You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Removing MacDefender variants

For anyone who has been affected by MacDefender, MacSecurity or MacProtector, I've got a full run-down on how to remove it, complete with screenshots, on my blog:


Identifying and removing MacDefender trojans


* Disclaimer: links to my pages may give me compensation.

Posted on May 7, 2011 11:48 AM

Reply
13 replies

May 7, 2011 12:13 PM in response to WZZZ

I have not heard of anything like that. It might be interesting for someone to use LittleSnitch to check and see what is being sent back. I may or may not have time to test that in the next few days... I think my wife might get a little annoyed if I'm jacked in to the computer too much tomorrow, it being Mother's Day and all! 🙂 To this point, I've only run these trojans long enough to see what they look like and get screenshots, and then I've deleted the entire account I ran them on. (And I haven't actually run the installer...)


Perhaps if I have some time next week I might create a SL system on an external drive and do some detailed testing. If anyone wants to beat me to it, feel free. 😉

May 7, 2011 1:44 PM in response to thomas_r.

I know your opinion of MacScan, but don't see why they'd be making this stuff up. This was where I found that bit about phoning home. No information on what, exactly, it may be sending back


From UPDATE - MAY 4TH, 2011


The new version did not change the main functionality of the code, but rather cleaned up the existing code and added small updates including the capability to send information about the infected system back to the authors of the malware

http://www.securemac.com/MAC-Defender-Rouge(sic)-Anti-Virus-Analysis-Removal.php


Also, latest is people getting infected from hotmail (scummail)


https://discussions.apple.com/thread/3042885?start=15&tstart=0

May 7, 2011 3:36 PM in response to WZZZ

I know your opinion of MacScan, but don't see why they'd be making this stuff up.


Yes, I agree that it's unlikely they'd just make stuff up. It would be too easy for someone to prove them wrong. However, before I jump at that possibility, I'll want to find out what's actually going on. After all, people freaked out about iPhone location data that turned out not to even be exactly what everyone assumed it was.

May 15, 2011 5:35 AM in response to babowa

That is not related. Sounds to me like some guy has been illegally distributing software he purchased through the App Store and other folks are downloading it, with our without the realization they are engaging in software piracy, and don't understand why it won't work for them without logging on to the account it was purchased on. It takes a real dope to distribute App Store software, since it's linked to your Apple ID. 😁

May 15, 2011 8:19 AM in response to thomas_r.

In addition to Thomas's excellent advice in removing the current incarnation of the MacDefender Trojan, one should also take into careful consideration that malware evolves and is altered and delivered by other parties.


What steps you are taking following Thomas's may work and appear to be enough, but it's impossible to be 100% sure as you can't compare his version of the malware with the version you have.


My advice is to take Thomas's advice as a first step, then take a additional measures to backup your files and resintall the operating system from the (hold c bootable) OS X installer disks after using Disk Utility to Zero erase (under the menu) your boot drive (all data will be destroyed, format HFS+ Journaled) and then reinstall OS X. Re-install programs from fresh sources.


Yes, it's a lot of work unfortunatly, if you don't know how to do this, take it to a computer professional who can.


If you didn't give this Trojan (or any malware) your administrative password (or it didn't gain root access some other way), then my steps above are not necessary.



To prevent this MacDefender Trojan from happening again:


It preys upon a JavaScript vulnerability on web pages among other things.


Since turning Safari's JavaScript Preference on/off constantly is a chore.


I advise using the Firefox web browser and the Add-On: NoScript which in Firefox Toolbar customization you drag a Noscript button to the toolbar or easy on/off of all scripts and plug-ins.


NoScript also offers other "web cop" features, it takes some getting used too as your surfing the web without anything running, then turning it on per site basis once you trust the site.


Firefox also has a download opt out window before it downloads, giving you a chance to stop this thing in it's tracks.

Removing MacDefender variants

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.