Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

spazzcat

macrumors 68040
Jun 29, 2007
3,713
4,827
Apple computers do not get a virus. Yeah right. (as the Tui advertisment goes).

Why does someone make this comment every time there is a new malware? Again malware is not a virus....
 

Yamcha

macrumors 68000
Mar 6, 2008
1,825
158
Why does everyone automatically think that every single Mac user is immune to Trojan's?

Most Mac or PC users are not very computer savvy, and among many of those people are my parents and nearly all my friends..

I'm certain If my parents saw that dialog box they would click continue..
 

jman240

macrumors 6502a
May 26, 2009
798
243
Why does someone make this comment every time there is a new malware? Again malware is not a virus....

Yes but a virus is malware. It's just in the general vernacular as virus so for all intents and purposes this is how it is understood by most people. Semantics really aren't as important as good practices and education about threats to computing IMHO.

----------

Why does everyone automatically think that every single Mac user is immune to Trojan's?

Most Mac or PC users are not very computer savvy, and among many of those people are my parents and nearly all my friends..

I'm certain If my parents saw that dialog box they would click continue..

My same issue, parents. Im thinking of installing Sophos while I wait for Mountain Lion to release.
 

jbrown

macrumors 6502a
Jul 7, 2002
997
4
London
Important!!

Could some who *KNOWS* please answer this. I got a prompt this morning supposedly from Adobe saying there was an update to Flash. It appeared in the style of the CS5 installer windows ( black rectangle with coloured text ).

I thought no more and installed it.

Now I read this and am worried it may have been this trojan.:eek:

Any advice gratefully received.:(
 

ArtOfWarfare

macrumors G3
Nov 26, 2007
9,567
6,073
The argument has usually been applied to viruses. Trojans require user input and can effect anything. Yes, security holes are taken advantage of to make this Trojan look legit, but there is no defense for the most basic Trojan. If I wrote and app that said you'll be granted three wishes after you enter your password, but instead I use your password to delete all files on you computer, that is a Trojan. There is no defense for such things expect common sense.

Won't the default GateKeeper setting coupled with the sandbox requirement for the Mac App Store reduce malware to entirely nonexistent?

The one thing I worry about is the error message that Apple displays if GateKeeper is on and someone attempts to run an unsigned app. It basically says "THIS IS MALWARE!" I see the message as having two horrible impacts:

1 - The clueless user who doesn't know what they're doing will say "Oh crap! Macs have malware! Yes, this one was blocked, but how many others weren't?"
2 - The user who has common sense and knows it isn't malware but doesn't understand GateKeeper will see the message as reporting false positives on a malware checks.
 

CrickettGrrrl

macrumors 6502a
Feb 10, 2012
985
274
B'more or Less
Could some who *KNOWS* please answer this. I got a prompt this morning supposedly from Adobe saying there was an update to Flash. It appeared in the style of the CS5 installer windows ( black rectangle with coloured text ).

I thought no more and installed it.

Now I read this and am worried it may have been this trojan.:eek:

Any advice gratefully received.:(

Don't click on the links, go to the real Adobe site directly, and check there whether you need the latest update or not.
 

CrickettGrrrl

macrumors 6502a
Feb 10, 2012
985
274
B'more or Less
It's installed already!

If it was fake, then you may notice problems using Safari, and Skype.

Are you using Lion or Snow Leopard? Because with Lion, you'd have seen the certificate warning. With Snow Leopard, you'd be more vulnerable, unless your Updates (re Java) are current.
 

stisdal

macrumors 6502
Feb 28, 2010
320
1
USA
Yeah if you can train my parents to do that be my guest. I don't live with them, they use a Mac.

Anyway, I found ClamXAV and Sophos. Anyone have experience with these?

I'm interested in an answer from someone experienced with either of these as well. I worry about the wife's Macbook as the kids also use it....
 

*LTD*

macrumors G4
Feb 5, 2009
10,703
1
Canada
not as many as Windows but not as little as you would like to think Mr. LTD

OS 9 had a far smaller share and more malware.

OS X has been on the market for nearly twelve years and all we have are a handful of trojans. And all this despite over 50 million users.

The old market-share argument dictates that we should have at least 1000 viruses by now, and that's being conservative. Right now we still have zero viruses and a few trojans.

The iDevice ecosystem (and the rapid proliferation thereof) has rendered this entire virus discussion moot anyway.
 

nitro912gr

macrumors regular
Oct 3, 2010
102
6
Athens, Greece
I'm a little confused, I though that no more java updates where to be given through the software update.

It is years since I have last seen one.
 

wnorris

macrumors member
Feb 16, 2008
79
134
Yeah if you can train my parents to do that be my guest. I don't live with them, they use a Mac.

Anyway, I found ClamXAV and Sophos. Anyone have experience with these?

If you install ClamAV from the App Store be aware that it does not automatically scan. It is user initiated scans.

If you decide on Sophos you should read the following thread:

https://forums.macrumors.com/threads/1204593/

Good luck.
 
Last edited:

Macman45

macrumors G5
Jul 29, 2011
13,197
135
Somewhere Back In The Long Ago
Could some who *KNOWS* please answer this. I got a prompt this morning supposedly from Adobe saying there was an update to Flash. It appeared in the style of the CS5 installer windows ( black rectangle with coloured text ).

I thought no more and installed it.

Now I read this and am worried it may have been this trojan.:eek:

Any advice gratefully received.:(

There has been a recent update to Flash....You should be fine. If you want to check, go to the flash icon in system>preferences and do a check from the Flas icon there.
 

CrickettGrrrl

macrumors 6502a
Feb 10, 2012
985
274
B'more or Less
This new trojan variation irritates me no end. I just spent the past week helping a friend who downloaded koobface or Flashback from a Facebook prompt to update Flash after she clicked on a dog video sent by a friend. It totally wiped her hard drive somehow. Dumb mistake on her part, although she made several mistakes by refusing to update her OS because she believed it would screw up her iMovie program :rolleyes:. --Oh, and not having any current backups or a bootable clone.

I unilaterally updated her system to Snow Leopard and unchecked Java and Safe Downloads in Safari, etc., etc. -And told her she's much safer in SL, and now this, in which SL is somewhat vulnerable... :mad:
 

fins831

macrumors 6502a
Oct 7, 2011
657
0
11.1.102.55 is installed. Thats the latest version of flash according to the website (official).

I am still running SL and am updated, have ClamXav also as a backup, windows has made me aware that nothing is absolutely secure, so even though right now most malware is you being dumb, I am just preparing for that scan when it just bypasses it completely.
 

salmoally

macrumors regular
Jan 26, 2012
192
0
In Mountain Lion, Gatekeeper makes perfect sense for people who would naturally just click accept on stuff like this, which I would imagine is the large majority of consumers.

This means less support calls for Apple and more importantly less support calls from family/friends if you're seen as a "computer expert".
 

jbrown

macrumors 6502a
Jul 7, 2002
997
4
London
Thanks for the replies everyone.

I'm on Lion - and there was no certificate notification.

So I'm hoping I'm OK. But will be more careful in the future! :)
 

Bodycalming

macrumors regular
Jan 15, 2009
118
29
London.
If you install ClamAV be aware that it does not automatically scan. It is user initiated scans.

If you decide on Sophos you should read the following thread:

https://forums.macrumors.com/threads/1204593/

Good luck.

This is not true, Sentry can be set to scan the hard drive as you work.

See this text from the ClamXav site.

Clean, simple-to-use interface
Clearly lists infected files
Free virus definitions (usually updated daily)
Save your favourite scan locations for easy access
Customise the toolbar - or hide it entirely
Send selected files to quarantine or trash with one click
Specify files to exclude using plain text* or by using drag & drop from the Finder
Specify schedules to update virus definitions and perform scans
Use ClamXav Sentry to monitor your hard drive and scan new files as they arrive†
Use the bundled ClamAV engine or bring your own installation†
Compatible with Mac OS X 10.5, 10.6 and 10.7 Lion
 

locust76

macrumors 6502a
Jan 23, 2009
688
90
Wirelessly posted (Mozilla/5.0 (iPhone; CPU iPhone OS 5_0_1 like Mac OS X) AppleWebKit/534.46 (KHTML, like Gecko) Version/5.1 Mobile/9A406 Safari/7534.48.3)

This is not a virus this is a Trojan blah blah blah blah... Queue the bickering!
 

wnorris

macrumors member
Feb 16, 2008
79
134
This is not true, Sentry can be set to scan the hard drive as you work.

See this text from the ClamXav site.

Clean, simple-to-use interface
Clearly lists infected files
Free virus definitions (usually updated daily)
Save your favourite scan locations for easy access
Customise the toolbar - or hide it entirely
Send selected files to quarantine or trash with one click
Specify files to exclude using plain text* or by using drag & drop from the Finder
Specify schedules to update virus definitions and perform scans
Use ClamXav Sentry to monitor your hard drive and scan new files as they arrive†
Use the bundled ClamAV engine or bring your own installation†
Compatible with Mac OS X 10.5, 10.6 and 10.7 Lion

You are making the assumption that most users will have Sentry installed. I do not believe it is installed on the App Store version.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.