New OS X Trojan Adware Injects Ads Into Chrome, Firefox, Safari

timothy posted 1 year,29 days

Botnet 129

An anonymous reader writes "A new trojan specifically for Macs has been discovered that installs an adware plugin. The malware attempts to monetize its attack by injecting ads into Chrome, Firefox, and Safari (the most popular browsers on Apple's desktop platform) in the hopes that users will generate money for its creators by viewing (and maybe even clicking) them. The threat, detected as "Trojan.Yontoo.1" by Russian security firm Doctor Web, is part of a wider scheme of adware for OS X that has "been increasing in number since the beginning of 2013," according to the company."

Anonymous Coward | 1 year,29 days | (#43237239)

Happy now??? Grow up dickhead!!!

Inb4 apple h8rz (2)

noh8rz10 (2716597) | 1 year,29 days | (#43237491)

Inb4 cries of "but apple always said they were virus free!" NB this is a Trojan which the user installs himself. These have always been an issue with macs, although not very prevalent. Now OSx has built in blacklisting which is pushed out to all computers every update. I'm sure this will be blocked in the near future if not blocked already. Not too shabby, eh?

Re:Inb4 apple h8rz (-1)

Anonymous Coward | 1 year,29 days | (#43237899)

Ooh god stfu. Majority of applefags couldnt tell the difference between the two. Congrats on having a brain. Maybe you can actually use it

Re:Inb4 apple h8rz (2)

Wookact (2804191) | 1 year,29 days | (#43238367)

You do realize that in the minds of 99.9% of the population that trojans are a type of virus. Therefore if you say you are immune to viruses, and you KNOW that people think trojans are viruses, and you DO NOT clarify. Then you have INTENTIONALLY misled people.

Re:Inb4 apple h8rz (2)

noh8rz10 (2716597) | 1 year,29 days | (#43238509)

what do you want me to say? regardless of people's perceptions, words have definitions, and those definitions are what defines them. truth and accuracy are the twin torches by which I light my path in life.

Re:Inb4 apple h8rz (2, Interesting)

Wookact (2804191) | 1 year,29 days | (#43238587)

Actually in the world of communications, misunderstandings are the speakers fault, and not the listeners fault.

Apple intentionally mislead people. It does not matter if they are technically correct, they left out key information that would have assisted the listener in understanding the issue better. That makes it AOK in my book at least to gripe about the fact that Apple mislead the pleebs.

Food for thought::
Bill Clinton said he did not have sex with Monica, and he didn't, and people still got pissed at him for "lying". Why is that?

Re:Inb4 apple h8rz (1)

noh8rz10 (2716597) | 1 year,29 days | (#43239673)

I dont think you know much about communications. Perhaps you misunderstood what I said earlier?

Re:Inb4 apple h8rz (1)

Wookact (2804191) | 1 year,29 days | (#43240001)

I have obviously failed to explain my position adequately.

I understood you correctly if you were saying that apple never made the overt claim that they are safe from trojans. Therefore people should not make any disparaging comments concerning their previous statments.

My supposition is because they made an overt claim that it was safe from viruses, that they implied that they were protected from malware. Due to the implication that Apple was safe and others were not, that they mislead consumers.

That is exactly like Billy misleading America when he said he did not have sex. He did something that most people would consider a form of sex, even if it technically is not.

Apple claimed they do not have viruses. They do have stuff that many people would consider viruses. Even if they technical are not.

Therefore if people believe that Bill lied, then the same logical steps could be used to come to the same conclusion that Apple lied.

Re:Inb4 apple h8rz (1)

noh8rz10 (2716597) | 1 year,29 days | (#43240397)

to be fair, if you go back to the marketing material, you'll see that apple claimed to be immune to PC viruses. A very true statement!

Re:Inb4 apple h8rz (1)

kermidge (2221646) | 1 year,29 days | (#43241719)

Given the percentage of people who watch television and the number of some of the advertisements I've seen, I'd venture that most people consider Trojans to be a brand of raincoat to be worn by Mr. Willie "Pud" Johnson for, among other things, preventing the spread of viruses and such.

Re: Inb4 apple h8rz (2)

mjwx (966435) | 1 year,29 days | (#43241493)

Very shabby. Blacklists suck as a defence. Look at how many different versions of Windows Trojans like Zeus and Conficker there are. Blacklisting one only means that a malware author has to make minor revisions to get around it. A malware author with half a brain would have prepared several in advance. Blacklist all you like. It wont help against an unpatched vulnerability or an 0day. The problem with Apple security is that Apple have trained their users to believe they are automagically protected.

Re: Inb4 apple h8rz (0)

noh8rz10 (2716597) | 1 year,29 days | (#43241863)

Just sayin, whenever there is an apple story all the googtards and apple h8rz come out to play. I'm trying to inject some rational logic into the convo.

Re: Inb4 apple h8rz (2)

smash (1351) | 1 year,29 days | (#43242171)

Which is where gatekeeper comes in. If gatekeeper is enabled this will either warn that this is unsigned code, or outright prevent it from running unless the user bypasses it manually. I.e., if you run a current OS (even back to 10.7.4) - you are, by default, protected from this.

Re:Inb4 apple h8rz (1)

smash (1351) | 1 year,29 days | (#43242149)

Furthermore, even if you don't use the blacklisting, both Lion (Pretty sure, since 10.7.4) and Mountain Lion both have gatekeeper. Which if enabled or left enabled will warn that this software is not signed.

Sure, if you have this option turned off then you can run and install it like any other software. But if you've turned that option off, it is expected that you know what you are doing.

Re:The only defence is a good HOST file (1)

benjfowler (239527) | 1 year,29 days | (#43237455)

Utterly pointless.

This guy isn't even pissing anybody off for entertainment value.

Doesn't compute.

Re:The only defence is a good HOST file (2)

black3d (1648913) | 1 year,29 days | (#43237891)

He's trying to do a parody of Time Cube. www.timecube.com It's a relatively good impression in places, but it'd be better in a more appropriate article.

Re:The only defence is a good HOST file (0)

Anonymous Coward | 1 year,29 days | (#43237645)


Clarification (3, Insightful)

schneidafunk (795759) | 1 year,29 days | (#43237043)

Can someone explain to me why advertisers would want to pay for bogus clicks? How does this money get laundered to hide the trojan creator and also defraud the advertiser?

Re:Clarification (0)

Anonymous Coward | 1 year,29 days | (#43237111)

They pay without wanting to, that's the short answer. There's no filter for "good clicks"

Re:Clarification (1)

schneidafunk (795759) | 1 year,29 days | (#43237351)

That's not 100% true. I've done adword campaigns through Google (and other sites) and was able to track the return on investment from different ads & clicks.

Re:Clarification (2)

Darinbob (1142669) | 1 year,29 days | (#43239463)

It's their own fault. They do automatic signup and usage of advertising, without ever meeting their customers or getting a contract. Imagine an ad agency doing this with radio and television stations; you could just mail in a letter saying you are manager of WAFK 101.1 FM, and their spot played 27 times, so please pay up.

Better Question (4, Interesting)

Deathlizard (115856) | 1 year,29 days | (#43237335)

Can Someone explain to me why Yontoo is detected on the Mac Platform but on Windows it's totally ok.

While we're at it, why are any of these still not detected by any malware scanner. Even as a Potentially Unwanted Program? I'm sure just about anything listed here does a lot more malicious stuff than anything spyware like Gator ever did.

Anything from Conduitt
Anything from Mindspark Interactive
coupon wonderland
big fish games
we care ASCPA Reminder (my personal favorite. When you uninstall it, it basically accuses you of wanting to kill puppies.)
shop to win
inbox toolbar
anything from Crawler
24x7 help

Most of the above either popup ads, install, or trick users into installing more junk like registry scanners, fake flash players and the like. Yet almost no scanner I've found short of JRT or ADWcleaner gets rid of these things.

It's about time these AV companies wake the heck up and realize that Spyware is back disguising itself as adware and is more prevalent than ever,

Re:Better Question (0)

Anonymous Coward | 1 year,29 days | (#43238109)



This is a valid question.

And while we're at it, let's put Wajam on that list, too.

Re:Better Question (1)

Aryeh Goretsky (129230) | 1 year,28 days | (#43244037)


Not sure which anti-malware software you are using, but a quick check of my employer's gave me half-a-dozen hits:

Not sure about the others, but would not be surprised if they are detected, just with a different name than you wrote. Maybe you just need to change anti-malware software, and make sure detection of Potentially Unwanted Applications [welivesecurity.com] is turned on on it.


Aryeh Goretsky

this is how it works (0)

Anonymous Coward | 1 year,29 days | (#43237385)

When you have a website and get Google's advertising, they'll pay you when someone clicks on the ads being shown on your site - when I did it, they wouldn't send you a check until your Google ad acount hit $100; which is A LOT of clicks - tens of thousands. That's right, if you never hit $100, Google keeps the money - they kept about $20+ from me.

So, if you have something or someone that can click the ads, you could rake it in at the advertisers' expense. It's against their policy and if they found out, they'd just shut your account down, but it happens and I don't think that they can check.

Makes sense (0, Troll)

ColdWetDog (752185) | 1 year,29 days | (#43237055)

As everyone on Slashdot knows, Apple users exist only to spend money. They have no other useful information (who cares about email contacts these days). Just get them to click on the ads and you're golden.


Re:Makes sense (2, Funny)

Anonymous Coward | 1 year,29 days | (#43237115)

Meanwhile the communists using Linux are not a target since they all have ad blockers and get their content via torrents anyway.

Re:Makes sense (0)

Anonymous Coward | 1 year,29 days | (#43237223)

"... not a target because of the average aptitude level of the users .."


Re:Makes sense (0)

Anonymous Coward | 1 year,29 days | (#43237845)

Personally, I've been using Linux for a decade and a half and I'm borderline retarded.

I guess I'm just helping to level out that average.

Re:Makes sense (0)

Anonymous Coward | 1 year,29 days | (#43239457)

Personally, I've been using Linux for a decade and a half and I'm borderline retarded.

That's his point, they'd struggle to understand the ads anyway.

Great Strategy (1)

Anonymous Coward | 1 year,29 days | (#43237063)

>hopes that users will generate money for its creators by viewing (and maybe even clicking) them

Nothing makes me want to support a company more than when in injects advertising onto my computer.

Not true !!! (0, Funny)

Anonymous Coward | 1 year,29 days | (#43237133)

This has to be a lie, because everybody knows there is no such thing as viruses, worms or ad-ware on OS-X operating systems. They're so advanced, that these things are impossible.

Re:Not true !!! (0, Flamebait)

Lumpy (12016) | 1 year,29 days | (#43237673)

You must be one of those retards that posted the same comments over on lifehacker...

I love how utterly uneducated you fools are.

I'll worry when it can spread without an installer (5, Insightful)

Kenja (541830) | 1 year,29 days | (#43237137)

Basically, this requires you to download and execute an installer, then click through it (including entering the administrator password). At that point, you could have installed something far worse then adware.

Re:I'll worry when it can spread without an instal (1, Funny)

RedHackTea (2779623) | 1 year,29 days | (#43237199)

Hmmm, so the only useful thing from this /. post: I like the adorable, red robot with the shiny key!

Re:I'll worry when it can spread without an instal (4, Insightful)

h4rr4r (612664) | 1 year,29 days | (#43237201)


The user is a flaw every OS has.

Re:I'll worry when it can spread without an instal (1)

the_Bionic_lemming (446569) | 1 year,29 days | (#43237237)

Only now, it's "Blame the user" instead of the way it used to be - "Blame that Buggy OS" ..

Re:I'll worry when it can spread without an instal (4, Insightful)

h4rr4r (612664) | 1 year,29 days | (#43237329)

Not at all.

Blame the buggy OS is when you get a nice drive by install or virus. Adware that requires a user to install is always the users fault.

Re:I'll worry when it can spread without an instal (1)

Thrill Science (2845693) | 1 year,29 days | (#43237587)

No it's not always the user's fault. Try doing this on an un-jailbroken iOS device.

Re:I'll worry when it can spread without an instal (1)

h4rr4r (612664) | 1 year,29 days | (#43237647)

Then you tell the user to do a jailbreak. Sure it might not always work, but conning users is conning users.

I would rather take the risk, than have my ability to own my computers stolen from me.

Re:I'll worry when it can spread without an instal (1)

dgatwood (11270) | 1 year,29 days | (#43238895)

No it's not always the user's fault. Try doing this on an un-jailbroken iOS device.

Only the approach is different. There's nothing preventing you from convincing users to install a web browser that provides some customization features and displays extra ads in exchange. And if you can convince them to install it and use it, you now have adware that isn't really substantially different from adware that installs itself as a Safari browser extension on the desktop.

So yes, adware that requires a user to explicitly install it is always the user's fault. You can certainly try to make it harder for the user to make changes that they can't undo, as iOS does (and, to some degree, OS X does), but ultimately if a user is so naïve that he or she is incapable of recognizing scams, that user will eventually get conned, and there's really not much you can do about it besides finding and arresting the people who do the conning and punishing them harshly so that they will serve as an example to others.

Re:I'll worry when it can spread without an instal (1)

BasilBrush (643681) | 1 year,29 days | (#43240161)

There's nothing preventing you from convincing users to install a web browser that provides some customization features and displays extra ads in exchange.

Unless the app is up front about this in it's description, then the app will be rejected. If it *is* upfront, and the user chooses to install it anyway, then it's not a problem. The user decided the tradeoff was worth it for the features they are getting.

Re:I'll worry when it can spread without an instal (0)

Anonymous Coward | 1 year,29 days | (#43239535)

Wasn't it a while back where it was a feature of said platform that simply opening a PDF would jb said devices?

Re:I'll worry when it can spread without an instal (1)

smash (1351) | 1 year,29 days | (#43242213)

Try doing this with gatekeeper enabled. If it works at all, it will be for a limited time only until apple revoke the cert, and go after the developer who the cert was issued to.

Re:I'll worry when it can spread without an instal (1)

AmiMoJo (196126) | 1 year,29 days | (#43241879)

Maybe they are complaining that MacOS runs any software you like, unlike iOS where everything is curated by Apple. This "criticism" (I view it as a complement) is often levelled at Android, for example.

Re:I'll worry when it can spread without an instal (1)

BasilBrush (643681) | 1 year,29 days | (#43240071)

Well not quite. This is where the curated app store of iOS comes in. The user can only install apps from a store that requires the apps to be prevetted. And the store will remove any malware that manages to sneak past the vetting process, as soon as it becomes known.

This is removing user stupidity as a vector for trojans.

Re:I'll worry when it can spread without an instal (1)

hawk (1151) | 1 year,29 days | (#43241617)


This isn't "malware;" it's "stupidware."


Re:I'll worry when it can spread without an instal (4, Funny)

j00r0m4nc3r (959816) | 1 year,29 days | (#43237227)

At that point, you could have installed something far worse then adware

Like RealPlayer

Re:I'll worry when it can spread without an instal (1)

Anonymous Coward | 1 year,29 days | (#43237893)

At that point, you could have installed something far worse then adware

Like RealPlayer


Re:I'll worry when it can spread without an instal (2)

BLToday (1777712) | 1 year,29 days | (#43238035)

QuickTime on Mac is pretty useful. It's shit on WIndows. On the Mac, QuickTime can be used for screen recording and is generally pretty fast. Never knew how useful a screen recorder was until my friend needed to record a training session. Windows version is like me trying to run a marathon in a business suit, isn't very functional and pretty slow.

Re:I'll worry when it can spread without an instal (0)

Anonymous Coward | 1 year,29 days | (#43241111)

Yeah but you look so damn sharp.

Re:I'll worry when it can spread without an instal (1)

BasilBrush (643681) | 1 year,29 days | (#43240189)

Jeez, you just reminded me of one of the things that pushed me to switch to OSX. The Realplayer menace - shudder.

Re:I'll worry when it can spread without an instal (0)

thetoadwarrior (1268702) | 1 year,29 days | (#43237281)

Exactly. It doesn't really target OS X, it targets complete morons.

Re:I'll worry when it can spread without an instal (0)

Anonymous Coward | 1 year,29 days | (#43237375)

Exactly, and everyone knows Apple [youtube.com] product users are known for their savvy!

Re:I'll worry when it can spread without an instal (2)

smash (1351) | 1 year,29 days | (#43242233)

Most of the network engineers, storage engineers I know run Mac Laptops. Linus himself owns apple machines. Try again.

Re:I'll worry when it can spread without an instal (1)

marsu_k (701360) | 1 year,28 days | (#43244139)

Linus himself owns apple machines.

...and he runs Linux on them, your point is?

Re:I'll worry when it can spread without an instal (3, Funny)

Anonymous Coward | 1 year,29 days | (#43237315)

You and the summary left out the best part: the installer's name is "Free Twit Tube." Almost as bad as a girl on a dating site agreeing to go out with someone with the username "DonkeyPunchLover."

Re:I'll worry when it can spread without an instal (2)

Anubis IV (1279820) | 1 year,29 days | (#43237389)

Exactly. And given past trends, it's entirely likely that there will be a malware definition update pushed out to all Macs running the last few iterations of OS X within the next 24-48 hours, rendering this threat moot.

Moreover, even in the case of idiotic users, the default behavior on all new Macs is to not allow installs from unregistered developers. I.e. This malware will only work against folks who ignore all warnings and are using something other than the latest release, which had an extremely fast adoption rate, or for users who have explicitly chosen to override the default behavior, in which case they'll still need to ignore all of the warnings.

Re:I'll worry when it can spread without an instal (2, Insightful)

Anonymous Coward | 1 year,29 days | (#43237941)

And then, after downloading, and authenticating the install, OS-X also reminds you that it is from the Internet and you might want to pause and consider before actually launching the program.

It really does target people who *want* to run it.

Re:I'll worry when it can spread without an instal (0)

Anonymous Coward | 1 year,29 days | (#43237521)

Unlike in Windows, where you simply have to view an advert in Internet Explorer and your system is infected...

Re:I'll worry when it can spread without an instal (0)

Anonymous Coward | 1 year,29 days | (#43237801)

You mean just like that other thing that happened to mac users last year?

Re:I'll worry when it can spread without an instal (3, Insightful)

amicusNYCL (1538833) | 1 year,29 days | (#43238191)

Unlike in Windows, where you simply have to view an advert in Internet Explorer and your system is infected...

IE itself is exploited no more than 10% of the time to infect a Windows computer. Windows gets drive-by infections these days from exploits in Java, Acrobat, and Flash, which are not unique to Windows. There's no reason for attackers to focus on a single browser any more when they can instead target a plugin like Java that works across all browsers.

Re:I'll worry when it can spread without an instal (1)

McFly777 (23881) | 1 year,29 days | (#43239377)

There's no reason for attackers to focus on a single browser any more when they can instead target a plugin like Java that works across all browsers.

Java... Write once, Infect everywhere!

Re:I'll worry when it can spread without an instal (0)

Anonymous Coward | 1 year,29 days | (#43241751)

I'd say typically Windows users who don't use IE are savvy enough to have things like adblock, no script, have disabled java in their browser etc. It is the users who "stick with the defaults" who are more likely to be infected. Chances are they won't even have any malware protection installed either. This could maybe be your "mom and pop" crew, or the people who simply believe IE is secure thanks to Microsoft's adverts and removing browser choice (http://www.bbc.co.uk/news/technology-21684329). Not saying others don't get infected, just they are typically more knowledgeable. Thankfully, it seems most people are realising using a Windows OS means making a lot of changes to browsing habits, as Chrome now seems to have a large portion of the browser market share (http://en.wikipedia.org/wiki/Usage_share_of_web_browsers).

Re:I'll worry when it can spread without an instal (1)

smash (1351) | 1 year,29 days | (#43242247)

You mean like the huge number of users still running Firefox 3.5, despite there being many security updates it doesn't have?

Re:I'll worry when it can spread without an instal (0)

Anonymous Coward | 1 year,29 days | (#43237989)

Then it wouldn't be called a trojan but a worm...

Macos, like windoze, is a juicy target because it has a lot of users and many of those are completely clueless.

Re:I'll worry when it can spread without an instal (1)

smash (1351) | 1 year,29 days | (#43242189)

You also forgot - bypass gatekeeper or click through the "are you sure, this is unsigned code?" warning.

Yontoo (2)

BradleyAndersen (1195415) | 1 year,29 days | (#43237163)

Yontoo has been around already, and not just @ Macs. I recently removed it from a Windows 7 PC. The uninstaller does not uninstall (shock!) ... one needs to remove registry keys to prevent this thing from sticking itself into Chrome, IE, etc. Spybot will find it well before Norton and others.

Re:Yontoo (2)

MachineShedFred (621896) | 1 year,29 days | (#43237495)

Luckily for Mac users though, that if it installs from a standard PKG or MPKG (which another comment above basically states) you can go to /var/db/receipts and get the entire bill of materials for that package with the lsbom command.

Pipe that into a delete routine, and you're all set.

(this works as a fairly effective uninstall for most PKG installs)

Re:Yontoo (1)

BasilBrush (643681) | 1 year,29 days | (#43240245)

Interesting. Is that how apps like AppZapper know what to delete when uninstalling some random app?

I'm not sure how useful it would be for malware though, because when it's run for the first time, it can of course create new copies of files with different names and/or locations.

Re:Yontoo (1)

MachineShedFred (621896) | 1 year,28 days | (#43244685)

I haven't looked at AppZapper, but I did write a perl script that would uninstall just about any PKG by reversing the order of the lsbom output, and then deleting files, and deleting the directory if it was empty.

Worked like a champ for getting rid of an application that liked to scribble all over the disk, rather than be a good Mac app and self-contain...

As for the malware thing, it's got to run from somewhere. As they can't even be bothered to find themselves a proper exploit to get installed, I doubt they are executing from somewhere not in the following list:

Find the .plist, blow it away, reboot. The rest is benign.

Here it comes (0)

Sparticus789 (2625955) | 1 year,29 days | (#43237171)

In this corner, wearing the green trunks, the Apple FanBoys. In the opposing corner, wearing the blue trunks, the Windows FanBoys. Standing outside the ring, holding the steel folding chair and molotov cocktail, the Linux FanBoys. LET THE GAMES BEGIN!

uh oh (4, Interesting)

slashmydots (2189826) | 1 year,29 days | (#43237225)

Yontoo Layers is a "legitimate" advertising program that just barely complies with US laws. I find it on at least 1 in 3 customer computers at my shop. It has a legit uninstaller and asks for permission to install by piggybacking on freeware and installer framers like download.com's new atrocity. So to call it a trojan is just asking for another Symantec style lawsuit for defamation, etc. You have to call it "possibly unpopular software" now. And if this is coincidentally another Yontoo unrelated to the actual company, that's a whole new depth of deep shit they're in for naming it that. That'd be right up there with naming it Pepsi.

Pepsi (0)

Anonymous Coward | 1 year,29 days | (#43239375)

That's brilliant, naming a virus after a brand to keep people from talking negatively about it.

Re:Pepsi (1)

slashmydots (2189826) | 1 year,29 days | (#43241021)

Don't virus writers rarely name their viruses? It's usually "security researchers" they name them. They should stop giving them such cool-sounding names half the time! Seriously@ Yontoo is crap but I've heard stuff like overlord and mega-justaboutanything and things sounding like a japanese robot. Seriously. Call it jackass1, asshole2, and my favorite, srslywtfwhatajackass32

Simpler the Better (1)

F.Minusia (748125) | 1 year,29 days | (#43237233)

Seems to be done in a simpler way without depending on Java. But the report at Dr webs does not say much?

I remember when they'd convince you to install it (0)

Anonymous Coward | 1 year,29 days | (#43237355)

By offering to pay you. Was it AllAdvantage? AdAdvantage? I can't recall. I got like one check from them.

Was nice.

It seems that every year /. hypes a Mac Trojan. (-1, Troll)

RocketRabbit (830691) | 1 year,29 days | (#43237371)

These proof of concept Trojans, which were likely all created by AV software companies, come out every year or so and Slashdot reports on them like clockwork.

What about the Trojan that delets all your data? It looks like this, and works on Linux too!

rm -rf /

Re:It seems that every year /. hypes a Mac Trojan. (1)

CanHasDIY (1672858) | 1 year,29 days | (#43237545)

shred -fuz /*

Re:It seems that every year /. hypes a Mac Trojan. (1)

AliasMarlowe (1042386) | 1 year,29 days | (#43238081)

shred -fuz /*

If you're not logged in as root (and many linuxes strongly discourage it), you'd need a sudo in front of that. Anyway,
sudo srm -rz /*
would work better, as it will wipe many jounaled file systems. Both would leave fragments around on NFS volumes, however.

While you're at it, don't forget to leave the shred or srm command until last, after you've cleaned "empty" space and the swap file. To clean empty space, first fill it with:
sudo scrub -X -s 1G /
Some versions of scrub will also remove the files securely after making them, but others don't. So it's best to securely delete them in a separate step. The swap partition should be wiped with:
sudo swapoff -a
sudo umount -f /dev/swap_partition
sudo sswap -z /dev/swap_partition

Then you can issue the shred or srm command, leaving you a nice clean unbootable system.

Re:It seems that every year /. hypes a Mac Trojan. (1)

CanHasDIY (1672858) | 1 year,29 days | (#43239679)

... aaaaand this is why I continue to visit Slashdot! Great post, man. Just spiffy. /nosarc

Re:It seems that every year /. hypes a Mac Trojan. (1)

0111 1110 (518466) | 1 year,28 days | (#43243437)

How can you use sudo without the account password? Also, what if sudo is not installed?

Re:It seems that every year /. hypes a Mac Trojan. (1)

flyingfsck (986395) | 1 year,29 days | (#43238037)

Yeah well, rm -rf is so 01d 5k001. You can do much better on bleeding edge Linux distros with: cat /dev/zero /tmp/crashme

I don't believe it! (1)

Thrill Science (2845693) | 1 year,29 days | (#43237441)

Steve Jobs told me the Mac was secure by design, and immune to attacks. I'm going to stick my fingers in my ears and sing "LA LA LA." This is obviously propaganda spread by Windows users.

Re:I don't believe it! (-1)

Anonymous Coward | 1 year,29 days | (#43237723)

Look everyone another person with an IQ below 81. Because he is too fucking stupid to know the different between a HACKER ATTACK, a VIRUS, and adware that requires the users to install it.

Put your thumb and finger on your forehead and say "herpderp" for the rest of the day you tard.

Re:I don't believe it! (1)

Anonymous Coward | 1 year,29 days | (#43237839)

Everyone here knows that when a user installs something malicious on Windows it is Microsoft's fault, but when a user installs something malicious on OS X it is the user's fault. Come on that is Slashdot 101.

macs don't get viruses... (0)

Anonymous Coward | 1 year,29 days | (#43238357)

...they get CANCER.

Lies..... (1)

Anonymous Coward | 1 year,29 days | (#43238719)

Lies.. All Lies.. Mac's can't be infected.

doctor web is an extortionist outfit (0)

Anonymous Coward | 1 year,29 days | (#43240019)

they create the virus and then "discover it". fuck russia and fuck russians.

Re:doctor web is an extortionist outfit (0)

Anonymous Coward | 1 year,29 days | (#43241573)

In Russia, the security firm controls the viruses.

internet explorer? (0)

Anonymous Coward | 1 year,29 days | (#43242121)

i was gonna ask why the adware doesn't inject advertisments into internet explorer, then i remembered most everyone doesn't use IE 5.2.3 on Mac OS X Snow Leopard 10.6. lol. But on a serious note; i didn't know that Apple operating systems encounter adware and malware. i only thought Windows computer catch adware. learned something new today.

bitch (-1)

Anonymous Coward | 1 year,29 days | (#43242437)

fun to be again. Hubbard a8d Mike if you* don't Usenet is roughly
