Saturday, July 2, 2011

A New Virus That Masquerades As Mackintosh Antivirus Software

A new malware attack for computers connected to the Internet isn't really news. There is one every minute. But only when it's for Windows computers is it not news – Windows computers have famously had nearly half a million pieces of malware designed for them. When someone designs malware especially for Apple computers, it certainly is news. The Mac has tried to push as its selling point it's low profile to malware designers. Apple has always said that the company, with its 12% market share, just doesn't present as interesting a target to malware designers. Apparently, someone just thought that designing stuff to take the Mac down could win him a bit of attention. The malware in question is especially remarkable for the fact that it masquerades as a version of the MacDefender Macintosh antivirus software. Mac users who try to download the popular MacDefender Macintosh antivirus software end up often with the pirate version that brings up a load of viruses with it.

So what exactly do people do wrong to actually become infected? Apparently, Mac users have mostly been targeted by the malware through the course of a search through Google Images. The malware apparently just downloads itself as you browse through images. You also need to be using Safari. As you go about the Internet, minding your own business, the Safari browser suddenly displays a message that your computer has been infected. It offers the rogue MacDefender macintosh antivirus software as the remedy for it. Macintosh users, who aren't really used to the deviousness that malware makers use to get past their defenses (Windows users would never fall for that one), readily believe in what they're being told.

The reason the creators of this virus have chosen to masquerade as the popular Macintosh antivirus software is probably that the Safari browser is by default set to automatically install trusted software. Since MacDefender is a trusted software company, it just gets right past the gate. The good part is, that this virus, clever as it is, isn't really that malicious. It just keeps asking you for payment and for your credit card number. To remove it is pretty simple.

To stop the program from running, you probably want to go to the Activity Monitor and disable everything that's named MacDefender. Search Launch Agents and Launch Daemons for any mention of MacDefender; look at your Library and StartUp items as well. Once you're done, you can then drag the MacDefender program from the Applications folder to the Trash. You can also search for MacDefender with Spotlight and delete everything you find. If you don't have the virus yet, make sure that you make it difficult for the virus to enter your computer in the first place. You need to open Safari, go to Preferences and under the General tab, take the checkmark out of the "Open 'safe' files after downloading." Box.

No comments: