• On TechRepublic: Why Android beats iPhone
advertisement
March 31, 2009 8:43 AM PDT

Warning: "Conficker" worm may affect some Mac users

by CNET staff
  • Font size
  • Print
  • 26 comments

There is a new worm out called "Conficker" (also known as "Downadup" and "Kido") that has reportedly infected millions of Windows PCs. It has been detected by various antivirus companies and unfortunately it is suspected to become active tomorrow (April 1st, 2009) so currently there is little known about what it will do.

Fortunately for most Mac users, this worm is Windows-only, so there shouldnt be any problems. However, many Mac owners have windows or windows-compatible environments running on thier systems in the forms of Virtual Machines (Parallels and VMware) as well as direct installations via Bootcamp. In addition, there are several windows emulation environments such as Codeweaver's Crossover which will run windows programs directly on your mac, and may allow the worm to execute.

Given the concern about this threat, we strongly recommend you install and run antivirus software on your windows installations. In addition, while this threat does not yet affect OS X, you may consider running a virus scanning package on your mac as well to prevent spreading the malware to Windows users. Be sure to also fully update your Windows installations, since Microsoft has recently released patches to help tackle this threat.

VirusBarrier (Mac/Win)
Sophos (Mac/Win)
VirusScan (Win)
AVG (Win/Free)
F-Secure (Win)
ESET (Win/Free Trial)
Enigma Software (Win/Free)
Norton (Mac/Win)

More information on this virus can be read at the following locations:

Resources

  • VirusBarrier
  • Sophos
  • VirusScan
  • AVG
  • F-Secure
  • ESET
  • Enigma Software
  • BitDefender
  • Norton
  • Microsoft
  • Wikipedia
  • MacWorld
  • MacSimumNews
  • More from Late-Breakers
  • Recent posts from MacFixIt
    Apple releases Aperture 3.0
    Manage iCal's automatic e-mail generation for invitations
    CNET TV Apple Byte: Apple faces critics
    Weekly Utilities Update: Net Monitor, MiniUsage, TimeMachineEditor, more...
    Odds and Ends: Essential video codec packs for OS X
    Address Book: Unable to add, view contacts
    Persistent 'Faster Browser Search' overtaking Safari's default search
    Quick tip: Faster Time Machine backups
    Add a Comment (Log in or register) Showing 1 of 2 pages (26 Comments)
    by earthsaver March 31, 2009 9:17 AM PDT
    I recommend Avast http://www.avast.com antivirus for Windows?simple and to the point, automated background updates?with the MacLover OS X skin http://www.avast.com/eng/maclover_os_x.html.

    ---
    - Ben

    PBG4 1.25 - Leopard

    Reply to this comment
    by JD_1 March 31, 2009 9:17 AM PDT
    >
    This is a reply to a previous comment by earthsaver


    Agreed!

    I've used it for a few years on my Winbox after ditching the overpriced and bloated Norton product.

    Works very well and updates itself automatically, sometimes more then once a day!
    Reply to this comment
    by frito-bandito March 31, 2009 9:28 AM PDT
    kaspersky... for a pc, the only virus protection you need
    Reply to this comment
    by Rick Auricchio March 31, 2009 10:31 AM PDT
    A Windows environment, even hosted on a Mac system, has always been vulnerable to everything that attacks Windows systems.

    This is not news.
    Reply to this comment
    by tkessler March 31, 2009 10:31 AM PDT
    >
    This is a reply to a previous comment by Rick Auricchio


    What are you talking about? This is definitely news...news enough to be mentioned all over the news channels including 60 minutes, and be mentioned on many websites and even other mac websites. It's a threat that stands out from the rest, and should be considered by everyone.
    Reply to this comment
    by baddawg65 March 31, 2009 10:31 AM PDT
    >>
    This is a reply to a previous comment by tkessler


    Well, news is relative to reader or hearer of the news.
    Yes, Conficker worm news has been out there for several months now but its supposed activation date of April 1, 2009 is the issue here. Also some parts of the world it is already April 1, 2009 so this may already be happening.
    Also people who have virtualization with Microsoft Windows operating system need to make sure their guest Microsoft Windows is updated with current security patches and virus definitions (if anti-virus program is installed) to prevent this worm from possible damage to your system. It is more important that CrossOver or WINE type of virutalization is updated since this method run concurrent with the Macintosh OS so whatever Conficker worm does can have an direct effect on the Macintosh OS also. For example, delete a file on the Windows OS side can delete the file on the Mac OS side.
    Reply to this comment
    by lexicon5_ March 31, 2009 11:58 AM PDT
    If you run Windows in dual boot mode or in a virtual environment and you've shared the Mac OS side with the Win side...your whole world could be upset.
    Not everyone is bright enough that they can separate hardware and software in their brain. We still have people who think turning off the monitor turns off the computer....this after YEARS of using a computer. It's not news to those of us that have been on Macs for more than a couple of years....but there are a LOT of n00bs out there.
    Reply to this comment
    by Rick Auricchio March 31, 2009 11:58 AM PDT
    >
    This is a reply to a previous comment by lexicon5_


    The n00bs aren't reading MacFixit.
    Reply to this comment
    by Gennx30 March 31, 2009 1:26 PM PDT
    IF THIS DOESNT TURN OUT TO BE A Y2K THING (FOR MACS ANYWAY)
    wouldnt it just effect the Windows inside your system-if at all-the worst case scenario
    would be transfer by mail-and is it Universal Binary ;-P
    Reply to this comment
    by Gennx30 March 31, 2009 1:26 PM PDT
    >
    This is a reply to a previous comment by Gennx30


    since we cannot edit-
    I might add that in the 15 years of Mac use reading all the BBs sites and journals-ive heard of ONE mac virus back in-1990?-OS 8 which didnt seem to do any harm
    go to SECUNICAs website ANUAL INDEX of VIRUS- one page of "proof of concept" for Macs, and a whopping 20 pages of Windows viruses that REALLY do damage-nothing theoretical about them


    Use Sorceforges CLAM XV-its free and its not going to slow down your system;

    To show you how safe Macs are-NORTON has to cry "Wolf!" every so often to drum up flat/declining Mac sales-as people realize they dont need the CPU hog;
    I wonder if you CAN infect or REALLY hack into an Apple computer
    Reply to this comment
    by Balsamic_ Vinegar March 31, 2009 1:26 PM PDT
    >>
    This is a reply to a previous comment by Gennx30


    Please read the following unbiased article about the recent Pwn2Own contest. This guy worked for the NSA and is an expert security consultant. No Spin. It's a balanced interview given by a Mac user. No flames intended.

    http://weblogs.baltimoresun.com/business/appleaday/blog/2009/03/more_from_pwn2own_winner_charl.html
    Reply to this comment
    by hh186jor March 31, 2009 1:26 PM PDT
    >>>
    This is a reply to a previous comment by Balsamic_ Vinegar


    Safari could not open the page ?http://weblogs.baltimoresun.com/business/appleaday/blog/2009/03/more_from_pwn2own_winner_charl.html? because the server is not responding.
    Reply to this comment
    by hh186jor March 31, 2009 1:26 PM PDT
    >>>
    This is a reply to a previous comment by Balsamic_ Vinegar


    A truncated URL appears to work http://weblogs.baltimoresun.com/business/appleaday/blog/2009/03/
    Maybe the server was just overloaded.
    Reply to this comment
    by Balsamic_ Vinegar March 31, 2009 1:26 PM PDT
    >>
    This is a reply to a previous comment by Gennx30


    Really wish we could edit here!

    From my last reply I am not indicating that Conficker will pose any problems for Mac users, but I did want to point out that there are security concerns with OS X.
    Reply to this comment
    by joetekk March 31, 2009 2:25 PM PDT
    ClamXav FTW:

    http://www.clamxav.com
    Reply to this comment
    by baddawg65 March 31, 2009 2:25 PM PDT
    >
    This is a reply to a previous comment by joetekk


    I use clamXav already but it doesn't scan inside virtual disk like VMWare or Parallels and it doesn't scan BootCamp Windows partitions which this worm will infect. You still need need to make sure that your Microsoft Windows guest system or BootCamp MS Windows partition is updated and you can use clamav for Windows like clamwin http://www.clamwin.com/ to scan for problems.
    Reply to this comment
    by Balsamic_ Vinegar March 31, 2009 6:42 PM PDT
    MS has had a patch for this out since October of 2008. I am not being sarcastic in any way, shape, or form, but people really need to keep on top of their updates. That's one of the most important things you can do.
    Reply to this comment
    by tkessler March 31, 2009 6:42 PM PDT
    >
    This is a reply to a previous comment by Balsamic_ Vinegar


    For frequently used computers I'd expect this of them, but some people may have virtual machines that they dont use too much, which might not be updated so regularly.
    Reply to this comment
    by Balsamic_ Vinegar March 31, 2009 6:42 PM PDT
    >>
    This is a reply to a previous comment by tkessler


    Good point...
    Reply to this comment
    by calibeep March 31, 2009 9:46 PM PDT
    I had a very clueful tech type recommend Parallels for me because I have no choice but to use a few IE-only websites from time to time. But even they were not worried about malware and thought running in convergence mode would protect me!

    I'm installing Free AVG tonight because I used to use it when I was stuck with a PC :) and I wlll check the Windows updates.

    But I am interested in protecting my Mac in order to not spread malware to friends who use Windows. Some have no choice for their OS for various reasons and I don't want to infect them. Does anyone have any knowledge of what the best Mac antivirus programs are? I don't want to buy something stupid!
    Reply to this comment
    Showing 1 of 2 pages (26 Comments)
    advertisement
    Click Here

    About MacFixIt

    MacFixIt is CNET's troubleshooting resource for all things Mac. The information here helps you navigate the ins-and-outs of Mac ownership with how-tos, troubleshooting information, news, reviews, and more.

    Add this feed to your online news reader