Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Mac.BackDoor.iWorm

Do we have any official/semi-official answer yet on how to detect/remove this malware?

MacBook Air (13-inch, Early 2014), OS X Mavericks (10.9.5)

Posted on Oct 3, 2014 8:44 AM

Reply
7 replies

Oct 3, 2014 10:24 AM in response to henleygoldnet

maestroarts wrote:


Do we have any official/semi-official answer yet on how to detect/remove this malware?

Very little. Have not even been able to find anybody that has it, nobody seems to know where it comes from and only the executable files have been found, apparently not including the downloader Apple needs to come up with a signature for it.


With only 17,000 infected computers, it's highly unlikely you are one of them.


Intego and Dr. Web say they can remove it.


Look for this directory: /Library/Applications Support/JavaW/. If you find it, move it to your trash can and come back so I can tell you a couple of other things to look for.

Oct 3, 2014 11:13 AM in response to henleygoldnet

iWorm is not really new, known since 2009.

https://securelist.social-kaspersky.com/en/descriptions/iframe/Backdoor.OSX.iWor m.c


http://malware.wikia.com/wiki/OSX.iWorm



On a Belgium computer forum is mentioned that

Illegal software from the pirate bay is a possible cause ➽ read post #2.

http://www.intermactivity.be/forum/showthread.php?123944-OSX-malware-opent-de-ac hterdeur-Mac-BackDoor-iWorm


I just found this: Roll-your-own Defense Against Mac.Backdor.iWorm:

http://jacobsalmela.com/roll-defense-mac-backdoor-iworm/

Oct 3, 2014 12:34 PM in response to Raicya

Raicya wrote:


iWorm is not really new, known since 2009.

No, this is something very different. It bears resemblance to the old iService malware in many ways, but installs it's files in very different places, establish outgoing communications in a unique manner and sets it up as a botnet.


See Dr. Web announces new “iWorm” malware for most of what we know about this so far.

Jan 28, 2015 5:56 PM in response to tngn

tngn wrote:


Is it worth setting up Folder Actions as in the page at the link you provided?

I don't know your circumstances, but I would guess no. XProtect and GateKeeper should provide adequate protection now against future infection from iWorm as long as you don't disable it, if iWorm actually still exists anywhere today. AFAIK, all the active sources of this malware have been shut down.

are there Network Actions so that users can be alerted if an outgoing connection is established outside of system software like Safari?

Not provided by OS X. You would have to invest in something like Litte Snitch or Hands Off or an A-V software suite that provides such a firewall. A better alternative is to simply stay away from sketchy sites that distribute unlicensed media and software. That's the only place where iWorm was ever found.

Mac.BackDoor.iWorm

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.