The University of Massachusetts Amherst
Categories
Security Virus/Malware

Arrrr! Piracy be Dangerous!

Its a trap!
Admiral Ackbar is wary of pirated copies of software.

I was reading my RSS feed for Slashdot and I came across this article. This is a great example for why piracy is dangerous. Mac users who get copies of iWork ’09 from the Internet can get a trojan virus. That’s right! While Mac OS X is generally safe against viruses, most programs require that you type in your username and password to install them. As soon as you do this, you are granting the program administrative access to your system! If the program contains a virus, you are giving it free reign.

It’s important to trust the place that you get your software. Make sure that you download software from the maker’s official website or an authorized mirror. That is to say, if you want to get a program like Firefox, you should go to http://www.mozilla.com or http://www.getfirefox.com — not some random website from Google.

Arrr! Be wary, mateys! Sometimes the booty be trapped! If you believe that you have a virus on your computer, contact OIT Help Services for assistance.

(Neither the Office of Information Technologies nor the University of Massachusetts Amherst condone the piracy of copyrighted material. For more information on copyright infringement, please visit this link.)

Instructions for removing the infected iWork package (from MacRumors):

Solution 1: This is the easiest and safest way for users to remove this Trojan. It is a small utility that has been created by the makers of MacScan AntiVirus software for Mac users. Please note that this is not officially supported by OIT Help Services and we cannot guarantee its effectiveness.

http://macscan.securemac.com/files/iWorkServicesTrojanRemovalTool.dmg

Solution 2:

Note: BE VERY, VERY CAREFUL. Typing in these commands incorrectly can delete large swaths of information from your hard drive. Use the following solution at your own risk. We recommend that you try Solution 1 first!

1) (open Terminal.app)
2) sudo -i (enter password)
3) rm -rf /System/Library/StartupItems/iWorkServices
4) rm -f /private/tmp/.iWorkServices
5) rm -f /usr/bin/iWorkServices
6) rm -rf /Library/Receipts/iWorkServices.pkg
7) killall -9 iWorkServices