Here's maybe some sanity in this exercise in yet another over-reaction from a security company that this particular malware has started.
I got this in a posting on usenet:
It seems that the entire Flashback thing is much ado about nothing. See
<
Threat Explorer - Spyware and Adware, Dialers, Hack tools, Hoaxes and other risks
99>. If an AV vendor, who by definition has a reason to shout and carry on
about a 'threat', makes a big deal out of something I usually regard their
announcements with some suspicion. If, however, an AV vendor, who by
definition has a reason to shout and carry on about a 'threat', declare that
a 'threat' is, and I quote, of a 'very low risk level', and that they have
detected '0-49' cases from '0-2' sites in the time starting 30 Sept 2011 (the
day they first detected the 'threat') and ending 6 April 2012 (the day that
the 'threat' assessment was last updated, well, I believe 'em. Symantec
doesn't think that this is a real threat. Why should you? An AV vendor,
looking to find something to trumpet so as to get people to buy their
product, could only find less than 50 infections at one or two sites in _six
months of looking_. Either they didn't look very hard or there's nothing to
find.