Malware Warnings

 

Next Meeting

 

Fake security software takes aim at Mac users


'Rogueware' plague expands from Windows to Mac OS, tries to dupe Apple users into paying $60-$80 for a worthless "cure".

Recently a new series of Trojan horse attempts have targeted OS X users with downloadable malware applications that try to lure you to providing personal information, and with malicious Web sites that trick you into downloading malware onto your systems.

Links to Mac Malware and Virus Sources
Read Ron's and Jerry's two page list as presented at Club Mac of Monterey.
Their list is available in three formats:

Mac Malware and Virus Sources.pdf
Mac Malware and Virus Sources.html
Mac Malware and Virus Sources.docx


Jerry's CMoM Yahoo site has vital information! 

Click here:  http://tech.groups.yahoo.com/group/ClubMacMonterey/messages


See messages with various links to help identify and manage current malware for the Mac which is circulating on the Net. 
The MacGuard variant is particularly vicious
.  Prevention is key!

Click here:  http://tech.groups.yahoo.com/group/ClubMacMonterey/messages

420   Securing your Mac from the new MacGuard malware variant
MAY 25:  Securing your Mac from the new MacGuard malware variant by Topher Kessler......

422 Apple offers MacDefender malware removal instructions
MAY 25:    Apple offers MacDefender malware removal instructions by Topher Kessler The new MacDefender malware for OS X is scam software that is......

423 UGNN - Apple Malware: How bad is it?
More on malware... http://www.ugnn.com/2011/05/apple-malware-how-bad-is-it/#more-9707......

426  Apple's new malware security offers daily definitions updates
MAY 31:   Apple's new malware security offers daily definitions updates by Topher Kessler ......

427 Apple's malware detection update circumvented in 8 hours
JUNE 1, 2011 9:08 AM PDT Apple's malware detection update circumvented in 8 hours by Topher Kessler ......

428    Re: Apple's malware detection update circumvented in 8 hours
June 1:   I installed the Apple security update and I was infected in four hours!...... David C. Powell

429    Apple quashes latest version of MacDefender
JUNE 2:  Apple quashes latest version of MacDefender by Elinor Mills .......

430   OS X 10.6 showing high CPU usage after Security Update
JUNE 2:  OS X 10.6 showing high CPU usage after Security Update by Topher Kessler .......

431 Bug in System Preferences Security Pane
Here's some info and a link about this bug. Jerry.......

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Hello Jerry,

The security update is for Apple's "Xprotect" malware detection technology. This was introduced in OS X 10.6 so users of OS X 10.4 and 10.5 will not benefit from the update (and will not be able to install it). Users of both OS X 10.4 and 10.5 will need to use a third-party scanner to detect the malware, or use a manual method for removing the malware.

-Topher
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


http://reviews.cnet.com/8301-13727_7-20067942-263.html

Apple's malware detection update circumvented in 8 hours

June 1, 2011 9:08 AM PDT   by Topher Kessler    Let the cat and mouse games commence. Less than a day after Apple tackled the malware threats in OS X with an updated implementation of its malware detection technologies, the MacDefender malware developers have issued another variant that bypasses Apple's definitions to root out and remove the malware.
As described by ZDNet editor Ed Bott, the new variant comes as a download called "Mdinstall.pkg" and will run without being detected by Apple's new security implementations. It also shows that the malware developers are very actively trying to circumvent Apple's efforts; the file's time stamp shows that it was issued less than 8 hours after the security update for OS X was released.


http://news.cnet.com/8301-27076_3-20067694-248.html

Apple security update targets MacDefender malware

Security Update 2011-003, which went out to Mac OS 10.6 Snow Leopard users this afternoon, adds file quarantine and built-in removal of the MacDefender malware.


http://support.apple.com/kb/HT4650

How to avoid or remove Mac Defender malware   A recent phishing scam has targeted Mac users by redirecting them from legitimate websites to fake websites which tell them that their computer is infected with a virus. The user is then offered Mac Defender "anti-virus" software to solve the issue. This “anti-virus” software is malware (i.e. malicious software). Its ultimate goal is to get the user's credit card information which may be used for fraudulent purposes. The most common names for this malware are MacDefender, MacProtector and MacSecurity.

The Resolution section below provides step-by-step instructions on how to avoid or manually remove this malware. Products Affected Mac OS X 10.4, Mac OS X 10.6, Mac OS X 10.5

How to avoid installing this malware   If any notifications about viruses or security software appear, quit Safari or any other browser that you are using. If a normal attempt at quitting the browser doesn’t work, then Force Quit the browser. In some cases, your browser may automatically download and launch the installer for this malicious software. If this happens, cancel the installation process; do not enter your administrator password. Delete the installer immediately using these steps:   (1) Go into the Downloads folder or your preferred download location. (2) Drag the installer to the Trash. (3) Empty the Trash.

How to remove this malware If the malware has been installed, we recommend the following actions:   Do not provide your credit card information under any circumstances.   Use the Removal Steps listed on the Apple support website.


User Group Network News, Views, Reviews
http://www.ugnn.com/2011/05/apple-malware-how-bad-is-it/#more-9707

http://news.cnet.com/8301-27080_3-20064394-245.html
     How bad is the Mac malware scare? (FAQ)

http://www.bleepingcomputer.com/virus-removal/remove-mac-protector

Remove Mac Protector (Uninstall Guide)   You can thank George Engel, LaMUG, for this one!  George writes: Step-by-step process on how to remove “Mac Protector” infection, with pictures. If you don’t need it yet, store this file somewhere for future use, or for a friend.  Open Safari, and go to this web-site. READ THIS REPORT


http://reviews.cnet.com/8301-13727_7-20063683-263.html#ixzz1MgMMuXlW

How to protect your Mac from recent malware

What the recent malware does:    If you have seen the false "Apple Security Center" Web site and have clicked on the "Remove All" button, the site will download an installer file for malware that runs locally on your system. The program is distributed in several forms that so far have taken the names "Mac Defender," "Mac Security," and "Mac Protector." When installed it will run in the background and launch pornographic Web sites and other unwanted content, and show a fairly clean and crisp-looking scanner interface that will ask you to purchase an upgrade.

Removing it!   1. Shut it down   2. Remove the program 3. Remove reference to the program

Ongoing protection:   1. Disable auto-handling of files   2. Always manually install programs or open documents   3. Install a reputable malware scanner.

There are a number of reputable malware scanners out there, so purchase one, install it, and keep it updated with the latest malware definitions. Some of these scanners are free, and others are commercial products (this list is not complete):
Sophos Antivirus   ::   MacScan  ::  Intego VirusBarrier  ::  KaperskyClamXav  ::  iAntivirus :: Avast ::  MacKeeper ::   Norton Antivirus  ::  McAfee VirusScan


Return to Top

 

 

 

 

 

 
CMoM Forum/Forum2006.html