Apple to Issue Mac OS X Update to Remove 'MacDefender' Malware

Apple has posted a Knowledge Base article that addresses the recent MacDefender malware issue and also reveals they will be addressing it in the next few days through a software update
In the coming days, Apple will deliver a Mac OS X software update that will automatically find and remove Mac Defender malware and its known variants. The update will also help protect users by providing an explicit warning if they download this malware.
Apple describes "MacDefender" as a recent phishing scam that has targeted Mac users by redirecting them from legitimate websites to fake websites which tell them that their computer is infected with a virus. The user is then offered Mac Defender "anti-virus" software to solve the issue.

Apple also offers instructions and tips for avoiding installation of the malware and how to remove the malware. Apple had previously been criticized for not allowing their support staff from addressing the issue in retail stores.

111 months ago

nice to see them take a page out of MS book on dealing with this.

Easy there killer, there are posters here that still think Apple invented the zipper ;)
111 months ago

Never thought a Mac could get a virus. Hope it won't be bad as Windows viruses. Its good thing that APPLE is taking this seriously and not Microsoft.

To be clear, this is not a virus. It does not appear to self-replicate, spread itself to others, or steal information surreptitiously.

It is really more of a scam that requires the active duping and input of the user. Although it does qualify as malware...

Don't get me wrong. It IS possible for Macs to get viruses. But this isn't one.
111 months ago

It's NOT a virus. It's a piece of software written to perform hidden, often harmful tasks, MALWARE. The user still has to actually install it, unlike a virus which may be acquired with usual specific user actions such as opening an email or surfing.
111 months ago

You can't be serious.
111 months ago

really? seems a completely different approach to me.

Nope, MS releases updates that search for and remove common malware (it's called the malicious software removal tool).
111 months ago
In a slightly ironic twist, the fact that OS X doesn't have any viruses in the wild for it (and Apple have gained mileage from that fact) will actually make OS X less secure for some users than Windows.
The simple fact is that the biggest security weakness in any modern OS is the organic bit sat in front of the keyboard: Users do stupid things!

On windows, people are well aware of the perceived risks and most average users run AV software (it's difficult to buy a PC nowadays that doesn't come with it bundled and on Vista and Windows 7 you get nagged to death if you don't have it installed). This might not catch zero day exploits but the AV vendors catch up pretty quick and any malware is caught and removed early if the user is stupid enough to click through a security warning on a dodgy software install.

However, on OS X, the average user is sat there thinking: Everyone knows Mac's can't get viruses so I'm perfectly safe doing anything I want on the internet (they don't care about the differences between malware, viruses, trojans, worms, etc: to them, anything that does bad things to their computer is a virus).

Now when they get the "enter an administrator username and password" prompt, they probably don't even pause for thought as they are perfectly happy with their false sense of security

The harsh reality is that no computer is immune from malware that's willingly installed by the user and good security practice is as important on OS X as Windows: Don't have "run safe files after download" set in safari, and never, ever, give a program your admin credentials unless you know exactly where it came from.
111 months ago

What is the difference between viruses, worms, and Trojans?


What Is a Trojan horse?

A Trojan Horse is full of as much trickery as the mythological Trojan Horse it was named after. The Trojan Horse, at first glance will appear to be useful software but will actually do damage once installed or run on your computer. Those on the receiving end of a Trojan Horse are usually tricked into opening them because they appear to be receiving legitimate software or files from a legitimate source.
111 months ago
Apple has done this before with security updates but theyve nevr had something spread like this in the wild before.

Microsoft releases a monthly "Microsoft Removal Tool" to remove the worst offenders currently out there as well. hopefully apple will start to do this as they are going to have more and more of this with the growing user base they have.
111 months ago

It's only the front page and there's already some serious apple circlejerking. How about the news that Apple told the Apple Geniuses to not even recognize the Mac Defender, and pretend it's nothing?

Apple doesn't support 3rd party software. not at the bar, not in the training sessions, not over the phone.

As such, they are not trained on what the software does, how to remove it etc.

Because they are not trained on the software, attempting to service it without knowing clearly what they are doing risks actually doing more damage than good. Which, because they got involved, now means they are liable.

So they were actually better off not saying anything until the engineers etc had a chance to sort things out.

In the end, the only damage this software appears to have caused was by tricking you into telling them your credit card (or even several) for a software that would fake running a scan on your system and telling you that you are good, need to buy an update pack or whatever
111 months ago

How about the news

Unfortunately, you lack the mental capacity to distinguish between news, and rumors.

That would kinda explain your disdain and anger towards everyone around here.

Thankfully, I run in a non-admin account and would never download something as fishy as this.
But thanks, Apple, for taking care of the problem for others!

A non-admin account would have done nothing to protect you (although, its great practice). Your good sense in not downloading something as fishy as this is what really helped.
