Defending against MACDefender

Recently, a new form of malware has been making the rounds and causing distress among Mac users. While surfing the web—typically Google Images—a message may pop up claiming your Mac is infected with a virus and recommending that you install a security program to clean it off. The program will then automatically prompt you for your system password to allow itself to install. After entering your administrator password, the next time you start your Mac, you will receive a message stating your machine is infected with a virus, and that the only way to get rid of it is to pay to register the software. Your system might also start randomly showing adult websites and Viagra ads to further “prove” it it is infected. While some of these symptoms may seem convincing, the good news is, they are all fake—there is no virus on your Mac.

The idea of “scareware” is not new. In the case of MACDefender, all of the warnings shown are fake; registering the program will do nothing more than remove them. Not only does MACDefender not clean anything, there was nothing to clean in the first place. This malware exists solely to dupe users into giving their credit card numbers to a scammer. For a the long time, these scare tactics were limited to Windows systems, since a “virus scanner” could install itself in the background without user intervention. A window appearing to be a legitimate Windows error screen would pop up and ask if you wanted to install a program to clean your system. Unfortunately, in this instance regardless of what you selected, your PC would already be infected. Thankfully, Macs are immune to this kind of browser exploit.

MACDefender appears to be a different animal as it isn’t a web page made to look like an application warning, it’s actually a Mac application. Many fake warnings use very poor grammar, so they are typically easy to spot as scams. While MACDefender is better than most, it still has its share of grammatical mistakes. For example, the “About” information contains the phrase: “The largest worldwide companies trust MAC Defender their nets and security.” However professional it may look, any malware appearing on OS X is bound by its built in security model: An application cannot be installed and modify system settings without an administrator password. In order to trick you into entering your password, the application makes it sound like the only smart choice is to install it. This is the critical step. If you do not enter your password, the application cannot install and no harm is done. If you did register the program and entered credit card information, you should call your bank immediately to alert them to watch your account activity.

Though any financial information given to the app unfortunately cannot be rescinded, it is at least relatively easy to remove MACDefender from your machine:

  1. Open System Preferences and go to the Accounts pane.
  2. Look at the login items for your account and find the listing for MACDefender. (It may also be called Mac Defender, Mac Security, Apple Security, or Mac Protector.) Select the entry and click the “-” sign to delete the it. Do not delete any other entries unless there is more than one listing for MACDefender.
  3. Restart your system. The fake “warnings” should not come up.
  4. Go to Applications and look for a program named one of the aforementioned titles. Drag this application to the Trash, and empty the trash.

To help prevent an attack like this from happening again, we recommend visiting Safari preferences and unchecking “Open safe files after downloading.” This will prevent applications from automatically launching. We also suggest visiting Sophos and downloading its free Mac scanner, which will warn you the next time something like MACDefender tries to infiltrate your computer.

To clarify a few points: Google Images is not the source of the problem. Whoever is trying to spread garbage like MACDefender is setting up web pages to spread it, and manipulating Google’s search engine to rank their sites higher. No matter what you search for, their site will appear—an attack such as this is called SEO poisoning. Second, MACDefender and its ilk are not technically viruses. A virus spreads itself without user intervention. Due to the security model built into OS X, a virus would not be able to install itself. MACDefender is considered to be malware, which can be as bad as a virus but cannot spread on its own from computer to computer. The best way to prevent malware is to pay attention to what you’re clicking on. If you go to a web page and are prompted for your system’s administrator password, you should navigate away from that page immediately.

Similar Posts

  • De-authorize your iTunes Account Before Hardware Repair or Sale

    Pretty much everyone has downloaded media from the iTunes store, but not too many of us know just how iTunes keeps track of computer authorization. Every device on the internet has at least two unique identifiers: a MAC address and an IP address.

    MAC is an acronym for Media Access Control. Many believe that Mac, the abbreviation for Macintosh, should be written with capital letters – this is incorrect. Likewise, iPod – not iPOD or IPOD; iMac – not iMAC or IMAC; etc. Network interfaces have MAC addresses; Macintoshes can be called Macs.

    Since your MAC address is completely unique, it’s the ideal way for iTunes to know that you’re authorized to play purchased content on any given machines. Trouble is, your ethernet port is part of the main logic board, which requires replacement in some repairs. With a new main logic board comes a new MAC address, which confuses iTunes and some other, generally high-end, software.

    You’re allowed to authorize up to five computers at any one time to play your purchased content, but replacing your logic board changes the MAC address. If you didn’t de-authorize before repair, you’ve lost 20% of your available authorizations. I made this mistake a few years ago when I had to replace the logic board in a Mac Mini hooked up to my television, and when I sold my iBook. I also lost an authorization when my two-week-old PowerBook G4 flew off the roof of my car at highway speed. Thankfully, iTunes allows you to de-authorize all computers on your account once annually.

    I only have one Machine these days, a 17-inch MacBook Pro, so this hasn’t been a problem of late for me. It’s a common question asked our technical support team, and a good fix to file in your troubleshooting arsenal.

    The full details from Apple can be found here: http://support.apple.com/kb/HT1420

  • Better Surfing With Safari

    While I occasionally use Firefox, and I think it’s great, Safari is my web browser of choice. Like most OS X applications, Safari…

  • OS X 10.4 Security Tip

    Here are the different types of user accounts that can be created and operated in OS 10.4. Knowledge of the different account types…

  • Chax – iChat On Steriods

    Ed recently informed me of this program called Chax. After a quick Google, I was downloading the latest version of this piece of…

  • Nifty Image Editor

    If you want to add that really cool mirror effect to your images then Picturesque is probably the easiest way to get it…

  • RAM Disk under OS X

    by Jon, Jon@smalldog.com (written by Jon, posted by Ed) RAM disks could be easily created in the Classic MacOS, going all the way…