Mac Malware Bundled with Pirated iWork 09 and Photoshop CS4

by malwarekilla on January 28, 2009

LOL! …OK, I'm sorry…but I hope I stop hearing "the best antivirus is a Mac" talk. OSX is getting pretty popular these days and malware distributors are finally taking notice.

Pirated copies iWork 09 and Photoshop012809 1717 macmalwareb1 Mac Malware Bundled with Pirated iWork 09 and Photoshop CS4 CS4 are being bundled all sorts of malware…from unix rootkits (have fun removing one of those) to rogue mac antivirus (imunizator). iWork 09 and Photoshop CS4 are being distributed via P2P mac networks as well as bit torrent hubs.

EDIT - 6:24 PM - A Rep from PC Tools just informed me that they have an antivirus (anti-malware) solution for Mac called iAntiVirus.

The iAntiVirus™ database has been designed from the ground up to detect and remove Mac specific threats. This enables a high level of protection whilst keeping memory footprint and resource usage at a minimum. The iAntiVirus™ database is not cluttered with signatures for Windows specific threats which your Mac is immune against.

{ 24 comments… read them below or add one }

languy99 January 28, 2009 at 7:34 pm

Me too, I hate people that keep saying MACs are virus proof. I can’t wait until something big comes along and takes them down.

Brad January 28, 2009 at 11:36 pm

Only a matter of time before somebody makes an “iloveyou” scale virus for mac. I hate macs, windows are easier to use for me..

Ping January 29, 2009 at 12:25 am

Same with Brad. Soon hackers will drop the V BOMB on the macs!

f January 29, 2009 at 4:06 am

yeah

finnaly we can prove the
we have macs,we are virus proof forever

wrong
hope they get something like super sierous
and then laph at them

now ubuntu is virus proof, and if you use it, you will NEVER EVER get a virus

and like 3 days lator some ubuntu virus comes alon

evil paraters, this is how iwork and adobe pays you back

iantivurs sounds like some dumb rouge

so unriginal
and mac avs were out for long time

mcaffee, norton, avast had them for long time

AZLAN210396 January 29, 2009 at 6:15 am

It have A bit of false positives.

Quarantine

iAntiVirus™ quarantines all detected infections, allowing you to easily view and restore items in the case of a false positive (for example: when scanning with engine heuristics set to high).

So there is a chance of False positives

burning_chrome January 29, 2009 at 6:09 pm

What’s up with all the OS X hate? I own a MacBook Pro (for job purposes) and I’m fine with the comp as whole. Do I believe that it is nigh-invulnerable from malware or viruses? Heck no. With that being said, do I miss the availability of a DefenseWall or Sandboxie-like program being available for Mac? Absolutely.

Matt: Do you ever work on clients with infected Mac machines? If so, what do you recommend to them in terms of OS X security software?

Johan January 30, 2009 at 12:28 am

F: Maybe it does but haven’t you heard of PCTools before?
That company that have developed threatfire etc.. iAntivirus is NOT a rouge.
Just wanted to clearify that!

It’s just the (i) before antivirus like the (i) mac for example.
They just thought it sounds Appleish or what to say !-)

And yea Symantec,Alwil, and Mcafee have had Av’s available for the Mac for a long time YES. But what i’ve read from people using them is that they may slow your Mac down to a crawl, if you have bad luck.

Burning_chrome: I would recommend Intego’s AV too you, since they are experts on the Mac platform. And it’s ALWAYS Intego that comes up with these new threat reports to the public.
I have never seen Symantec, or Alwil(Avast) for that matter say
“hey we have found a new threat for OS X” NO they add the new threats after that Intego has published the news.

And the other 3 also don’t got all the focus on the Mac, no they provide protect Windows, Mac, etc.. But Intego got all the focus only at the Mac users.

So Intego is the one i recommend for Mac users.
Here is a review of Intego’s AV (VirusBarrier)
http://www.macenstein.com/default/archives/1842 <<<.

BUT if you want a FREE AV for your Mac then iAntivirus is a good chooise as well.

And i can say i’m not a Mac user my self YET, but soon !-)

Ping January 30, 2009 at 3:04 am

@ Johan

iAntivirus is not free. There is a free trial though.
My associates all use clamXav as their free antivirus

Emperor Darius January 30, 2009 at 4:49 am

@Ping:

it’s free, the full version just adds 24/7 support.
clamxav detects only 1 mac threat, all the others are av ones

f January 30, 2009 at 2:08 pm

i have heard of pctools

yes i know its not a rouge

i said
it SOUNDS like a rouge
is clamxAv same as clamav, except for mac?

James Baldwin January 30, 2009 at 3:25 pm

^^
It has a different GUI (I think) but it uses the same definitions and scanning engines.

bobicool January 31, 2009 at 12:17 am

Linux is very safe.

I don’t want to say that it’s flawless but when there is a hole in the systeme, a couple of days later an update fixes that for you and The End!

It’s very complicated, it just works!

ps: if there is realy people freaking rigth now on linux, just downbload clamav (even if it sucks..)

bobicool

matt January 31, 2009 at 12:43 am

Some people seem to think Linux is virus proof – they are incorrect. Let me explain:

Both Mac OS X and the various flavours of Linux are based on UNIX which just by design makes them inherantly more secure than Windows.

Let me be VERY CLEAR when I say this: They are NO viruses for macs – trojans most certainly but the number that are in the wild could be counted on one hand.

For any truly malicious mac malware to run the user would have to authenticate themselves – i.e by typing in their administrator username and password. And if a user is so idiotic that they type their admin username and password at any prompt that asks for it they need serious help anyway…..

matt January 31, 2009 at 12:44 am

Therefore to add on to my comment above Linux would be just as easy to make viruses for as macs but it simply hasn’t been targeted yet.

Emperor Darius January 31, 2009 at 7:09 am

I agree with matt. Macs can only be infected by user ingenuity. If you’re stupid enough to put your admin pass in a crack…
Otherwise, no Mac malware infects automatically.

matt January 31, 2009 at 8:22 am

If you infect your mac it’s 100% your fault – not the system’s. If you are dumb enough to type your admin username and password and give the rogue program godlike access to the system that’s your problem.

I rest my case.

bobicool January 31, 2009 at 1:58 pm

I totally agree with you!

darcjrt February 4, 2009 at 1:20 am

I disagree. Macs and linux PCs and Windows PCs they all get infected because of the user stupidity. Because users owns PCs without even knowing what is in them. The use a PC like crazy people. “I have a pC, I cool”. Dumb-ass!!! If you have windows and you click a link to a rogue or any malware, iexplorer or any browser will ASK YOU if you want to RUN the exe file….DUH!!! NOT!!! I DO NOT KNOW WHAT THE HELL IS THAT!!!

that is my friend, user stupidity.

matt February 4, 2009 at 2:39 am

Actually a Windows user can be infected by simple visiting a website, or opening their CD drive on my computer.

That is what I call a flawed operating system…

Emperor Darius February 4, 2009 at 2:42 pm

@matt:

Yeah, a system that makes you the root by default….that’s crazy.

evgeny May 16, 2009 at 3:39 am

@matt there are mac viruses
and maybe you will see sooner or later mac and UNIX malware

evgeny May 16, 2009 at 3:43 am

@matt AND f
oh wait
download a trail of PC tools’ mac antivirus

Jdbukis May 16, 2009 at 5:58 pm

Well With windows you can run as a standard user and then you cant get infected simply by opening a cd tray or visiting a web browser.
And in Vista you have internet explorer protected mode and UAC you would need to click allow (or enter a password) at least once possibly twice in order to get infected.

matt May 17, 2009 at 3:03 am

@evgeny – A virus by definition is a malicious self replicating program – there are no (by definition) mac os x viruses. Trojans yes, but no viruses.

@jdbukis – 99% of windows users don’t even have UAC on, and those who do probably don’t even read the UAC prompts and just hit continue because they are so annoying

Leave a Comment

Previous post:

Next post: