What is decryptedFile.dmg?

First off, I am a new Mac user, so bear with me. I opened Disk Utility and noticed that a seemingly strange file was showing up. Underneath the name of my hard drive and SuperDrive is "decryptedFile.dmg" and underneath that on a sub-level is "Flash Player." I researched online and found that "decryptedFile.dmg" is a sign of the Flashback trojan, but I've also read that it is a harmless 'leftover' from installing Flash Player. I bought my iMac in July of this year. Can someone please calm my nerves and confirm what this file is and does? Here is a screenshot:

Hi ABuck, and a warm welcome to the forums & Macdom!
Your pic doesn't show, draging & dropping on this forum looks like it woirks until you submit, you have to use the Camera icon in a reply to actually upload it.
Some info on that Trojan...
Disable Java in your Browser settings, not JavaScript.
http://support.apple.com/kb/HT5241?viewlocale=en_US
http://support.google.com/chrome/bin/answer.py?hl=en-GB&answer=142064
http://support.mozilla.org/en-US/kb/How%20to%20turn%20off%20Java%20applets
Flashback - Detect and remove the uprising Mac OS X Trojan...
http://www.mac-and-i.net/2012/04/flashback-detect-and-remove-uprising.html
In order to avoid detection, the installer will first look for the presence of some antivirus tools and other utilities that might be present on a power user's system, which according to F-Secure include the following:
/Library/Little Snitch
/Developer/Applications/Xcode.app/Contents/MacOS/Xcode
/Applications/VirusBarrier X6.app
/Applications/iAntiVirus/iAntiVirus.app
/Applications/avast!.app
/Applications/ClamXav.app
/Applications/HTTPScoop.app
/Applications/Packet Peeper.app
If these tools are found, then the malware deletes itself in an attempt to prevent detection by those who have the means and capability to do so. Many malware programs use this behavior, as was seen in others such as the Tsunami malware bot.
http://reviews.cnet.com/8301-13727_7-57410096-263/how-to-remove-the-flashback-ma lware-from-os-x/
http://x704.net/bbs/viewtopic.php?f=8&t=5844&p=70660#p70660
The most current flashback removal instructions are F-Secure's Trojan-Downloader:OSX/Flashback.K.
https://www.securelist.com/en/blog/208193454/Flashfake_Removal_Tool_and_online_c hecking_site
More bad news...
https://www.securelist.com/en/blog/208193467/SabPub_Mac_OS_X_Backdoor_Java_Explo its_Targeted_Attacks_and_Possible_APT_link
Crisis OS X Trojan is an effective spy tool…
http://www.net-security.org/malware_news.php?id=2200
Removal for 10.5...
http://support.apple.com/kb/DL1534
Check now whether your Mac is infected by Backdoor.Flashback.39!
http://public.dev.drweb.com/april/

Similar Messages

  • What' s "decryptedFile.dmg"?

    Hi there, My name is Piero and I'd need your help.. I've found a strange and unknown volume on the side bar of my UtilityDisk panel: it's called "decryptedFile.dmg" and classified as a "FlashPlayer something".. searching news on the net I've seen someone says is a virus, someone else says is sometin' 'bout FlashPlayer.. but there's nothin' certain and no-one is sure it's something safe or not.. do you know what is it and if I should remove it or not?
    Thank you very much to the ones who'll answer and help me.
    Bye,
    PIERO!!!

    I just found the same thing on my Mac.
    Clean installation of 10.8 as of 3 months ago. 10.8.2 update from just a few days ago. Java is NOT installed. Gatekeeper is enabled and set at default (won't open downloaded applications/packages that aren't signed or from Mac App Store without user interaction).
    Current Adobe Flash is installed and is set to auto-update itself.
    I ran Apple's official Flashback removal tool here: http://support.apple.com/kb/dl1517 just in case (the tool is simple, it just runs without notification if everything is OK, and only notifies if it found and removed the Flashback trojan). Nothing was found, and all I did was simply highlight the file in DiskUtility and click the "Eject" button in the menu.
    It is highly improbable that the mysterious dmg is a result of a Flashback trojan which is currently physically impossible to have been installed on my machine. Unless it has been greatly modified since it has been blocked and none of the AV companies know about it yet (some of which knew about Flashback before it became a problem for enough users for Apple to release the tool).
    Certainly it's something that could maybe possibly happen, but is not likely to be happening right now.
    Also, if anyone wants to spend the extra minute or two searching this issue specifically here in the discussion forums (through Google), user dmdimon is in every single one promoting the tool he has linked earlier in this thread, and scaring users with each further post while several others dismiss his claims. Apple has their own official Flashback tool to run that I linked to above. Apple has also released an official patch through Software Update.

  • Que es DecryptedFile.dmg Flash Player ??

    Hola a todos, a mi me ha pasado lo mismo,
    Pero lo que me preocupa es que ningún empleado trabajador de Apple o trabajador de Adobe Flash Player, se pronuncie y diga que es eso de decryptedFile.dmg Flash Player
    Saludos,
    Hi all, to me has been the same,
    But what worries me is that no Apple employee or worker worker of Adobe Flash Player, to rule and say that's that Flash Player decryptedFile.dmg
    regards,

    Hola, tengo la ultima versión OS X 18.8.2
    ¿porque en utilidad de disco sale esto? decryptedFile.dmg
    ¿Whay in utility Disk? decrypted.dmg
    Saludos regards
    https://discussions.apple.com/search.jspa?resultTypes=&dateRange=all&peopleEnabl ed=true&q=decryptedFile.dmg&containerType=&container=&containerName=&username=&r ankBy=relevance

  • What is a dmg file?

    What is a *.dmg file?  I am showing one in my Finder called ABEIDSNCS4_LS1.dmg and it's an image file.  My concern is that the size is 1.16 GB. What could this be and can I delete it?
    Thank you.

    .dmg files are Disk Images. Basically they act like a separate volume on a hard drive. Often when you download an application from the Internet it comes on a disk image file. Once you have run the installer, you can delete them by dragging them to the Trash and emptying the Trash. Another way would be to hold down the control key on your keyboard when you click on the .dmg file and select Move to Trash from the menu that appears. Again you'll want to empty it.
    Best of luck.

  • What is a Dmg? What is in that .ipa File?

    Does Anyone know what is inside that .ipa file? is it just the N45Ap.Plist file will the reconizations true and not false?
    Also What is a Dmg, And how can i open using windows?

    *What is a Dmg, And how can i open using windows?*
    That is a Mac disk image file, it's not for use on Windows. Opening a disk image file on OS X will mount a virtual disk on the Desktop. It's commonly used to deliver software installers for Mac programs. For instance a Mac user downloads and installs iTunes in such a file.

  • What is ACCD DMG file and what is it for?

    What is ACCD DMG file and what is it for?

    See the last post in this thread: https://discussions.apple.com/thread/2084745?start=90&tstart=0

  • I bought and transfer mac application (fxpansion Tremor) to ipod touch. Double tap dmg file in FileApp brings up unknown filetype dialog. What app processes dmg files to install them?

    I bought and transfer mac application (fxpansion Tremor) to ipod touch. Double tap dmg file in FileApp brings up unknown filetype dialog. What app processes dmg files to install them?
    an ipod touch supports all files types which its apps support

    thanks, it's good to get a reply, but why do you keep going on about windows? Agreed, there is no mention that Tremor runs on iOS. So far this is the only reason given that it cannot run on iOS. You can read and I can read.
    By putting the question to the community I was hoping for something like: the app you want is here-link, or the app you want cannot be written because technical-reason.
    From a words point of view it would seem to be open for any ios developer to support DMG files.

  • In disk utility, below Macintosh HD I have 4 trojan "decryptedFile.dmg (flash player)" and my computer is super slow, does erasing Macintosh HD will also erase these files?  If not how can I erase? (bear in mind computer so slow a click takes forever)

    in disk utility, below Macintosh HD I have 4 trojan "decryptedFile.dmg (flash player)" and my computer is super slow, does erasing Macintosh HD will also erase these files?  If not how can I erase? (bear in mind computer so slow a click takes forever)

    Thank you Thomas in fact I have seen your guide before  and had gone thru the steps including repair disk which didn´t work. I am erasing disk before checking hardware. I have posted a photo of the 4 decrypted files in the disk utility and also of the adobe icons in the dock and question marks. Some people say if the adobe appears in the dock is because it is the trojan flash player and they keep jumping in the dock.  If this is not malware it seems to be an incredible coincidence that when I start seeing these things in my dock and the decrypted files in my disk utility is when my computer goes so slow (I am typing this in my macbook air because to write this message in my imac would be about 6 hours, I am not kidding, it is completely useless at this point it took me 2 and half days too instal mac os x after disk repair, it took me 3 days to transfer just 100 gigabites and now is taking the whole day (and it says another day more) just to erase the disk. Despite all this the icon of adobe keeps jumping in the dock so, although I am no computer and mac expert, just an user, I am inclined to think that it is malware and it is a shame that mac doesnt´recognize it or have anything here to help me get rid of this.  I am not even sure if erasing the disk will work since repairing didn´t work... all advice is welcomed.

  • What is a *.dmg.cc extension?

    i downloaded a hash app but it came with a .dmg.cc extension. what is the cc suffix?

    I found one "dmg.cc" file on cnet downloads. It is litelabel something or other. It is just a poorly made upload file and very unlikely to run on Lion or be worth your time.
    That is the problem with Sophos. It slows your machine down and gives you a false sense of security. There never was any malware risk on Macs. The risk of poorly made 3rd party software is much higher. All Mac anti-virus software falls into that category.

  • What is tempinstallmc.dmg?  Should I delete it?

    The program "tempinstallmc.dmg" keeps popping up on my desktop of load a program.  Even after moving it to trash, it appears on the desktop later.
    Can it be deleted without harming the operating system?

    You inadvertently installed adware. Eradicating it is simple and you don't have to download or install anything to fix it.
    tmpinstallmc.dmg, if you were to open it, will subsequently attempt to install the Genieo adware. Don't do that.
    For an explanation or how this may have occurred, how to avoid it in the future, and for Apple's recommended solution read How to install adware.

  • /Mac HD/private/var/folders/hw/gblkb20s77bcj2wxv_pcm8f80000gp/T/decryptedFile.dmg

    This is showing up in Disk Utility.  I have no clue what it is or how to actually get to it.
    I'm not seeing any issues on my system, but this has never been there before.  Any help appreciated.
    Lloyd

    Link is good on my machine.  And no, it isn't a server.
    But I got to the file, mounted it and found out it was the Flash Player installation crap!  I deleted it since my flash player is up to date.  Who knows what the heck Adobe was doing stuffing that there.
    Thanks for the reply.

  • Strange decryptedFile.dmg appearing in Disk Utility window.

    See screenshot. I have no file on my desktop with this name and I can't find it using Spotlight and the path at the bottom doesn't exist?
    Is this a virus?

    Thanks Thomas
    I just found it strange and a bit scary after hearing about viruses coming in on the back of Flash.
    I noticed that it came back yes.
    I dug down to the hidden file it's located in, (see screenshot) really messy, but couldn't access as no permission to open folder it's in.
    If you think this is OK I'll get on with some work.
    Thanks again for your quick response.
    John

  • Disk Util shows "decrptedFile.dmg" and below Flash Player - Is this a virus?

    While doing some routine maintenance with Disk Utility I see a disk image showing but it is hidden. I have nothing  connected by usb except an external HD which is listed separately.
    I am worried about this because it shows up as a disk image but I cannot see it.
    The string is:
    /ROB'S /private/var/folders/00/28smjdm92zs__qh85x2sc2gc0000gp/T/decryptedFile.dmg
    I used REVEALER to make the files visible
    I find a lot of files in there but I have no flash drive connected.
    Is this some kind of hidden virus?
    Should I remove these files?

    OK. Got it.
    Thanks for the help and the quick reply!
    I booted up from an external HD and checked later and it was gone.
    I wouldn't delete it without being sure of what I was doing.
    I very much appreciate the information and help!
    THANKS!
    Expat in Kunming, China

  • DMG file after partitioning with Disk Utility

    For the first time that I know of a file appeared after I partitioned a new external hard drive.
    The file is listed in Disk Utility under the grey line
    decryptedFile.dmg
    Flash Player
    It says it is located on the boot drive at:
    /private/var/folders/dZ/(long string of alpha numeric)
    (Note: Tried to post a screen shot here but I failed that task.)
    The file must be an invisible file or my bifocals are cloudy because I did not find same.
    Appreciate any info on what and why of this file. Attaching a screen shot.
    Thank you

    I don't recall ever working on Flash Player but I'll take your word.
    Thanks for the help. I'll delete and forget.
    BTW, are they invisibles?
    Thanks,

  • .dmg problems

    Hey good people,
    I'm sure this is a silly question with an easy answer.. but nevertheless I have to ask it because I can't seem to figure it out by myself..
    I got Virtual PC in a .dmg file, and want to install it. When I open the .dmg file it mounts up like it should and inside is a file 1.5GB without any file extension. I tried to open it, but it is not recognized by any program. I then tried to open it with Stuffit-expander, but it just starts up and shuts down again after a few seconds (I guess Stuffit doesn't understand that file eighter). I also tried to just drag (copy) the file out of the mounted .dmg volume, but still couldn't open it after that..
    Does anybody have any ideas what I should do? Is it possible the file is an ISO file or something ...that I have to create a CD from it and install Virtual PC from that CD ??
    Would appreciate any advice!
    Thanks guys
    Stian Andre

    I agree with you that these forums should only be used to discuss issues of technical usage etc.
    I'm glad you agree.
    But I have to disagree with you when you're saying that I asked for assistance on stolen downloaded software.
    Ummm... by your own admission, it was
    What I wanted help on was to figure out how to deal with the .dmg file I had, because I'm not exactly sure about how they function yet, being a PC-person up until now. How I should extract or convert the information in them etc was the help I meant to ask for.
    A .dmg file is a self mounting file. It is an image of a CD or DVD. When you double click it, the image is mounted; kinda like inserting a CD/DVD into your drive.
    I obviously shouldn't have mentioned what it contained (that was a mistake I really agree on and I certainly see that my question is not expressing that intent), because that was what you focused on, comparing me with a common thief and all, witch I have to tell you I'm not.
    What I focused on is discovering from where you got the .dmg file from. If it was from a legitimate source then I would have been able to further assist you by dowloading it myself and seeing if I could replicate the symptoms you were experiencing. Since the source was not legitimate there is nothing we can do to assist.
    Anyways, I don't intend to turn this into a discussion about filesharing, because I see with your strong opinion that you have already made up your mind in that regard.
    You are correct, I do have strong opinions on this. Theft is theft. One can try and disguise it or whatever but at the end of the day it is theft.
    I'm sure you're a real rightful fella that has never downloaded a single mp3 or anything.
    I have never obtained software or music via questionable means. Everything I have is fully registered.
    All right, so to end this the right way I want to say that I didn't mean to bring down the quality of this discussion group with my question. I surely should have formulated my question in a different way! I'm sure most of you see that. I think these groups are awesome, even though some here are aggressively interested in criticizing genuinely well-meant asked questions.
    Stian - when you download a file from a questionable source and, inveriably, encounter problems what do you expect us to say.
    Your question about what is a .dmg file is legitimate. Part of the fault finding process though is to try and replicate the symptoms. There is no way that I, and I would contend others, would download a dodgy file from a dodgy source. The solution to your symptoms is to delete the .dmg file and buy Virtual PC. If you insist in continuing to download various files from questionable sources then expect to encounter problems.
    My computers are very mission critical to me. They are used to provide solutions to my clients. That's how I earn my living. There is no way on this earth that would risk infecting them with dodgy files. Is your computer mission critical to you?
    Red Dwarf

Maybe you are looking for

  • Source system 8(ODS name) does not exist

    Hi experts! When I transport some Process Chane from DEV to PRD I faced with issue that the source system 8(ODS name) does not exist. Is anyone faced with same error? Thx!

  • Problem building some pkgs from AUR

    I think this must have a known solution, but I didn't found it :-/ so I'm asking. Today I tried to compile these pkgs: http://aur.archlinux.org/packages.php?ID=754, http://aur.archlinux.org/packages.php?ID=261 In both cases, I got this Error message

  • Can I upload images that are not photos?

    Alright, so to start off I am new to macs. I want to make a website for a project I am currently working on and I want to include on a few of my pages some .jpg/.gif files that are not photos. I have tried looking through everywhere to figure out how

  • InDesign CS2 crashes on boot (Vista)

    Hi there I have just installed InDesign on this machine, and as soon as it tries to initialize, I get "Adobe InDesign CS2 has stopped working. A problem caused the program to stop working correctly. Windows will close the program and notify you if a

  • New camera tomorrow

    Well, the poking around is done and I have a new camera on the way which should land tomorrow. The Panasonic HMC70 was fine for its original intended purpose, green screen tutorial / interview type footage. However once I branched out into narrative