anne e

Q: Mac Defender

Mac Defender has appeared in my iMac (OS X 10.6.7)

I tried to remove it by dragging the program to the trash from the applications folder, but I cant because the program is open.

The program is pretending to be an antivirus program send $$, obviously a scam.

I re-started but I cat stop it from loading.

 

There is very little info on this program out there (MacDefender.app)

 

Any ideas?

iMac, Mac OS X (10.6.7)

Posted on Apr 30, 2011 8:41 AM

Close

Q: Mac Defender

  • All replies
  • Helpful answers

first Previous Page 6 of 12 last Next
  • by iGary,

    iGary iGary May 6, 2011 9:01 AM in response to Linc Davis
    Level 4 (1,577 points)
    Servers Enterprise
    May 6, 2011 9:01 AM in response to Linc Davis

    ...after entering the admin credentials.

  • by Linc Davis,

    Linc Davis Linc Davis May 6, 2011 9:08 AM in response to iGary
    Level 10 (208,037 points)
    Applications
    May 6, 2011 9:08 AM in response to iGary

    And the reason for the failure?

  • by iGary,

    iGary iGary May 6, 2011 9:57 AM in response to Linc Davis
    Level 4 (1,577 points)
    Servers Enterprise
    May 6, 2011 9:57 AM in response to Linc Davis

    I'm not sure. I didn't look into the Console logs.

     

    It seemed to me that it is a poorly written installer and is not able to gain access to /Applications, even after being supplied admin credentials.

  • by babsabstabs,

    babsabstabs babsabstabs May 6, 2011 3:06 PM in response to MacJoseph
    Level 1 (0 points)
    May 6, 2011 3:06 PM in response to MacJoseph

    I just did this and it worked to get rid of it.  Such an annoying bug.  Also called MacProtector.  So look out for both. 

  • by Dolphbucs,

    Dolphbucs Dolphbucs May 6, 2011 7:36 PM in response to Linc Davis
    Level 1 (55 points)
    May 6, 2011 7:36 PM in response to Linc Davis

    I seem to remember hearing somewhere ( I believe it was on a Tech Podcast ) that one of the advantages of a Unix based system is that permissions can only be elevated one level ( ie Standard to Admin or Admin to root but NOT Standard to Root ). If this is true, could it not be that the installer is looking for Root permission to install some file ?  If that were the case it would explain why someone logged in as standard ( as opposed to Admin )would have the installer not succeed. The above argument was used, I believe, to illustrate the benefit of running as a standard user whenever possible ( a practice that, for some reason, very few seem to want to follow even after hearing about cases such as this )

  • by R C-R,

    R C-R R C-R May 6, 2011 8:14 PM in response to Dolphbucs
    Level 6 (17,700 points)
    May 6, 2011 8:14 PM in response to Dolphbucs

    When the installer runs, it asks for an admin name & password. If a user supplies that then the install runs with admin permissions, elevated to root as needed.

     

    This has nothing directly to do with this malware. Any installer package that uses Apple's Installer.app & is programmed to install anything anywhere that requires admin or greater privileges will do the same thing. The request for admin authentication comes from Installer.app, not the package it is installing.

  • by Dolphbucs,

    Dolphbucs Dolphbucs May 6, 2011 8:29 PM in response to R C-R
    Level 1 (55 points)
    May 6, 2011 8:29 PM in response to R C-R

    Then why is it that some apps, like Final Cut Express, need to be installed from within an admin acct ? I thought it uses the installer.app ... maybe I'm wrong ?

  • by R C-R,

    R C-R R C-R May 6, 2011 10:02 PM in response to Dolphbucs
    Level 6 (17,700 points)
    May 6, 2011 10:02 PM in response to Dolphbucs

    Some app packages are programmed to allow installation only from admin accounts, or only over certain versions of the OS, or with other restrictions. This is done with scripts included in the package by the app's developer. Installer.app reads the scripts & executes them, subject to the limits it & the OS place on what the scripts are allowed to do.

     

    It's flexible & secure … as long as the user isn't careless or tricked into doing something ill advised..

  • by Dolphbucs,

    Dolphbucs Dolphbucs May 6, 2011 10:54 PM in response to R C-R
    Level 1 (55 points)
    May 6, 2011 10:54 PM in response to R C-R

    Ahhh, thanks for clearing that up. Come to think of it, I believe that podcast was talking about Unix in general .... not OS X specifically and definitely they did NOT mention Installer.app.

  • by kimberlyfrommerrimack,

    kimberlyfrommerrimack kimberlyfrommerrimack May 7, 2011 5:50 AM in response to MacJoseph
    Level 1 (0 points)
    May 7, 2011 5:50 AM in response to MacJoseph

    WHERE DO I FIND ACTIVITY MONITOR?

  • by kimberlyfrommerrimack,

    kimberlyfrommerrimack kimberlyfrommerrimack May 7, 2011 5:58 AM in response to MacJoseph
    Level 1 (0 points)
    May 7, 2011 5:58 AM in response to MacJoseph

    I tried removing to trash, but I got a message from finder that I couldn't trash because it was open.  I can't shut it down...as there is not a close.

  • by Linc Davis,

    Linc Davis Linc Davis May 7, 2011 6:17 AM in response to kimberlyfrommerrimack
    Level 10 (208,037 points)
    Applications
    May 7, 2011 6:17 AM in response to kimberlyfrommerrimack

    Don't bother with Activity Monitor. Start up the computer in safe mode by rebooting and holding down the Shift key when you hear the chime. Keep holding it until the Apple logo shows on the display. Then you can empty the Trash. Also open the Accounts preference pane and delete any login items you don't recognize. Finally, reboot again as usual (without holding the Shift key.) That will get rid of it.

     

    For your information, you can launch applications by typing the first few letters of their name in the Spotlight text box, under the magnifying glass on the right side of the menu bar. You don't have to hunt for them in the Applications folder.

  • by karelshades,

    karelshades karelshades May 8, 2011 3:48 PM in response to anne e
    Level 1 (0 points)
    May 8, 2011 3:48 PM in response to anne e

    Ok, I am really new and don't know how to go to my library or activity monitor. HORRIBLE websites are popping up on my computer.

     

    Please! Would someone type out instructions from the beginning. I can't allow my children on here until this is off completely.

     

    Thank you in advance for your time!!!

  • by peter186,

    peter186 peter186 May 8, 2011 3:56 PM in response to bobfromeugene
    Level 1 (0 points)
    May 8, 2011 3:56 PM in response to bobfromeugene

    I don't understand. The scam software requires admin password to install. From what I've seen it can't just install by itself. It downloaded the zip on my Mac but I never installed it so just deleted it.

  • by WZZZ,

    WZZZ WZZZ May 8, 2011 4:06 PM in response to peter186
    Level 6 (13,112 points)
    Mac OS X
    May 8, 2011 4:06 PM in response to peter186

    In response to karelshades:

     

     

    First, restart in Safe Boot by holding the Shift key down at the chime. Or, alternatively, open Activity Monitor in Utilities, set to Active Processes, find the program and force quit it. This will keep it from running, so you can remove it.

     

        1.    Drag the MacSecurity program -- or whatever it's called, MAC Defender, MacProtector (installed in the Applications folder by default) to the Trash. Empty the Trash.

        2.    Remove item of same name from the Login Items for your Account in the OS X System Preferences (if it exists).

        3.    Go to your Home folder Library>Preferences and Application Support (may not be one there) and search for any files with one of the above names and trash them. Empty the trash.

        4.    If you use Safari, go to Preferences>General and UNCHECK "Open "safe" files after downloading. Keep that unchecked.

     

    If you paid for it, they have your credit card #. Call your credit card and dispute the charges. Also, cancel the card ASAP.

     

    As a precaution, change your password.

     

     

    If you don't feel comfortable with any of that, then one option is to download the free demo of MacScan. Be sure to run any updates.

     

    http://macscan.securemac.com/

     

    http://www.securemac.com/MAC-Defender-Rouge-Anti-Virus-Analysis-Removal.php

first Previous Page 6 of 12 last Next