Register FAQ / Rules Forum Spy Search Today's Posts Mark Forums Read
Go Back   MacRumors Forums > News and Article Discussion > MacRumors.com News Discussion

Reply
 
Thread Tools Search this Thread Display Modes
Old Oct 19, 2011, 10:13 AM   #1
MacRumors
macrumors bot
 
Join Date: Apr 2001
Tweaked Trojan Disables Automatic Updating of OS X Anti-Malware Tools




Last month, we noted as part of a report on an update to the anti-malware tools in OS X that a new trojan horse threat known as Flashback.A had surfaced, with the malware masquerading as a Flash Player installer. While Apple has continued to update its XProtect.plist to detect Flashback.A, security firm F-Secure now reports (via ZDNet) that a revised version of the trojan which disables the auto-updating feature of Apple's anti-malware tools has appeared.
Quote:
There's something new brewing in Mac malware development (again).

Recent analysis has revealed to us that Trojan-Downloader:OSX/Flashback.C disables the automatic updater component of XProtect, Apple's built-in OS X anti-malware application.
The report walks through how the modified trojan overwrites XProtectUpdater files, preventing infected systems from performing their daily check for updated malware definitions and thus keeping the door open for future attacks.




Flashback.C installer
The Flashback.C trojan is capable of connecting to a remote host in order to download and execute further code, but it is unclear what the exploit is being used for at this time. Users are of course advised to download Flash Player and other software from trusted sources so as to avoid infecting their systems with trojans such as Flashback.C.

Update: MacRumors has heard and Sophos has confirmed that Apple had already updated its XProtect.plist entries to detect Flashback.C by the time news of it broke to the public. Consequently, users encountering the malware on Mac OS X Snow Leopard or OS X Lion should be automatically warned of the threat prior to mounting the package.

Article Link: Tweaked Trojan Disables Automatic Updating of OS X Anti-Malware Tools
MacRumors is offline   1 Reply With Quote
Old Oct 19, 2011, 10:16 AM   #2
MultiMediaWill
macrumors 65816
 
Join Date: Aug 2010
Location: Illinois
i tH0uGh7 m4c d0Nt g3T v1rus
__________________
Click here for the iPhone 5 iOS 6.0 Jailbreak!
MacBook Pro 15" 2011 , 2.2 GHz Quad i7, 750GB HDD, 8GB RAM, Anti-Glare
iPhone 5 32gb
iPad 3 16gb
MultiMediaWill is offline   -23 Reply With Quote
Old Oct 19, 2011, 10:19 AM   #3
Unggoy Murderer
macrumors regular
 
Join Date: Jan 2011
Location: Livingston, Scotland
Quote:
Originally Posted by MultiMediaWill View Post
i tH0uGh7 m4c d0Nt g3T v1rus
They don't, this is a Trojan. Big difference
__________________
27" iMac, i7 3.4GHz, 16GB RAM 13" MBP 2.66 GHz, 8GB RAM 3rd Gen iPad 64 GB Wifi+4G, iOS 5.1 iPhone 5 32 GB, iOS 6.0 Mac Mini 2.00 GHz, 2GB RAM
Unggoy Murderer is offline   -2 Reply With Quote
Old Oct 19, 2011, 10:21 AM   #4
Aduntu
macrumors 6502a
 
Aduntu's Avatar
 
Join Date: Mar 2010
Quote:
Originally Posted by Unggoy Murderer View Post
They don't, this is a Trojan. Big difference
Your sarcasm meter is obviously broken.
Aduntu is offline   19 Reply With Quote
Old Oct 19, 2011, 10:21 AM   #5
jmpnop
macrumors 6502a
 
jmpnop's Avatar
 
Join Date: Aug 2010
Quote:
Originally Posted by MultiMediaWill View Post
i tH0uGh7 m4c d0Nt g3T v1rus
tRoj4n is n0t v1rus.
__________________
Sent from my iPod Shuffle.
jmpnop is offline   -4 Reply With Quote
Old Oct 19, 2011, 10:21 AM   #6
Sacird
macrumors 6502a
 
Join Date: May 2010
Location: Northern, VA
OH noes!!!
Sacird is offline   1 Reply With Quote
Old Oct 19, 2011, 10:21 AM   #7
bender o
macrumors 6502
 
Join Date: Mar 2009
Damn you Flash!! When are you gonna go extinct!! you suck!!
__________________
13" Macbook Pro 2.4Ghz 8Gb RAM 500Gb Mid 2010; iPhone 4 32Gb 4.2.1 Jailbroken; iPad sux for studying => SOLD
bender o is offline   -12 Reply With Quote
Old Oct 19, 2011, 10:21 AM   #8
daxomni
macrumors 6502
 
Join Date: Jun 2009
Quote:
Originally Posted by MultiMediaWill View Post
i tH0uGh7 m4c d0Nt g3T v1rus
The Reality Distortion Field that previously protected all Macs from all attacks appears to have dissipated.
__________________
iPod 3 | Nano 1/3/6 | Touch 2 | iPhone 1/2/4 | iOS 1/2/3/5 |MBP 2K9/2K10/2K12 | OSX 5/6/7/8 | E4G | GS3 | AOS 2/4 | DOS 5/6 | W31/95/98/XP/W7/W8 | NT4/2K/2K3/2K8
daxomni is offline   -17 Reply With Quote
Old Oct 19, 2011, 10:22 AM   #9
iStudentUK
macrumors 65816
 
iStudentUK's Avatar
 
Join Date: Mar 2009
Location: London
Quick everyone download MacDefender!


(My team of lawyers require me to note that I'm not actually suggesting anyone download MacDefender.)
__________________
UK students may want to read about Apple education discounts and free student warranties here
iStudentUK is offline   17 Reply With Quote
Old Oct 19, 2011, 10:22 AM   #10
roadbloc
macrumors 603
 
roadbloc's Avatar
 
Join Date: Aug 2009
Location: UK
It's happening more and more.
__________________
roadbloc is online now   3 Reply With Quote
Old Oct 19, 2011, 10:23 AM   #11
RoboCop001
macrumors 65816
 
Join Date: Oct 2005
Location: Toronto, Canada
I don't understand why these fools waste everyone's time by writing viruses, and I mean for any platform. Can't they put that energy and effort into something positive?
RoboCop001 is online now   31 Reply With Quote
Old Oct 19, 2011, 10:24 AM   #12
igazza
macrumors 6502a
 
Join Date: Aug 2007
Location: earth
iOS is the future
__________________
igazza is offline   -10 Reply With Quote
Old Oct 19, 2011, 10:25 AM   #13
Mad-B-One
macrumors 6502a
 
Mad-B-One's Avatar
 
Join Date: Jun 2011
Location: Southern Plains
Quote:
Originally Posted by daxomni View Post
The Reality Distortion Field that previously protected all Macs from all attacks appears to have dissipated.
It changed size and is only hovering over iOS at this time.

Quote:
Originally Posted by iStudentUK View Post
Quick everyone download MacDefender!


(My team of lawyers require me to note that I'm not actually suggesting anyone download MacDefender.)
Would be a solution. Two Trojan horses fighting each other. Maybe they block each other then? Someone please try that in a VM
__________________
Join the Macrumors.com - Team Folding and donate your CPU & GPU processing power to a good cause!
Visit my YouTube channel: ThoringersTanks
Mad-B-One is offline   1 Reply With Quote
Old Oct 19, 2011, 10:25 AM   #14
CodeBreaker
macrumors 6502
 
Join Date: Nov 2010
Location: Sea of Tranquility
So have they managed to scare anyone?
__________________
.
CodeBreaker is offline   -3 Reply With Quote
Old Oct 19, 2011, 10:25 AM   #15
Sacird
macrumors 6502a
 
Join Date: May 2010
Location: Northern, VA
Quote:
Originally Posted by RoboCop001 View Post
I don't understand why these fools waste everyone's time by writing viruses, and I mean for any platform. Can't they put that energy and effort into something positive?
I'm actually with ya on that. I feel so bad when anyone on any platform has to deal with this crap. Lock as many up as possible and throw em in camps. Put em on a PPV where they are tortured like in Hostel, they'll learn sooner or later.

Not actually serious about torture and stuff to be clear.
Sacird is offline   9 Reply With Quote
Old Oct 19, 2011, 10:25 AM   #16
ndpitch
macrumors regular
 
Join Date: Jun 2010
Looks like this could be a leadup into needing anti-virus/anti-malware/anti-spyware on the Mac.
ndpitch is offline   -3 Reply With Quote
Old Oct 19, 2011, 10:25 AM   #17
hobo.hopkins
macrumors 6502a
 
hobo.hopkins's Avatar
 
Join Date: Jul 2008
I foresee this discussion degrading very quickly...

In reality all one needs to do is be cautious of where they are downloading files, and this wouldn't be a problem.
__________________
Think morality requires religion? Name me an ethical statement made or an action performed by a believer that could not have been made or performed by a non-believer. I'm waiting...
hobo.hopkins is offline   12 Reply With Quote
Old Oct 19, 2011, 10:26 AM   #18
tubular
macrumors newbie
 
Join Date: Oct 2011
A couple questions

1 - how can we tell if a machine is infected?
2 - how, if infected, can we remove it, short of a clean install?
tubular is offline   9 Reply With Quote
Old Oct 19, 2011, 10:27 AM   #19
Shrink
macrumors Demi-God
 
Shrink's Avatar
 
Join Date: Feb 2011
Location: New England, USA
Quote:
Originally Posted by MultiMediaWill View Post
i tH0uGh7 m4c d0Nt g3T v1rus
Oh, god, here we go again with the virus vs malware vs trojan vs etc., etc.

Malware is a generic category (malicious software). Viruses, trojans, spyware and all other crap that f***ks with your computer are malware.

Macs have never been infected by a virus up to this date. Yes, it is possible sometime in the future a virus could be developed that will infect a Mac. Nothing to this date!

Trojan is NOT a virus - it is a form of malware. Unlike a virus which can infect a computer without action on the part of the user, trojans have to be invited in. In short - the user has to screw up.

The best defense is an educated user.

(GGJstudios - How did I do?? )
__________________
Two things are infinite, the universe and human stupidity; and I'm not sure about the universe. -- Albert Einstein
Shrink is offline   8 Reply With Quote
Old Oct 19, 2011, 10:28 AM   #20
stage1
macrumors newbie
 
Join Date: Oct 2011
CRAP!! I downloaded a flash update today on my macbook!

What should I do help!! I'm not joking.
stage1 is offline   -3 Reply With Quote
Old Oct 19, 2011, 10:28 AM   #21
Memo86
macrumors newbie
 
Join Date: Sep 2011
Well... i was a PC user in the XP era and i didn't get any virus (and there are thousands of windows wiruses, right?) so, I think that is REALLY HARD to get your mac infected. ¿Who would download flash from other site than Adobe.com?
Memo86 is offline   2 Reply With Quote
Old Oct 19, 2011, 10:29 AM   #22
igazza
macrumors 6502a
 
Join Date: Aug 2007
Location: earth
Best idea is to use chrome as your browser
__________________
igazza is offline   0 Reply With Quote
Old Oct 19, 2011, 10:30 AM   #23
RoboCop001
macrumors 65816
 
Join Date: Oct 2005
Location: Toronto, Canada
Quote:
Originally Posted by tubular View Post
1 - how can we tell if a machine is infected?
2 - how, if infected, can we remove it, short of a clean install?
I can't completely give you those answers but one way is Time Machine. If you're infected or fear that you are infected just restore your whole HD to a previous state.
RoboCop001 is online now   2 Reply With Quote
Old Oct 19, 2011, 10:30 AM   #24
Memo86
macrumors newbie
 
Join Date: Sep 2011
Quote:
Originally Posted by stage1 View Post
CRAP!! I downloaded a flash update today on my macbook!

What should I do help!! I'm not joking.
If you downloaded from Adobe Updater or from Adobe.com i'm sure you're safe... if you downloaded from some pr0n site or crappy page maybe you're in trouble... :P
Memo86 is offline   7 Reply With Quote
Old Oct 19, 2011, 10:30 AM   #25
Unggoy Murderer
macrumors regular
 
Join Date: Jan 2011
Location: Livingston, Scotland
Quote:
Originally Posted by Aduntu View Post
Your sarcasm meter is obviously broken.
No, not really. Functioning perfectly fine the last time I checked.
__________________
27" iMac, i7 3.4GHz, 16GB RAM 13" MBP 2.66 GHz, 8GB RAM 3rd Gen iPad 64 GB Wifi+4G, iOS 5.1 iPhone 5 32 GB, iOS 6.0 Mac Mini 2.00 GHz, 2GB RAM
Unggoy Murderer is offline   -4 Reply With Quote

Reply
MacRumors Forums > News and Article Discussion > MacRumors.com News Discussion

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
thread Thread Starter Forum Replies Last Post
Disable automatic downloading of iTunes Match songs on iOS Scriz iCloud and Apple Services 10 Apr 10, 2012 11:35 AM
Networked Drives - Disabled Automatic Opening of Finder Window? dylanbrown OS X 0 Feb 9, 2011 05:28 PM
Alarm Clock Radio App - disable automatic start of iPod hoymevoy iPhone Tips, Help and Troubleshooting 0 Dec 29, 2010 02:20 PM
Disable automatic updates chrisblaze OS X 7 Aug 18, 2010 10:52 AM
disabling automatic update for ipod jaypeebee Mac Applications and Mac App Store 0 Oct 22, 2003 12:08 AM


All times are GMT -5. The time now is 09:07 AM.

Mac Rumors | Mac | iPhone | iPhone Game Reviews | iPhone Apps

Mobile Version | Fixed | Fluid | Fluid HD
Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.

Privacy / DMCA contact / Affiliate and FTC Disclosure
Copyright 2002-2013, MacRumors.com, LLC