Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

security software should it be installed

Should security software be installed.If so what is recommended.

iMac, OS X Mavericks (10.9.3)

Posted on Jun 13, 2015 8:01 AM

Reply
13 replies

Oct 22, 2015 5:51 PM in response to LynnNOW

Mi amigo got his wires crossed speed reading emails - here is his response to me (since he has gone to rehearse "tripping the lights fantastic") - he seems to be heartily endorsing Mountain Lion ( " ML " ) - as I recall, many have said that Mountain Lion was the best OS X version EVER - before or since.


Which computer? I thought ML was a wonderful OSX iteration on my 2012 MBP--it came with ML. Everything seemed to work right and on 4GB RAM.

Jun 13, 2015 8:14 AM in response to Skipbowler

DON’T PANIC! But be aware that the Internet is riddled with potential threats to the security and well-being of your Mac or iOS device. No computer system is completely immune from possible attack, but Apple’s OS X (being Unix-based) is less vulnerable than most, particularly the latest versions - Lion and Mountain Lion. The following seeks to offer some guidance on the main security threats and how to avoid them. If you have further questions please post in the forum appropriate to your particular hardware or operating system.


There are many forms of ‘Malware’ that can affect a computer system, of which ‘a virus’ is but one type, ‘trojans’ another. Using the strict definition of a computer virus, no viruses that can attack OS X have so far been detected 'in the wild', i.e. in anything other than laboratory conditions. The same is not true of other forms of malware, such as Trojans. (The expression ‘malware’ is a general term used by computer professionals to mean a variety of forms of hostile, intrusive, or annoying software. Not all malware are viruses.) Whilst it is a fairly safe bet that your Mac will NOT be infected by a virus, it may have other security-related problem, but more likely a technical problem unrelated to any malware threat.


Since the introduction of Snow Leopard, Apple OS X has an anti-malware system built-in known as XProtect but officially called File Quarantine (see here: http://support.apple.com/kb/HT3662 ), which may alert you to, and prevent installation of, certain forms of malware. Later versions of OS X include further features to protect you, about which here: http://support.apple.com/kb/PH11432 and Apple also recommend that you take simple steps to protect your Mac as detailed here: http://support.apple.com/kb/PH10580


So what other anti-virus software do I need?


Whilst viruses designed to attack the Microsoft Windows operating system cannot affect Apple OS X, it is possible to pass on a Windows virus, which you may have received but not noticed, to a Windows user, for example through an email attachment. Many use the free ClamXav just to check incoming emails for this reason. However, extensive testing in the Fall of 2013 showed that ClamXav is falling behind in terms of malware detection, and our resident expert Thomas A Reed now recommends either VirusBarrier Express or Dr. Web Light, both from the App Store. They're both free, and since they're from Apple’s App Store, they can't destabilize the system. Thomas’s excellent guidance on this subject can be read here: www.thesafemac.com/mmg


Many users also like the free application Sophos (although some have mentioned that it can slow your system down):


http://www.sophos.com/en-us/products/free-tools/sophos-antivirus-for-mac-home-ed ition.aspx



Do not install Norton Anti-Virus on a Mac as it can seriously damage your operating system. Norton Anti-Virus is not compatible with Apple OS X.


Do not install MacKeeper or iAnti-Virus: See this User Tip: https://discussions.apple.com/docs/DOC-3022


FAKE ANTI-VIRUS SOFTWARE and associated MALWARE (To repeat: the expression ‘malware’ is a general term used by computer professionals to mean a variety of forms of hostile, intrusive, or annoying software.)


Do not be tricked by 'scareware', such as pop-ups on your browser, that tempts computer users to download fake anti-virus software that may itself be malware.

Once installed, the software may steal data or force people to make a payment to register the fake product. Examples include MacKeeper and iAntivirus, but there are others. Also, beware of MacSweeper and MACDefender* (also goes under the name of MacProtector, MacGuard, MacSecurity or MacShield): These are malware that mislead users by exaggerating reports about spyware, adware or viruses on their computer in an attempt to obtain payment for an application that does nothing that free utilities do not also offer, and in many cases will also mess up your system.

*Malicious software dubbed MACDefender takes aim at users of the Mac OS X operating system by automatically downloading a file through JavaScript. But users must also agree to install the software, leaving the potential threat limited.


*(This malware is not to be confused with MacDefender, the maker of geocaching software including GCStatistic and DTmatrix. The company noted on its site it is not affiliated with the malware.)

Malware spreads through search engines like Google via a method known as "SEO poisoning." The sites are designed to game search engine algorithms and show up when users search for certain topics. It is always a good idea to Block Pop-ups in your browser preferences.


TROJANS and RE-DIRECTION TO FAKE WEBSITES


The appearance of Trojans and other malware that can possibly infect a Mac seems to be growing, but is a completely different issue to viruses.


If you allow a Trojan to be installed, the user's DNS records can be modified, redirecting incoming internet traffic through the attacker's servers, where it can be hijacked and injected with malicious websites and pornographic advertisements. The trojan also installs a watchdog process that ensures the victim's (that's you!) DNS records stay modified on a minute-by-minute basis.


Mac users should always obtain their copy of Adobe Flash Player directly from Adobe’s official website and to disable the "Open 'safe' files after downloading" option in Safari Preferences/General to avoid automatically running files downloaded from the Internet. Also, do not turn on Java in Safari Preferences/Security. Few websites use Java. Javascript is something entirely different and should be left active.


(Adobe is aware of malware posing as its Flash Player and warns users to ignore any updates that didn't originate on its own servers. "Do not download Flash Player from a site other than adobe.com," said David Lenoe, Adobe's product security program manager, in an entry on Adobe Product Security Incident Response Team's PSIRT blog. "This goes for any piece of software (Reader, Windows Media Player, QuickTime, etc). If you get a notice to update, it's not a bad idea to go directly to the site of the software vendor and download the update directly from the source. If the download is from an unfamiliar URL or an IP address, you should be suspicious.")

Last, but by no means least, using Open DNS is the simplest way of preventing infection in the first place. Open DNS also protects against phishing attacks, re-directs, speeds up your internet connection, and works for all users of OS X from Tiger upwards:


http://blog.opendns.com/2012/04/09/worried-about-mac-malware-just-set-up-opendns /


How to get it:


http://www.opendns.com/home-solutions


Java can present serious security threats: Users with Intel Macs running Snow Leopard OS 10.6, Lion OS 10.7 or Mountain Lion should ensure that they have downloaded and installed all the recent Java updates from Apple, which are designed to prevent infection and also remove any infection already present.

New Macs running Lion or Mountain Lion do not have either Flash Player nor Java installed.


+++ OTHER ISSUES +++



HOW TO AVOID RE-DIRECTION


Adding Open DNS codes to your Network Preferences should give good results in terms of added security (phishing attacks, re-direction etc) as well as speed-up of your internet connection:


Open System Preferences/Network. Double click on your connection type, or select it in the drop-down menu, and in the box marked 'DNS Servers' add the following two numbers:


208.67.222.222

208.67.220.220


(You can also enter them if you click on Advanced and then DNS)


Sometimes reversing the order of the DNS numbers can be beneficial in cases where there is a long delay before web pages start to load, and then suddenly load at normal speed:


http://support.apple.com/kb/TS2296


There may be other ways of guarding against Trojans, viruses and general malware affecting the Mac, and alternatives will probably appear in the future. In the meantime the advice is: be careful where you go on the web and what you download!


GENERAL ADVICE ON HOW TO AVOID INFECTION IN THE FIRST PLACE:

1. Avoid going to suspect and untrusted Web sites, especially p'orn'ography sites.


2. Check out what you are downloading. Mac OS X asks you for you administrator password to install applications for a reason! Only download media and applications from well-known and trusted Web sites, i.e. the developers’ own web sites or the Apple App Store. If you think you may have downloaded suspicious files, read the installer packages and make sure they are legit. If you cannot determine if the program you downloaded is infected, do a quick Internet search and see if any other users reported issues after installing a particular program.


3. Use an antivirus program like ClamXav. If you are in the habit of downloading a lot of media and other files, it may be well worth your while to run those files through an AV application.


4. Use Mac OS X's built-in Firewalls and other security features.


5. Avoid Peer-to-peer sharing applications. Download torrents (such as the now defunct LimeWire) supplying pirated software, movies etc are hotbeds of potential software issues waiting to happen to your Mac. Everything from changing permissions to downloading trojans and other malicious software can be acquired from using these applications. Similar risks may apply to using Facebook, Twitter, MySpace, YouTube and similar sites which are prone to malicious hacking: http://news.bbc.co.uk/1/hi/technology/8420233.stm

It has been estimated that one in six links posted on Facebook pages are connected to malicious software.http://www.bbc.co.uk/news/technology-12967254

6. Check for security updates from Apple using Software Update and install them!

YOUR PRIVACY ON THE INTERNET and the latest risks to look out for:


There is the potential for having your entire email contact list stolen for use for spamming:


http://www.nytimes.com/2009/06/20/technology/internet/20shortcuts.html?_r=1


And if you are using iPhone Apps you are also at risk of losing all privacy:


http://www.engadget.com/2010/10/03/hacker-claims-third-party-iphone-apps-can-tra nsmit-udid-pose-se/


The advent of HTML5 may also be a future threat to internet privacy:


http://www.nytimes.com/2010/10/11/business/media/11privacy.html?_r=1&hp


NOTE: Apple's Snow Leopard, Lion and Mountain Lion operating systems silently update the malware protection built into Mac OS X to protect against a backdoor Trojan Horse that can allow hackers to gain remote control over your treasured iMac or MacBook.


+++++ MORE POTENTIAL ISSUES +++++


PHISHING AND POTENTIAL IDENTITY THEFT:


"Phishing" (also known as "carding" or "spoofing") refers to email that attempts to fraudulently acquire personal information from you, such as your account password or credit card information. On the surface, the email may appear to be from a legitimate company or individual, but it's not.

As a general rule, never send credit card information, account passwords, or extensive personal information in an email unless you verify that the recipient is who they claim to be. Many companies have policies that state they will never solicit such information from customers by email, and that includes your bank, credit card company, and Apple.

If you do receive email that you're not sure is valid, here are some tips that can help you determine its legitimacy:

Learn how to identify fraudulent "phishing" email:

http://support.apple.com/kb/HT4933?viewlocale=en_US

How to report phishing scams to Apple:

via email to: reportphishing@apple.com

If you discover that emails are being received by your entire address list which you didn’t send, it is possible that you have been infected by a Botnet. Simply put, a bot – which is short for robot – is an automated computer program that allows outside sources to control computers remotely without the users' knowledge. A botnet is a network of hundreds or thousands of computers infected with botnet malware that communicates covertly with a command-and-control (CnC) server run by a type of cybercriminal called a botmaster. Unbeknownst to the individual users, their computers are linked in a rogue network which the botmaster can utilize for a variety of nefarious purposes.

Detailed information here:

http://mac-internet-security-software-review.toptenreviews.com/how-do-i-know-if- my-computer-is-a-botnet-zombie-.html

Additional reading:

"Antivirus Software On Your Mac: Yes or No?"

http://gigaom.com/apple/antivirus-software-on-your-mac-yes-or-no/


LAST BUT NOT LEAST: BE GLAD YOU HAVE A MAC!


Some Windows PCs can be infected with viruses during the manufacturing process in the factories - in other words they can actually be purchased with viruses bundled with the operating system!


Several new computers have been found carrying malware installed in the factory, suggests a Microsoft study.

One virus called Nitol found by Microsoft steals personal details to help criminals plunder online bank accounts.

Microsoft won permission from a US court to tackle the network of hijacked PCs made from Nitol-infected computers.

http://www.bbc.co.uk/news/technology-19585433


This does not happen with Apple computers!

Jun 13, 2015 9:22 AM in response to Klaus1

It has been a while since I saw you post the entirety of your User Tip(s) 😎


Too bad there is no facility in the JiveWare to have just ONE that uses aliases or parent dependency to get 'em where they need to be! Here's why...


In them ALL you say:

... No computer system is completely immune from possible attack, but Apple’s OS X (being Unix-based) is less vulnerable than most, particularly the latest versions - Lion and Mountain Lion. ...

DELE the last part or edit to include Yosemite? If these were files on a website server, it would be easy to do with something like Dreamweaver or BBEdit/TextWrangler, but alas, they are data in a database to which we have no such access.


Maybe I see why you don't do the Tips, but if you have the Tip local and paste it (as above) - 'tis easy fix.


buenos tardes

ÇÇÇ

(glad not to be in "The Cedars" neighborhood of my town, Big D. little a - double L a...s)

Oct 22, 2015 11:47 AM in response to ChitlinsCC

Thank you ChitlinsCC, much appreciated.


QUestion: I went to download it and install then run it and once I went to run it it said it can't because

it only works on systems Mac OS 8.0 and above (mine is Mac OS 7.5)


I'm happy to install and update my computer to newer OS but I've heard so many warnings and my business is too important to lose proper funcitonality of my computer or lose being able to run other programs, etc.


What do you or the community here suggest I upgrade my computer to? (and do I need to go through the sequence of upgrades

or can I just skip to whichever highest one is suggested?)


Forgive me if my question is incorrectly asked but this part of computing is obviously not in my wheelhouse. Thus, I all the more appreciate your support, wisdom and advice.


With gratitude,

Lynn

Oct 22, 2015 12:31 PM in response to LynnNOW

You're welcome.

Ooops! FWIW, I am on a PPC Powerbook w/ 10.4.11 - no adwaremedic for me either, but I am exceedingly careful.


Flattery will get you everywhere! I will notice whether anyone has chimed in - some folks are busy and some do not 'Follow' the Mavericks forum where yur post was 'tacked onto' an existing thread.


In the future, it is ALWAYS best to start your own New Question with a detailed Story of your issue - and pick an appropriate forum to stick it in. That last may be the hardest - rules of thumb:

  • if it is hardware related, put it in your Mac's forum
  • any software at all, put it in the OS X version forum (unless it is any Apple software other than Safari, although Safari has its own forum too)

Oct 22, 2015 10:54 PM in response to ChitlinsCC

Thanks CC! Yet another thoughtful, great reply.


So, if I"m to judge from your friend's reply correctly, I should get Mountain Lion and just go directly to there?
(and not upgrade further from this machine? I will probably get a new computer in the new year)


Also, THANK YOU for your advice. Well taken. I will do all new posts from now on when having an important question.


You...well,...ROCK!


:-)


Lynn

Oct 23, 2015 7:38 AM in response to LynnNOW

Based on what little you have said, your Mac should probably be considered compromised - and thus vulnerable to adware or malware you likely installed.


Here is what I would do:

  1. Start a New Question (top right of this page)
  2. Use the following as a guide thoroughly detailing the Story of what you did
  3. Choose the appropriate forum for Your Mac Model at the end of the "Post [Question]" page

You haven't really told us much about your experiences yet

I highly recommend the User Tip [linked below]

If you need some help getting some of the info in the first two bullets, let us know here BEFORE you get started

===

Tell us a Story

- with a beginning, a middle and end. We need to understand everything that you know and have experienced.

If this issue is new, tell us what immediately preceded its onset - add software, upgrade or update? New equipment?


Quoted from  Apple's "How to write a good question"

To help other members answer your question, give as many details as you can.

  • Include your product name and specs such as processor speed, memory, and storage capacity. Please do not include your Serial Number, IMEI, MEID, or other personal information.
  • Provide the version numbers of your operating system and relevant applications, for example "iOS 6.0.3" or "iPhoto 9.1.2".
  • Describe the problem, and include any details about what seems to cause it.
  • List any troubleshooting steps you've already tried, or temporary fixes you've discovered.
    Say you have tried to run MalwareBytes...AdwareMedic but OS is unsupported HERE


For a detailed "coaching", please see the User Tip > "Help us to help you on these forums"<https://discussions.apple.com/docs/DOC-5431>


"Keep It Short and Simple" - Take your time... but be thorough - ÇÇÇ

security software should it be installed

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.