Last edited by a moderator:
You can check for infection by looking for the following files:
/Library/Preferences/com.apple.PubSabAgent.pfile
/Library/LaunchAgents/com.apple.PubSabAGent.plist
The former. If it were the latter, it would be shown as ~/Library/PreferencesThe article says:
Anybody know if this is Mac HD/Library/Preferences or Users/user/Library/Preferences?
The vulnerability it exploits in Word was already patched almost 3 years ago, as described in the Microsoft Security Bulletin MS09-027. Anyone who hasn't applied updates for 3 years is certainly not practicing safe computing.Anyone encounter the latest Mac trojan, so-called "LuckyCat"? Evidently this affects Word docs opened on a Mac. Sounds like another exploit of Java. Any advice for the masses?
Thanks everyone.
Read the Mac Virus/Malware FAQ I posted, specifically the section: What about sending files to Windows users?My philosophical objection then is that unfortunately all of GGJStudio's excellent advice leaves Macs as the perfect Typhoid Mary's for Windows malware.
I recommend that you avoid using Sophos, as it could actually increase your Mac's vulnerability, as described here and here.Sophos made their endpoint security for Mac free several years ago.
I recommend against using Sophos. Read post #9 in this thread.~snip~
<snip>
My philosophical objection then is that unfortunately all of GGJStudio's excellent advice leaves Macs as the perfect Typhoid Mary's for Windows malware. Perfect because they are clothed in a false sense of heightened security by their users as they are carried past corporate and personal firewalls and connected to LANs. They can forward virus-laden e-mails.
<snip>
I recommend against using Sophos. Read post #9 in this thread.
You don't need any antivirus app to detect the trojans. Instructions have been posted everywhere on how to locate them.Does ClamAV detect the two Trojans on OSX this past week?
You don't need any antivirus app to detect the trojans. Instructions have been posted everywhere on how to locate them.
My response was neither snarky nor condescending. I simply stated facts, with no emotion at all expressed or implied.If I wanted to manually do that every time this would be a great response instead of a snarky, condescending response. I want to do it automatically and preferably soon after new variants are discovered in the wild.
If I wanted to manually do that every time this would be a great response instead of a snarky, condescending response. I want to do it automatically and preferably soon after new variants are discovered in the wild.