Apple Disclosure for Malware outbreak...

How to avoid or remove Mac Defender malware

  • Last Modified: May 24, 2011
  • Article: HT4650

    Summary

    A recent phishing scam has targeted Mac users by redirecting them from legitimate websites to fake websites which tell them that their computer is infected with a virus. The user is then offered Mac Defender "anti-virus" software to solve the issue. 

    This “anti-virus” software is malware (i.e. malicious software).  Its ultimate goal is to get the user's credit card information which may be used for fraudulent purposes. 

    The most common names for this malware are MacDefender, MacProtector and MacSecurity.  

    In the coming days, Apple will deliver a Mac OS X software update that will automatically find and remove Mac Defender malware and its known variants.  The update will also help protect users by providing an explicit warning if they download this malware.  

    In the meantime, the Resolution section below provides step-by-step instructions on how to avoid or manually remove this malware.

    Products Affected

    Mac OS X 10.4, Mac OS X 10.6, Mac OS X 10.5

    Resolution

    How to avoid installing this malware

    If any notifications about viruses or security software appear, quit Safari or any other browser that you are using. If a normal attempt at quitting the browser doesn’t work, then Force Quit the browser.

    In some cases, your browser may automatically download and launch the installer for this malicious software.  If this happens, cancel the installation process; do not enter your administrator password.  Delete the installer immediately using the steps below.

    1. Go into the Downloads folder or your preferred download location.
    2. Drag the installer to the Trash. 
    3. Empty the Trash.

    How to remove this malware

    If the malware has been installed, we recommend the following actions:

    • Do not provide your credit card information under any circumstances.
    • Use the Removal Steps below.

    Removal steps

    • Move or close the Scan Window
    • Go to the Utilities folder in the Applications folder and launch Activity Monitor  
    • Choose All Processes from the pop up menu in the upper right corner of the window
    • Under the Process Name column, look for the name of the app and click to select it; common app names include: MacDefender, MacSecurity or MacProtector
    • Click the Quit Process button in the upper left corner of the window and select Quit
    • Quit Activity Monitor application
    • Open the Applications folder
    • Locate the app ex. MacDefender, MacSecurity, MacProtector or other name
    • Drag to Trash, and empty Trash

    Malware also installs a login item in your account in System Preferences. Removal of the login item is not necessary, but you can remove it by following the steps below.

    • Open System Preferences, select Accounts, then Login Items
    • Select the name of the app you removed in the steps above ex. MacDefender, MacSecurity, MacProtector
    • Click the minus button

    Use the steps in the “How to avoid installing this malware” section above to remove the installer from the download location.

    Note: Apple provides security updates for the Mac exclusively through Software Update and the Apple Support Downloads site. User should exercise caution any time they are asked to enter sensitive personal information online.

    Jason Bosket | Source Networks, Inc. | CEO / Apple Consultant |
    c: 847.878.3747 | www.sourcenetworks.com | jason@sourcenetworks.com |

    (download)

    Kerio Connect 7.2 and MS Office 2011 Issues...

    Known limitations with Outlook 2011 and Kerio Connect 7.2.0
    Space
    Solution
    As of version 7.2, Kerio Connect supports Microsoft Outlook 2011 for Mac, using the native Exchange connection. This special access method takes full advantage of the collaboration features available in Outlook 2011. Similar to Outlook for Windows, Outlook 2011 incorporates its features tightly around the capabilities of Microsoft Exchange Server. Some of these capabilities differ slightly when connected to Kerio Connect. This article is designed to point out some of these known behavioral differences, in addition to some known issues with Outlook 2011.

    The following limitations were observed during internal testing of Outlook 2011, however they are not specific to Kerio Connect:

    From address cannot be changed
    The e-mail address used in account configuration identifies the user's profile in Kerio Connect, so it must be the primary e-mail address (the one used for authentication). Otherwise authentication to Kerio Connect will fail. We are currently working on a solution to support modifying the default from address.

    Only scheduled synchronization
    There is nothing like push or notification from server to client like in Microsoft Entourage 2004/2008 via WebDAV. Synchronization is based on periodic checks or by manual "Synchronize Now" on folder/account, it causes delays between receiving of messages on server and availability in Outlook

    Categories in Public Folders
    Outlook 2011 does not ask server for categories for messages in Public folders

    Searching for contacts
    Menu -> Window -> Contacts Search -> [Search All Fields] in [All Folders]
    It appears there is no LDAP query from Outlook 2011

    Empty cache for entire account doesn't work correctly
    It doesn't empty cache, it merges folder structures from both sides, creating duplication of folders

    Delegated accounts show only default folders
    Only default folders (INBOX, Contacts, Calendars, etc.) are available in delegated accounts in Outlook 2011 for Mac. Workaround is copy/move these shared non-default folders to Public Folders, assign rights and subscribe to them as another users

    Public folders
    - They must be subscribed, they will not appear automatically
    - All subscribed folders in Outlook 2011 are in one level, there isn't any folder tree

    Deleted Items contains only mail folders or messages
    Non-mail items and folders deleted in Outlook 2011 are deleted permanently. If Deleted Items contains non-mail items deleted in another client e.g. in Kerio WebMail, they are invisible in Outlook 2011

    Non-mail folders are all in one level (no folder tree)
    If there is some structure (eg. Calendar -> Sub-calendar), it's visible in Outlook 2011 in one level.

    Custom headers editing was removed
    In Entourage 2004 and 2008, it was possible set useful headers like Reply-To, notifications about reading etc.
    This option was removed in Outlook 2011 -http://www.officeformac.com/ms/ProductForums/Outlook/3935

    Deleted Items removes preview pane
    If you set preview pane for Deleted Items, it disappears again after switching between folders

    The following limitations are specific to Kerio Connect:

    Out of Office
    Kerio Connect supports only the basic options for the Outlook 2011 Out of Office Reply. There are additional options for defining exclusions for certain recipients, or a start and end date for processing of the Out of Office reply. These additional options are not supported

    Advanced permissions in Folder Sharing
    Similar to Entourage, Outlook 2011 supports some additional sharing options (e.g creating subfolders, creating items...) which will be mapped to the closest permission available in Kerio Connect (reader, editor, administrator)

    Folder size calculation
    In the properties of a folder, Outlook 2011 can display the size of the message within the storage tab. This dialog will return an error message

    Delegates
    Although it is possible to share any folder type through the 'Sharing Permissions' option, there is a separate delegation dialog in the account properties which is not supported. Users can therefore share folders, however they cannot respond to invitations, or compose an email on behalf of another user

    Message status flags may not be synchronized in some circumstances
    If a message is read, forwarded or replied to from another email client, Outlook 2011 may not reflect this change. In most cases it will be synchronized during the normal schedule, however we are investigating why in some circumstances the message status is not synchronized

     

    CONSULTING • IMPLEMENTATION • SUPPORT
    Source Networks, Inc. is a new kind of consulting company - one based on professionalism and technical expertise delivering comprehensive technical support services and software solutions. Our consultants constitute some of the midwest's most knowledgeable and experienced consultants ready for any: 
    PRE-SALES CONFIGURATION, INSTALLATION, or long-term SUPPORT options.