This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

OS X Crisis/Morcut

Hi, 
I was researching an issue with flash player and the article linked below from ZDNET led me to check if I had either of the directories it refers to on my machine.

Article: http://www.zdnet.com/article/new-mac-malware-spies-on-you-via-adium-firefox-safari-skype/

Here are the directories I found on my system:

/Library/ScriptingAdditions/appleHID/

/System/Library/Frameworks/Foundation.framework/XPCServices/

I was concerned so I ran Sophos (I have the latest free version) and did a scan but it says "No threats found". I realize that the trojan will supposedly not work on systems running Mountain Lion or later (I'm on Yosemite 10.10) but I'm surprised that Sophos just ignores it.

So, should I delete these folders? Does anyone have any idea what other files this thing creates? Incidentally I found these directories on both my iMac and my Macair which are both on Yosemite 10.10.
 
This is really freaking me out as I am shocked that Sophos neither reported it nor cleaned it up.
Any information or help appreciated.
 
James
Milltek is online now Report Post  

:1020036


This thread was automatically locked due to age.
Parents Reply Children
No Data