You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Mac Defender

Mac Defender has appeared in my iMac (OS X 10.6.7)

I tried to remove it by dragging the program to the trash from the applications folder, but I cant because the program is open.

The program is pretending to be an antivirus program send $$, obviously a scam.

I re-started but I cat stop it from loading.


There is very little info on this program out there (MacDefender.app)


Any ideas?

iMac, Mac OS X (10.6.7)

Posted on Apr 30, 2011 8:41 AM

Reply
176 replies

May 2, 2011 11:00 PM in response to WZZZ

WZZZ wrote:

etresoft wrote: I just created my own MyTrojan.pkg.zip package. With the default Safari settings, just downloading this file will unzip it and start the installer.

Yes, the installer (Apple's Installer.app in the case of the MacDefender malware) will start (launch). But it will not install anything until & unless the user initiates that action by pressing the "Install" button.


I'm not sure it is actually possible to "fill the installer with animated GIFs" -- Installer.app generates the user interface & just reads content from the .pkg or .mkpkg files that launch it -- but even if it did, this is no different from what the rogue website did to simulate a scan. The install process is still controlled by Installer.app & nothing will be installed unless the user presses the "Install" button.


Sure, someone could attempt to use a preinstall script to do something malicious before anything is actually installed but, as explained in the "Component Package Scripts pane" section of this developer doc, that triggers a user warning before it will do so. The user has to dismiss & ignore that for anything to happen.


This malware is a social engineering exploit, not some new vector of attack that bypasses the security features built into OS X.


BTW, you might want to check out this Sophos article, which explains the attack in detail, including the fact that its free 'home edition' AV software for Macs already detects multiple versions of this 'fakeAV' exploit.

May 3, 2011 6:02 AM in response to anne e

I got hit with this this morning...I also installed it (have spent the last month planning a trip to Europe and a couple days ago I had a problem opening a .doc contract from a rental company). I thought perhaps there may have been a reason for that...or that that particular .doc may have been infected and my Microsoft Word app was somehow invaded. Yes, I should have known better but the MacDefender script makes it appear there really are "infected" files, etc. It all "happened" too quickly. As soon as I did it, I logged on here to check out my suspicions. I deleted the program using "Clean My Mac" and following the instructions in this thread, it appears to have cleaned out all the junk that came with the nasty little program.


Now I want my morning coffee.

May 5, 2011 5:51 AM in response to RadiomomDW

Gees! When will people learn that Macs are not infected by viruses and installing any antivirus software is the same as installing malware and/or spyware on your Mac? Just be careful what you download. I've used Macs for over a decade, both for business and pleasure and never run any anti-virus junk software nor have I ever had any issues. All this virus malarky is just left over paranoia from Windoze users. If your machine or browser is running bad it is because of a corrupt cache and/or preference file. That is all it can be.

May 5, 2011 6:40 AM in response to Silly rabbit

Silly rabbit wrote:

Gees! When will people learn that Macs are not infected by viruses and installing any antivirus software is the same as installing malware and/or spyware on your Mac?

That is a very simple view of a very complex topic. All AV software is not alike, & like every other kind of software -- including malware -- it evolves over time.


And just being careful is not necessarily enough: Apple takes trojans seriously enough that it has quietly added a modest amount of AV software into Snow Leopard itself, & although it works much like commercial AV software, it is currently limited to three specific types of trojans & is rarely updated.


The people easiest to fool are those that believe they can't be fooled. Whatever you decide to do about malware threats, don't think that just because you use a Mac you are immune. You may not always be able to tell a rogue web site from a legitimate one, or what looks like an Apple interface item from a bogus one. Pay careful attention not just to what you download or where it comes from, but also what happens after you download it.


If you are not an expert Mac OS user or for any other reason are not confident about your ability to tell trojans from legitimate software, you might want to consider AV software. Some users may need to configure their Macs for more security than the default, & Apple makes available guides for this as well.


It isn't all just malarky or paranoia. There are devious & clever people out there trying their best to compromise your Mac, & their attacks are getting increasingly more sophisticated & polished.

May 5, 2011 7:10 AM in response to Silly rabbit

"Gees! When will people learn that Macs are not infected by viruses and installing any antivirus software is the same as installing malware and/or spyware on your Mac? Just be careful what you download. I've used Macs for over a decade, both for business and pleasure and never run any anti-virus junk software nor have I ever had any issues. All this virus malarky is just left over paranoia from Windoze users. If your machine or browser is running bad it is because of a corrupt cache and/or preference file. That is all it can be."


i've had the same load of Windows XP on a machine for 9 years and never had an infection and have never run A/V software. and i ran several P2P file-sharing apps over that time. like i said before, it comes down to the user. you can pack your Windows system with all kinds of "defenses" but if you're not smart you WILL get infected.

as Mac becomes more popular you'll see malware written specifically for Mac OS. where there's a will there's a way. obviously Mac users need to smarten-up as well when i see all these threads about Mac Defender.

May 6, 2011 8:25 AM in response to anne e

I did some testing of this on a crash test dummy Mac I have. I wanted to see how the installer behaved in a Standard User account.


So I did a Google Images search using a keyword that I had heard would find the trojan for me. It took like 20 seconds to find.


So under a Standard User account and Safari's Open "safe" files option checked on, the download unzipped and presented an installer.


However, the installer failed after entering the admin credentials.

Mac Defender

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.