News & Information for Technology Purchasers NewsFactor Sites:     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
This ad will display for the next 20 seconds. Please click for more information, or scroll down to pass the ad, or Close Ad.
Home Enterprise I.T. Cloud Computing Applications Hardware More Topics...
Vblock™ Systems:
Advanced converged infrastructure
increases productivity & lowers costs.
Data Security
24/7/365 Network Uptime!
Average Rating:
Rate this article:  
Dangerous New Virus Scam Attacks Macs
Dangerous New Virus Scam Attacks Macs

By Barry Levine
May 20, 2011 1:54PM

    Bookmark and Share
Once installed, the malicious app, MAC Defender, indicates that the Mac PC or laptop is infected, and then opens Web pages for pornographic sites every few minutes. To counter the Mac "virus," the user is prompted to buy into MAC Defender's "anti-virus" protection service, and the trouble continues from there.

A frequent debate topic between Mac and Windows fans is Apple's susceptibility to viruses and other malware. Some say Mac is an intrinsically safer platform, which is the reason given as to why Macs are not nearly as virus-prone as Windows ones. Others contend that, with their smaller market share, Macs are simply not a target worth hacking.

Now, a new fake anti-virus software is making more Mac owners virus-aware. According to news reports, AppleCare has indicated that calls related to this malicious app -- called MAC Defender, MacSecurity, or Mac Protector -- are up dramatically.

'SEO Poisoning Attacks'

A memo that has surfaced on the Web, reportedly an internal communication to Apple support staff, instructs how to handle such calls.

Key points in the memo include "do not confirm or deny that any such software has been installed," "do not attempt to remove or uninstall any malware software," and do not escalate or send the customer to the Apple Retail Store.

According to Mac security firm Intego, MAC Defender targets users of that platform primarily through "SEO poisoning attacks," in which Web sites with malicious code use search optimization tricks to rank at the top of search results. A user who clicks on that search result is sent to a Web site that shows a fake screen and a fake malware scan, after which it tells the user that the computer is infected.

Javascript on the page automatically downloads a compressed ZIP archive file. If the "open 'safe' after downloading" option in Safari is enabled, the file is them unzipped and the user is presented with a Setup Installer.

If the user proceeds with installation, MAC Defender launches. Intego describes the application as "very well designed," with a professional look, a number of different screens, attractive buttons, and correct spelling.

Malware Building Kit

Once installed, MAC Defender indicates that the computer is infected, and then opens Web pages for pornographic sites every few minutes. To counter the "virus," the user is prompted to buy into MAC Defender's "anti-virus" protection service.

After a credit card number has been entered into a license purchasing page, the Web porn and virus warnings stop. But there is no service, and the user has just given the malware authors a credit card number.

Intego recommends not installing the application to begin with, of course, and to uncheck the "open 'safe' files" option in Safari or other browsers.

This kind of fake anti-virus software has, for years, been the bane of many Windows users' existence, but this is the first time it's been designed to target Macs. In fact, reports indicate that early versions of the malware still showed a Windows interface.

Although a rare example, MAC Defender/MacSecurity/Mac Protector is likely to be followed by an upsurge of such attacks. Macs now have an installed base big enough to be worthy of attention by hackers, and security experts have noted that a new Mac-oriented, point-and-click malware building kit is on sale in the criminal underground.

Tell Us What You Think



Posted: 2011-05-28 @ 11:24am PT saved me from a terrible wrecking ball with your "how to instructions"


Posted: 2011-05-22 @ 11:20am PT
thank you so much cjbanks10! i had that virus and just now was able to get rid of it. thank you thank you!


Posted: 2011-05-21 @ 9:12am PT
I got scammed with this too. And I took it off. Here's what to do:

1. Go to the Applications folder. Open "Utilities."

2. Open the "ACTIVITY MONITOR" under the "Utilities" folder. You will see a list of programs running. When you see "MacDefender/"MacScan" or whatever, select it and then click on the red button on the upper left corner of the window that says "QUIT PROCESS." The application will be forced to quit.

3. Now, go back to the Applications folder. Select the fake application software and drag it to the trash. You should be able to do this successfully since you forced the program to quit in the previous step. But keep following the next few steps, because you're not out of the woods--yet.

4. Open System Preferences. Click on "Accounts" and go have a look at the Login Items. You will also see MacDefender listed on there which will open itself at Startup. Click on the minus (-) symbol below the list of the login items, once you have selected the MacDefender app.

5. Clean out the trash. Bye-bye.

6. Go to Safari. Open Preferences. Uncheck the "Open safe items after downloading" box.

7. **RECOMMENDATION** Apple offers a ESET CyberSecurity software for around $43 or so. HOWEVER, I am going to warn you, be on the lookout for that same malware, because I caught it again when cruising around my usual sites and stopped it from downloading on my comp.

Hope this helps..

David L Mahler:

Posted: 2011-05-21 @ 7:05am PT
This is all great, but how do I get the pop-up boxes off my screen. I clicked on this to see what it was but did not enable it. Still, it is putting up pop-up boxes in the upper right hand corner of my screen every few minutes and is showing me a false Firefox page with the titles, "porn", "gayporn", and "viagra". Can you help me?


Posted: 2011-05-21 @ 3:24am PT
How does one get rid of it?


Posted: 2011-05-20 @ 8:45pm PT
Thanks for the warning. I have, alas, installed it, but not paid. I get lots of porn... How can I get rid of the program? When I want to put it in the trash, it refuses, saying that the program is active.

APC has an established a reputation for solid products that virtually pay for themselves upon installation. Who has time to spend worrying about system downtime? APC makes it easy for you to focus on business growth instead of business downtime with reliable data center systems and IT solutions. Learn more here.

 Data Security
1.   Malware Targets Facebook Users
2.   IBM Adds Disaster Recovery to SoftLayer
3.   How To Beat the Heartbleed Bug
4.   Google Proudly Scans Your Gmail
5.   NSC Backs Disclosing Vulnerabilities

Don't Reset Passwords for Heartbleed?
Added caution needed to ensure security.
Average Rating:
Malware Targets Facebook Users
iBanking app spys on communications.
Average Rating:
How To Beat the Heartbleed Bug
Big data analytics could be the key.
Average Rating:

Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
Google's Street View Software Unravels CAPTCHAs
The latest software Google uses for its Street View cars to read street numbers in images for Google Maps works so well that it also solves CAPTCHAs, those puzzles designed to defeat bots.
Canadian Teen Arrested for Heartbleed Hack
One week after the OpenSSL Heartbleed vulnerability was unveiled, Canadian authorities have made the first arrest -- a London, Ontario teenager -- connected to exploiting the security hole.
IBM Offers Security, Disaster Recovery as SoftLayer Service
New disaster recovery and security services for SoftLayer clients are being added by IBM. Big Blue said the new capabilities will speed cloud adoption by alleviating concern over business continuity.

Enterprise Hardware Spotlight
Vaio Fit 11A Battery Danger Forces Recall by Sony
Using a Sony Vaio Fit 11A laptop? It's time to send it back to Sony. In fact, Sony is encouraging people to stop using the laptop after several reports of its Panasonic battery overheating.
Continued Drop in Global PC Shipments Slows
Worldwide shipments of PCs fell during the first three months of the year, but the global slump in PC demand may be easing, with a considerable slowdown from last year's drops.
Google Glass Finds a Home in Medical Education, Practice
Google Glass may find its first markets in verticals in which hands-free access to data is a boon. Medicine is among the most prominent of those, as seen in a number of Glass experiments under way.

Mobile Technology Spotlight
Google Releases Chrome Remote Desktop App for Android
You're out on a sales call, and use your Android mobile device to grab a file you have back at the office on your desktop. That's a bit easier now with Google's Chrome Remote Desktop app for Android.
Amazon 3D Smartphone Pics Leaked
E-commerce giant Amazon is reportedly set to launch a smartphone after years of development. Photos of the phone, which may feature a unique 3D interface, were leaked by tech pub BGR.
Zebra Tech Buys Motorola Enterprise for $3.45B
Weeks after Lenovo bought Motorola Mobility’s assets from Google for $2.91 billion, Zebra Technologies is throwing down $3.45 billion for Motorola’s Enterprise business in an all-cash deal.

NewsFactor Network
Home/Top News | Enterprise I.T. | Cloud Computing | Applications | Hardware | Mobile Tech | Big Data | Communications
World Wide Web | Network Security | Data Storage | Small Business | Microsoft/Windows | Apple/Mac | Linux/Open Source | Personal Tech
Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.