How does one recover from Downloader:OSX/Flashback.C?

Hi All,
I am pretty sure I dowloaded and installed it on one or more of my machines...
It seems that a re-install of Lion is the only way to bring back Lion's XProtectUpdater functions...
Is there a thread for fixing this dumb mistake?
Cheers,
Adam

After giving this additional thought, I realize that you seem to be the first to report having been infected by this version, so I don't think any of us can offer an exact solution yet. If you don't mind taking your time, I'd like walk you through this slowly so we can all learn more about it.
It would seem that this version was served up for a short time around Oct 11. Do you know if you used it that long ago or was it more recently? Do you still have the installer? If so, hang on to it for now as we may need you to provide it to some sample sites.
Go ahead and test to see if XProtect has been compromised by opening your Terminal app (in the Utilities folder) then copy and paste the following into a new window after the "$" prompt:
sudo launchctl list
hit return and when prompted, enter your admin password (you won't see any typing) and hit return again.
The list should include "com.apple.xprotectupdater.plist" if it's working.
If it's not working, then inspect either of the following two files:
/System/Library/LaunchDaemons/com.apple.xprotectupdater.plist
/usr/libexec/XProtectUpdater
If either are blank, then you have been infected.  Restore from backup or reinstall Lion.
Next you will need to fix Safari and/or FireFox.  F-Secure has these instructions:
Disinfection
Manual Removal Instructions
In Terminal, convert the affected PLIST files to XML:
plutil -convert xml1 /Applications/Safari.app/Contents/Info.plist
plutil -convert xml1 /Applications/Firefox.app/Contents/Info.plist
Remove the following entry from the PLIST files:
<key>LSEnvironment</key>
<dict>
<key>DYLD_INSERT_LIBRARIES</key>
<string>%malware_path%</string>
</dict>
Delete the file specified in %malware_path%
Intego explains concerning Safari:
...it adds the actual backdoor module at /Applications/Safari.app/Contents/Resources/UnHackMeBuild.
What I don't know is whether or not any of the other files are still installed. They were:
.MacOSX/environment.plist
Library/LaunchAgents/com.apple.SystemUI.plist
Library/Preferences/perflib
Library/Preferences/Preferences.dylib
Library/Logs/softwareupdate.log
and Intego said that #4 is not installed.  If you find any of them please move them all at once and hold on to them and let us know. The first is a hidden folder, so if you need help looking into that let me know. If that one is not moved at the same time as the others you will probably be unable to log back into your account.

Similar Messages

  • Using family sharing, how does one view and download songs from a family member's collection in itunes?

    Using family sharing, how does one view and download songs from a family member's collection in itunes?

    When you click on your device you are presented with the pages
    Summary
    Info
    Apps
    Tones
    Music
    Movies
    TV shows
    Books
    Photos
    To remove Audiobooks depending on the type of Audiobook ie a series of mp3 files you will find under music and probably have to deselect the album name to remove it. I don't have any of these as I download from Audible or I use Audiobook Builder to stictch together mp3 files into m4b files. To find these Click on Books you will immediately see a section for books (in reality ebooks). Scroll down past that and you will see Audiobooks where you can select and deselect. Deselect the required Audiobooks and Click Sync

  • How does one recover lost photographs on the computer?

    How does one recover lost photographs on the computer?

    My photographs were successfully uploaded to iPhoto when I was forced to restart my computer. When it turned back on again, the photographs were gone from my camera and my computer. I do not know how to restore them from my backup and cannot find the photographs anywhere else. Thank you for your help!

  • How does one update from iwork '09?

    I followed blog advice to download iwork trial and try to upload from there, but no dice. how does one update from iwork /'09???

    With all due respect ... I do not see how one can change the Subtemplate value from Yes to No. When I query the offending Template, the Subtemplate column is not displayed in bold, indicating to me that it can not be updated. Clicking on Edit Configuration, doe not provide an ability to change the value either.
    As best I can determine, one needs to 1) query up the template
    2) download the rtf file(s)
    3) end date the template
    4) create a new template and then set the Subtemplate value to No.
    And the same steps appear to be required in order to add or update a template Description.
    Which raises the question, Why can this not be done by editing the configuration?

  • How Does One Backup a Downloadable-Only Software App?

    Plan to purchase new Final Cut Pro X but discovered it is only available as a download from the App Store without the usual CD/DVD for one's files. Given this, how is one to keep a copy for future use if upgrading to a new platform or rebuilding one's existing hard drive etc.?

    Dah.veed!
    Thank you for the prompt response to my question. Much appreciated. I can now go ahead and purchase FCP X knowing there is a way to maintain a back-up copy for future use.
    I noticed your long association with Mac! I started in 1986 with with an SE, gave gone through seven different platforms in the interim and and currently use a 24" iMac.
    Ybles

  • HT4436 how does one print from cloudon?

    I can work on the excel and word programs but can not print from it.
    how does on do this?

    From an iOS device you need either
    1)  an airprint printer -
    http://support.apple.com/kb/HT4356?viewlocale=en_US&locale=en_US
    2) If yours is not listed, then the only way to print is using a computer - for example, on a Mac, get Printopia for the mac.  Then your ipad can print using airprint, Printopia intercepts the job and routes it to a printer that the Mac can connect go.

  • How does one recover a lost Airport Express password?

    Both on my iPhone and iPad I can use the wifi signal at my friend's house, so they both have stored the password for her Airport Express. My friend, however, needs to re-enter her forgotten AE password to use her own AE. Me not good with technology, so how can I get my iPhone and/or iPad to display the password so that I can provide it to her?
    Thanks,
    Rick

    Hey, I'm slow, but at least I now see others have previously posted this same question. I'll research those threads.
    Thanks again,
    Rick

  • How does one print from Adobe Reader (I have windows 8)?

    I have adobe reader with my windows * and I just don't have a glue as to what to do.

    See FAQ: Printing from Adobe Reader for Windows 8 Tablets.

  • HT1766 When I turn on my iPad am confronted with the message "iPad Not Backed Up.  This iPad hasn't beern backed up.  Backups happen when this iPad is plugged in, locked and connected to Wi-Fi."  How does one proceed from this message?

    How do I overcome this impasse?

    Have you tried a reset ? Press and hold both the sleep and home buttons for about 10 to 15 seconds (ignore the red slider if it appears), after which the Apple logo should appear - you won't lose any content, it's the iPad equivalent of a reboot.

  • How does one transfer from imovie to fce without loss of quality. Using a panasonic hdc-tm15 full hd 1920x1080

    I am capturing my footage on a Panasonic hdc-tm15 full hd 1920x1080 avchd. The format recorded is not compatible with fce so i have to import to imovie first. what export settings do i need to use to ensure i dont lose quality when going from imovie to fce?

    It is suggested to output MOV with AIC codec to keep the raw video quality at max.
    Output like this: Share->Export Using QuickTime..
    In pop-up windows, click Options->in Moive Settings pop-up window, click Settings button->In Compression Type box, choose Apple Intermediate Codec
    Good luck.

  • How does one access their images in their libraries in Desktop Adobe Photoshop that are connected to their Mobile Adobe Shape?

    So
    I have Adobe Shape on my iphone, and in my Creative Cloud on the web it can access the images ive made. BUT, these images wont show up in my library on Photoshop on my computer and i cant seem to save them from the creative cloud on the web.
    How does one get from A to B?
    Thankyou
    Victoria

    Hi Victoria and welcome to the forum.
    I had to Google Shape but it looks interesting, and dies use the CC Libraries.  I am a big fan of CC Libraries, but have only used them between apps on the same machine.  So it is just a matter of see how they work between different systems
    Illustrator Help | Creative Cloud libraries - collaborate, sync, and share assets
    In my experience, I simply drag an asset onto the Library in one app, and it is there in my other apps.  But I have to make sure I am looking at the same library name on both computers.  Now I have been confused over syncing before, but I suspect that if you open the Application Manager and click on the little Cog icon, and in the Files tab make sure Sync is checked.  Otherwise you might as well read the help files.
    Sync digital assets in Adobe files and apps | Creative Cloud Libraries
    Good luck

  • Latest version of Lightroom will not download RAW files from my D750. How does one get around this? Bought Lightroom for it's ability to manage RAW files and now very disappointed.

    Latest version of Lightroom will not download RAW files from my D750. How does one get around this? Bought Lightroom for it's ability to manage RAW files and now very disappointed.

    Here is the contents of a batch file which will convert whatever raws you drop on it:
    "C:\Program Files (x86)\Adobe\Adobe DNG Converter" -cr7.1 -dng1.4 -p0 %*
    Once you download the latest converter (release candidate from adobe labs, if necessary), and save the appropriate contents of the batch file (change path to match your system, and parameters to match your druthers, if applicable), the procedure is:
    1. Drop raw files on bat file.
    2. Import as usual (the DNGs).
    Not too bad once you're set up (if DNG converter supports your raws).
    Documentation:
    http://wwwimages.adobe.com/content/dam/Adobe/en/products/photoshop/pdfs/dng_commandline.pd f
    Note: on Mac, you may need to use "$@" (with the double-quotes) instead of %* (which is dos batch syntax), and you will need to use the full path to the converter executable file, e.g.
    “/Applications/Adobe DNG Converter.app/Contents/MacOS/Adobe DNG Converter”
    If too much, just use the GUI instead of the bat file.
    Rob

  • HT1391 How does one delete apps or files from iCloud Permanently so I may re-download without retrieving existing cloud file?for example the U2 Marketing fast , an Album I have no interest in...is now in my Cloud.. How can I remove this File from iPhone &

    How does one delete apps or files from iCloud Permanently so I may re-download without retrieving existing cloud file?for example the U2 Marketing fast , an Album I have no interest in...is now in my Cloud.. How can I remove this File from iPhone & cloud

    Hey there Matt.dvs1,
    Although there is not a way to remove past purchases from your iTunes account completely, you can hide them so that you don't have to see them if you don't want to. This article will help you do that:
    iTunes Store: Hiding and unhiding purchases - Apple Support
    Hide your purchases
    Open iTunes on your Mac or PC.
    From the Store menu, choose Store > Sign In, and then enter your Apple ID and password.
    Go to the iTunes Store.
    Click Purchased from the Quick Links section on the right side of the iTunes Store.
    Choose a content type by clicking Music, Movies, TV Shows, Apps, or Books from the top of the window.
    A list of your purchased items for the content type you are viewing will appear. Mouse over the item you want to hide until an X appears its top-left corner.
    A confirmation dialog will appear once you click the X.
    Thank you for using Apple Support Communities.
    All the best,
    Sterling

  • How does one remove temporary files from Safari?  A friend logged on to her Facebook account using my iMac.  Now I can't remove her e-mail address from Facebook.  It was suggested to me that I try clearing temporary files from Safari but I can't find

    How does one remove temporary files from Safari?  A friend logged on to her Facebook account using my iMac running Mac OSX 10.7.5 and Safari 6.1.6.  Now I can't remove her e-mail address from my computer.  When I open Facebook her address shows in the user button.  I do not have a Facebook account.  It was suggested to me that I try clearing temporary files from Safari but I can't find anything that tells me how to do this.  Are temporary files the same as the cache?  It also was suggested that I try clearing Safari cache.  How do I do that?

    Check Safari/Preferences/Passwords to see if the Facebook account is there. If so, select it and remove it. If you are still having problems, Safari/Preferences/Advanced - enable the Develop menu, then go there and Empty Caches. Quit/reopen Safari and test. If that doesn't work, Safari/Reset Safari.

  • How does one update Subtemple value from Yes to No?

    Greetings! In the instructions of a published problem statement (Note ID: 808571.11) there is a line that says:
    "c) Check if the subtemplate is set to NO. Update it to NO if it is set to Yes."
    How does one update the Subtemplate value from Yes to No? In edit configuration, I do not see a Subtemplate value column.
    Many thanks in advance fr your suggestions.
    Tom

    With all due respect ... I do not see how one can change the Subtemplate value from Yes to No. When I query the offending Template, the Subtemplate column is not displayed in bold, indicating to me that it can not be updated. Clicking on Edit Configuration, doe not provide an ability to change the value either.
    As best I can determine, one needs to 1) query up the template
    2) download the rtf file(s)
    3) end date the template
    4) create a new template and then set the Subtemplate value to No.
    And the same steps appear to be required in order to add or update a template Description.
    Which raises the question, Why can this not be done by editing the configuration?

Maybe you are looking for

  • Hide password and user name fields in secure form on landing page

    On a landing page I don't want the password or user name displayed in the "secure" form because I think it will keep people from downloading our e-book. It will cause what some refer to as too much friction-visitors will feel that we are asking too m

  • Font embedding in Flash CS5

    Hi, I have 3 swf files: Main, FontLibrary and Graphics. Main.swf loads the other two and applies logic. Graphics.swf is created in Flash CS5 and contains a dynamic TextField instance, to which I want to apply a font from FontLibrary.swf. To know whic

  • My high resolution pictures got blurry and pixelet when imported into i-mov

    Hi I am trying to import bunch of high resolution pictures into I-Movie, when run the test, pictures all look very blurry and pixelet (lost pixel). I even disable the Ken Burn Effect inside the picture settings. Is there a way to keep the same qualit

  • ABAP errors messages stacking in BW

    We have experimented with available message types to send errors while validating variable input. Type "I" seems to work the way we want it to; however, I had to change one of our standard web template settings to no longer suppress warnings (<param

  • Converting into xstring

    Hi everyone, I have a non-character like structure and i wanna print it by passing the vallues of it into an xstring. So can anyone tell me is there anyone class which can be helpful in this process. If anyone has used it please try sending me the co