Advice on the Mac Trojan Flashback Infection Alert - April 2012

It has been reported across the net, on almost every Mac-related website of a virus-scare concerning a variant of the Mac Flashback trojan that exploits an un-patched Java vulnerability. Apple have since released a security update on 3rd April.
By: PR - Apple Mac Data Recovery London
 
April 10, 2012 - PRLog -- Dr. Web (a Russian based antivirus vendor) reported that Flashback may have infected over half-a-million Macs. This was originally reported early last week by a Dr. Web's Ivan Sorokin (a Russian based antivirus vendor) later estimated that their sinkhole now estimates over 600,000 infections. Each installation of Flashback creates a unique User-Agent.

Therefore if you have Java installed on your Mac — update now by running Apple Software Update via your Apple menu. It;s worth exercising caution and ensuring you are downloading updates via Software Update only. Therefore if a message appears on your Mac suggesting you should download any update and you have any suspicion all you have to do is simply quit or cancel the on-screen dialog or close its window. Then launch Apple Software Update from your Apple Menu and run the updates from there. It goes without saying that regularly running Apple Software Update is very important to make certain that the probability of encountering any vulnerabilities and/or system bugs are minimised.

For further information or to find fixes for removal of the Trojan and its associated files we advise to visit the Virus and Threat Description section of the F-Secure website. Full information on Java for OS X Lion 2012-002 and Java for Mac OS X 10.6 Update 7 can be found here.

If your skills in using the Terminal app aren't up to scratch - which most online solutions suggest you should use and input up to 18 commands - we discovered that Etresoft have updated their Malware Checker app to include identifying the Flashback Trojan. Full information is available on the Apple Support Communities section of the Apple website. Be aware that this app will most likely only indicate whether there is an infection or not rather than remove it.

Here is a list of the components of the Mac Flashback Trojan and what function they have:

   •   Trojan-Downloader:OSX/Flashback.K connects to a remote site to download its payload; on successful infection, the malware modifies targeted webpages displayed in the web browser.
   •   Trojan-Downloader:OSX/Flashback.I connects to a remote site to download its payload; on successful infection, the malware modifies targeted webpages displayed in the web browser.
   •   Trojan-Dropper:OSX/Revir.C silently drops other malicious programs onto the machine; on execution, Revir.C displays a titillating image to distract the user from the program's malicious activities.
   •   Backdoor:OSX/DevilRobber.A silently installs applications related to Bitcoin-mining; it may also harvest data from the infected machine and listen for additional commands from a remote user.
   •   Backdoor:OSX/Tsunami.A is a distributed denial-of-service (DDoS) flooder that is also capable of downloading files and executing shell commands in an infected system.
   •   Trojan-Downloader:OSX/Flashback.C poses as a Flash Player installer and connects to a remote host to obtain further installation files and configurations.
   •   Trojan-Downloader:OSX/Flashback.B poses as a Flash Player installer, and connects to a remote host to obtain installation configurations and files.
   •   Trojan-Dropper:OSX/Revir.B drops and executes a backdoor program detected as Backdoor:OSX/Imuler.A, while camouflaging its activity by opening a JPG file to distract the user.
   •   Trojan-Downloader:OSX/Flashback.A poses as a Flash Player installer, and connects to a remote host to obtain installation configurations and files.
   •   Backdoor:OSX/Imuler.A contacts a remote server for instructions; it may then steal files or capture a screenshot of the infected computer system, which is then forwarded to the remote server.
   •   Trojan-Dropper:OSX/Revir.A drops a downloader component that downloads a backdoor program onto the system, while camouflaging its activity by opening a PDF file to distract the user.

Apple Mac Data Recovery are based in London and provide disaster recovery solutions for Mac users throughout the capital. If you have any issue with your Mac concerning lost files, missing data or the integrity of your data or important files the services on offer can be of great assistance to you. Backed by a network of Apple specialists you are assured of a knowledgeable and helpful service which is available 365 days a year. Full information and contact details are found at their website
http://www.applemacdatarecovery.co.uk

# # #

Advanced Apple Mac Data Recovery Service for iMac, MacBook and MacBook Pro users in the United Kingdom.
End
Source:PR - Apple Mac Data Recovery London
Email:***@applemacdatarecovery.co.uk Email Verified
Tags:Apple Data Recovery, Mac Data Recovery, Apple, Mac, Virus, Trojan, Infected, Flashback, Advice, Help
Industry:Computers, Technology
Location:London City - London, Greater - England
Account Email Address Verified     Account Phone Number Verified     Disclaimer     Report Abuse
Page Updated Last on: Apr 10, 2012



Like PRLog?
9K2K1K
Click to Share