A Mac first - botnet is active
From MacWorld U.K.:
"The installer contains two files called OSX.Trojan.iServicesA and OSX.Trojan.iServicesB. These are installed alongside the full software package."Security experts Symantec caution that the iServices botnet code is structured to be extremely flexible, which could result in variations of the Trojan surfacing in the next couple of months. Symptoms users should be aware of begin with excessive CPU usage on their Macs (a result of instigating a denial-of-services attack on Web sites).
This malicious software has the capability to produce peer-to-peer communication, remote start-ups, and encryption, said researchers Mario Ballano Barcena and Alfredo Pesoli.
A botnet is a group of computers unknowingly linked together and remotely administered to perform specific tasks. Most commonly, they send out e-mail spam and collect and report personal information.
Be protected
Although it is extremely unlikely that most users have an infected computer--currently the only way to get the Trojan is by illegally downloading iWork '09 or Photoshop CS4, typically from peer-to-peer Web sites, installing it, and entering your administrator password--there are a few ways to check your system.
1. Most antivirus software has been updated to block the iServices botnet. Companies such as SecureMac offer removal tools specifically designed to block iServices.
2. You may be able to neutralize the activity of the Trojan by deleting these folders:1. "System/Library/StartupItems/DivX"3. The most effective way of staying safe is by not subjecting your Mac to even the possibility of being infected by malicious software--most abundantly distributed in pirated software packages, so don't download pirated software.
2. "System/Library/StartupItems/iWorkServices"
Resources
Read the MacWorld U.K. article describing the activation of the iServices botnet.
Click here to download and install iServices Trojan Removal tool.
(Note: this will begin an immediate download from MacScan.)
Experiencing problems? Have feedback? Let us know!
Resources

Some Mac user think iWork is free, like in beer.
Like in some free beer, there could be "date rape" drug or something worst in it so be careful with it.
I think 20,000 people could be right but only the bot master would know.
I keep seeing this phrase - "free like in beer". I haven't seen any free beer - or viruses or trojans!
This is the other half of a phrase used by the open-source software movement when when describing the "free" aspect of open-source software (free as in free speech, not as in free beer...)
A more apt phrase for this situation might be TANSTAAFL (you can easily google this one folks).
(Probably not, but one can always hope.)
Pirates got what they deserved, and "suffering"from 10,000 or 100,000 'puters doing a DOS attack is less than a bite from a dust mite.
SELL MORE ANTI-VIRUS APPS!
See, that's the meme that's being planted.
http://voices.washingtonpost.com/securityfix/2006/03/when_macs_attack.html
As the article states:
"The botnet Taylor had tracked was created using a known security hole not in Linux or OS X, but in something that runs on top of the operating system. This is PHP, a development programming language built specifically for Web sites."
It was not an OS-based botnet for Linux or Mac OS X. This botnet was OS-based. Hence, the first.
Whose side are Symantec et al on by facilitating protection against such infections or making removal/recovery easy? A no-brainer - their sales figures will give the answer.
---
Andreas
G5 2.1GHz ? OS 10.5.6 ? OS 10.4.10 for Classic & Applescript
So I paid a lot of money for the LEGAL version of Adobe CS3 Master Collection. It was for my daughter's work. But I cannot use it on my computer because activating this expensive suite with the registered owner numbers would prevent it from being used on my daughter's computer. I can understand, therefore, why someone might download an illegal copy of any of these apps.
That pro software is expensive... but since you bought it for your daughter's work, maybe she can repay you with some of the money she makes on your investment in her. Then you don't have to steal.
- by Cromdubh April 21, 2009 6:33 AM PDT
- What worries me is, with this botnet out and about,"In the wild?", whether being able to say all my software is legit, is sufficient protection against it and it's inevitable clones?
- Like this Reply to this comment
-
(12 Comments)