New Mac trojan virus posing as a flash update
A new Mac trojan called OSX/Flashback.C has been discovered that poses as an Adobe Flash updater (see pic below) and installs code that disables the built-in antivirus program xProtect from updating.
The trojan was reported today by f-secure. They included these removal instructions:
Manual Removal Instructions
- Scan the whole system and take note of the detected files
- Remove the entry
LSEnvironmentDYLD_INSERT_LIBRARIES
%path_of_detected_file_from_step_1%
From:
/Applications/Safari.app/Contents/Info.plist
/Applications/Firefox.app/Contents/Info.plist
- Delete all detected files
So be careful with Flash updates, only get them directly from adobe.com
Further info is at http://www.f-secure.com/v-descs/troj...shback_c.shtml