someone please tell me how to do this?

Also, I use Safe Download Version.  Recently I get the following message when trying to run it “Can’t make “Oct” into type integer.  Any help on both issues would be very helpful.

Thanks.

JonGl

The F-Secure website says to ?Scan the whole system and take note of the detected files?.? Can someone please tell me how to do this?

I think that, if you will look further down the page, they tell you what files and where they are. It’s a bit complex, but can be done manually, or so I would guess, but I’m not infected to test. wink

-Jon

goldenthal

Also, I use Safe Download Version.? Recently I get the following message when trying to run it ?Can?t make ?Oct? into type integer.? Any help on both issues would be very helpful.


Just to let you know, I am also getting the message re Oct—have no idea what it’s all about or what to do about it.


goldenthal

Nemo

Dear goldenthal:  If you have an Apple Store convenient to your location, I think that it is time for you to pay Apple’s Geniuses a visit, bringing, of course, your computer.

Nancy

I recently had a window come up on my iMac to update the Adobe
player, which I did.  It didn’t come in mail or from any website.  Now I’m
worried.  Haven’t had any problems that I know of.

Adam Christianson

Also, I use Safe Download Version.? Recently I get the following message when trying to run it ?Can?t make ?Oct? into type integer.? Any help on both issues would be very helpful.

I just released a patch for this bug which you can get here

goldenthal

Re “I just released a patch for this bug which you can get here”


Thanks, Adam;  works!


goldenthal

Log-in to comment