Symantec’s “Security Response” website lists “OSX.Macarena” as “a proof of concept virus that infects files in the current folder on the compromised computer.”
“Symantec has been predicting for quite a while now that virus authors would increasingly dedicate their attention to the Mac platform and that Macs were becoming a tempting target for hackers. However, a newly discovered Mac OSX virus is hardly the firewall breach that the antivirus software makers have been prophesising,” heise Security reports.
“The distribution of the 528 Byte bug is low; while Symantec does not provide an estimate, somewhere between zero and 49 infections are believed to have been reported. It is also unclear where it came from.”
Full article here.
Symantec’s “Threat Assesment” as follows:
• Wild Level: Low
• Number of Infections: 0 – 49
• Number of Sites: 0 – 2
• Geographical Distribution: Low
• Threat Containment: Easy
• Removal: Easy
• Damage Level: Low
• Modifies Files: Appends itself to files in the current directory on the compromised computer.
• Distribution Level: Low
Symantec’s website states, “When OSX.Macarena is executed, it performs the following actions: Infects other files when they are executed in the current directory, regardless of file name or extension.”
Full article here.
Swa Frantzen writes for The SANS Institute’s Internet Storm Center, “There is again a Proof of Concept Virus for Mac OS X. To be honest the virus is no big deal in itself. But it is yet another warning for a lot of parties involved.”
Full article here.
“Symantec has updated its definition files to remove the virus and repair the files, although it’s unlikely even one Mac OS X system has been affected as of yet,” Nate Mook reports for BetaNews.
“Although such proof-of-concept viruses have appeared in the past, Macs have been spared from actual real world attacks,” Mook writes.
Full article here.
MacDailyNews Note: Symantec’s information is sketchy at best and we’ve been down this road with them before (please see related articles below). We’ll have more info if and when it becomes available. In the meantime, enjoy Los Del Rio’s Macarena via Apple’s iTunes Store.
Related articles:
Symantec researcher: At this time, there are no file-infecting viruses that can infect Mac OS X – July 13, 2006
Symantec warns of new proof-of-concept ‘trojan horse’ for Mac OS X 10.4.6 – June 30, 2006
Mafiasoft launches Windows protection racket – May 31, 2006
Symantec CEO: We think more people ought to buy Apple Macs – May 15, 2006
Mafiasoft: Microsoft to charge $50 per year for security service to protect Windows – February 07, 2006
Why Symantec’s ‘scare tactics’ don’t worry Mac users – September 28, 2005
Motley Fool writer: ‘I’d be surprised if Symantec ever sells a single product to a Mac user again’ – March 24, 2005
Symantec cries wolf with misplaced Mac OS X ‘security’ warning – March 23, 2005
Symantec’s Mac OS X claims dismissed as nonsense, FUD – March 22, 2005
Symantec warns about Mac OS X security threat – March 21, 2005
Gosh I hate Symantec! They suck.
You know, they’re only hope is to get switchers because 99.99999% of Mac users HATE that company.
Who’s with me?!
It’s clear that Symantec wrote the virus.
Typhoon,
With you all the way with Symantec. They can’t drum up the business any other way without going with the FUD. They are sad
Did you look at the threat levels?
ITs no existent
its currently on 0 to 2 computers
that means no one even knows about this but symantic
WTF?
I read through all the articles linked to from the MDN article, and also looked for articles linked to from those stories. No one mentions the delivery method of this virus. Just like any other virus, if you have no way of infecting my machine then I have nothing to fear. Am I supposed to download it? Will someone send it to me as an email attachment? Perhaps I’ll click on a link and it’ll download and begin running? I’m not impressed until you can prove that you can actually get this on someones machine without them doing it on purpose.
I think I have that virus, because I can’t connect my Zune to my belly button!
Proof of Concept?!?
Sounds like “in theory”
This identification of the number of infections as “0-49” is ridiculous. Why not say 0 – 1,300,017? In either case the true stat is probably 0.
Yet another non-story. Like we keep saying, call us when there is an actual, real world threat out in the wild Symantec, OK???
No virus, worm or whatever can infect your computer unless the administrator lets them in. Unlike Windows, the MacOS does not give administrator access to the user.
The user and the administrator can be the same person, but the OS does not know that, nor does it care. This is why seperate passwords are strongly suggested for those that have multiple user accounts on a single computer. Only one of those owners will have administrator access, which is protected by password.
Hmmmm, Yea, I agree but,
Now just watch every other pain in the –butt writer go crazy showing how there has been a 10000 % increase in Mac viruses. Er. 0 to almost 1. LOL :-0
I guess I had better run right out and buy all the anti-virus software I can find. See Macs are only 1,234,567 viruses behind Microsoft. So we had better watch out.
” width=”19″ height=”19″ alt=”grin” style=”border:0;” />
Have a good and virus free (the cold kind
” width=”19″ height=”19″ alt=”grin” style=”border:0;” /> ) weekend.
N.
I’ll believe it when I see it. Symantec has a reputation of being a liar.
How could it a be a proof of concept AND they are keeping a count of infections. Doesn’t make sense.
Screw them. If viruses ever DO become a big problem for the Mac platform, I’m using someone else’s product.
In related news, Symantec’s fire extinguisher division details how to burn down concrete houses with a “proof of concept” gas can and matches. Lawers for the company reject questions concerning conflict of interest…
The smell of fear is odious.
Heard on floor four, “Macs are starting to sell. We need a plan.” They sat around the conference table, heads hanging.
A bubbly young intern popped her luscious head in the door. “Hey guys, Benjamin just got that Mac virus working.” Everyone stood, the mood lifting. An anonymous voice asked, “Can it be ready for the holiday season?”
FUD central.
It is clear that the 2 computers this virus attacks are those of the author himself. The virus probably only can infect with physical access to the computer.
Read the link on their website. It provides absolutely NO helpful details at all. A fifth-grader could write something more helpful. Does it require admin authentication? Is it self-replicating and self-propagating? Symantec calls themselves a security company?!?!?
Yeah, they’re scumbags.
Number of Infections: 0 – 49
All on Symantec machines no doubt!
If it has to execute, doesn’t the user have to be involved in the process? Doesn’t Mac OS X still give that warning about [app name] is about to run for the first time? I could probably write an Applescript app that, when launched and OK’s by the user, does something to the other files in the same directory.
The true nature of a computer virus is that it runs without the user knowing it’s there. Also, a truly threatening Mac OS X virus would have to launch and affect system (root level) files.
Poor Symantec. With Macs gaining popularity, they must try to convince people their bloated resourcehog software needs to hog resources on Macs, too.
BUAHAHAHAHA.
(yawn).
What time is it?
The tech dept. at my work installed Symantec Anti-Virus for Mac on all the Macs here. Anyway, one of buddies showed me a widget that tells you how much of your resources each program eats up. Symantec was using something around the 62% mark! I think the virus would eat up less, IF it’s actually genuine.
Kinda reminds you of those DAILY terrorist threats we sent out from 2001 until after election results in 2004 — and then, NADA! Zip! Gone! Geezus, we’re genius.
BTW, gas prices will skyrocket after Nov. 7 no matter the results. Cuz I said so.
“Number of Infections: 0 – 49”
What the heck does that mean? Why such an exact number? Why not 48, or 50? Where do they pull this info from. Wait, don’t answer that.
I have 0 to 100 millions dollars. I’m rich!
I fail to understand the venom directed at Symantec for merely adding a known proof of concept, file infecting virus (that isn’t in the wild) to their threat encyclopedia. If anything they should be commended for staying vigilant even when their time, resources and attention is drained elsewhere (Windows).
It’s not as if Symantec is shouting about this from the rooftops, ringing up all the newspapers, or pointing a hysterical finger at Mac OS X and saying “See?!?!? We told you so.”
I don’t see any marketing effort here. No pushing of product. It just appears to be a routine discovery that some journalist decided to latch onto in order to generate some cheap traffic.
George Mandell,
The venom is due to Symantec’s past actions regarding so-called “Mac OS X viruses.”
Symantec is going to have to do better than releasing a half baked Mac Virus story late in Friday news cycle. Now all weekend, if the new is slow…”Oh..thereis a virus for the Macs….”
The difference between a Mac Virus and a WIndows virus writer:
Mac Virus writer:
Ph.D. top 10 Computer Science school
Lost all hair from working 80 weeks for 15 years
Married to somebody that works in the same place they do b/c with this schedule…who can date.
Attends Trekkie conventions.
Windoze Virus writer:
Freshman……………………In Highschool
Got first pubic hair last week.
Doesn’t even hang out with girls
Attends trekkie conventions
Just my $0.02
Frankly, for all the crying wolf that Symantec has done, I don’t doubt that they created this virus in their labs so they have something to sell. That way they can say “See, here’s a virus that attacks Mac’s!”
my macintosh had a worm in it. I cut that section out and the rest was delicious.
George Mandell said:
“I don’t see any marketing effort here. No pushing of product. It just appears to be a routine discovery that some journalist decided to latch onto in order to generate some cheap traffic.”
The MacWorld news article quotes the release further:
“It is a warning to get antivirus protection for those Macs, even if the shopkeeper told you you do not need it, even if there are no viruses in the wild today, even if it’s hard to buy it.”
Nope, no marketing effort there.
Macworld article: http://www.macworld.com/news/2006/11/03/macarena/index.php
I agree and wouldn’t be surprised if Symantec had something to do with its creation.
Antivirus software companies oughta be the first suspects when new viruses are discovered, particularly when they can’t reliably identify the source. They have an invested interest in maintaining a need for their product.
There’s no proof yet as to where this particular piece came from, but whoever it was isn’t very ethical. I just hope it wasn’t a security expert because he’d have to stop calling himself an expert and start calling himself a criminal.
And for those other times when so-called security experts purposefully publish proof-of-concept code out on the internet or anywhere else, they oughta be put on the FBI’s most wanted list for purposefully endangering national security. It’s one thing to identify weaknesses, it’s another to shout it out to everybody. What’s the point? Most people can’t do anything with the information, and half of the very few people who can are the people you don’t want taking advantage of the info.
Any so-called security expert that announces details about unresolved security issues to the public is more interested in trying to make a name for themselves than actually helping the public. Funny thing is that hardly anybody cares about their name and most will hate those self-proclaimed security experts for releasing the information to even more criminals before a solution has been found.
It’s the same thing as your so-called friend discovering you didn’t lock your car and not discreetly telling you about it. Instead, on his way to tell you your car is unlocked, he stops halfway and shouts to you “Hey! Your car is unlocked! You might want to lock it to keep your brand new stereo system from getting stolen from your blue Ford Taurus, license plate number GTK738, parked a block down the street! Oh, sorry I didn’t bother to lock it for you! I thought it would be better I get the info to you as fast as possible, hence why I’m shouting this in public instead of taking the time to walk all the way to you! I’m sure you appreciate me doing this! Aren’t I such a wonderful guy telling you your blue Ford Taurus with license plate number GTK738 is unlocked as it sits a block down the street from here with that fantastically expensive stereo system in it, not to mention gifts you bought! Of course I’m a wonderful friend! No need to thank me! I’m just letting you know so you don’t lose your car! Good luck! You’re on your own from here! I hope you can run fast enough buddy! Don’t worry, I gave you a head start by shouting this info to you instead of walking all the way and telling you discreetly! And to make it perfectly clear, I didn’t lock your car for you because I knew time was of the essence! That should help, right?!”
They at Symantec received this mail:
To: Whom it my concern
Subject: Very funny
ATENTION! ATENTION!
You have been infected by the Macarena virus. You have to do the following:
a) Download the file ‘macarena.zip’
b) Double click on the “.zip” file already downloaded to extract the file “macarena.app”
c) When the system asks you, please type in your password
d) Once installed, the macarena application will ruin all your applications running on the installed folder
e) To spread the virus: Please go to Mail application, then create a new message to all your contacts, attaching the macarena.zip (that now is in the recycle bin…er… trash) then click the “send” button
Thank you for your cooperation.
The Redmond team at symantec.
—————-
MW: effect. As in: This will cause no effect…
“that means no one even knows about this but symantic”
Probably because if it’s real, Symantec wrote it
” width=”19″ height=”19″ alt=”smile” style=”border:0;” />
@ rick, that is beautiful, your are probably about right.
“Attends trekkie conventions”
And to release more than a “proof of concept” virus these days you need to add:
– Likes the prospect of being the prettiest young boy in prison
George Mandell said:
“It’s not as if Symantec is shouting about this from the rooftops, ringing up all the newspapers, or pointing a hysterical finger at Mac OS X and saying “See?!?!? We told you so.””
Actually, yes they are shouting it form the rooftops. The internet is a public forum, in case you haven’t noticed. It’s easier to find info than in the library, and you don’t have to tune in at specific times (e.g. 5 P.M. or 10 P.M. in the evening) to hear it. You can find it 24/7 any day of the week on the internet, and the more people write about a topic on the internet, the more easily it can be found.
There’s a responsibility of being sensible about what you shout out on the internet which a lot of people don’t understand. It’s mind boggling some security experts haven’t comprehended that about the internet.
In other news, Christmas is December 25.
Symantec, unable to sell a single copy of the crapware they’re peddling to Mac users, is now stooping to creating the viruses themselves??
Talk about desperation…
“I fail to understand the venom directed at Symantec. . . .”
Because Symantec wrote the damn thing, that’s why.
Throm i second that
And they are shouting it out in that they are trying to justify what they have been saying all along that the mac is vunerable to attack.
ITs a kind of “told you so” article which is BS
Whether Symantec created this or just found it, there is two problems with their report on it:
1. No info is given on real or possible vectors – how might I get this virus?
2. The only removal method (listed by Symantec) is to run their Norton AV for Mac. It has already been documented that this program (NAV for Mac) is: a) A security risk and b) a huge resource hog.
I guess I will take my chances with the virus.
I get the feeling Symantec wrote this virus. Maybe windows virus are created the same way. By Microsoft.
The sad thing is that this will work and get them business even if they did write it themselves (which they may ore may not have). Alot of switchers will be coming to OS X gun shy from being burned on security and they will be buying and installing Anti-viruses because in the world they are coming from it is a given necessity.
MDN word: “brown”
This story smells of shit, of the FUD variety. It would take extra effort to write a virus that is as limited (ie stupid) as described. The OS just doesn’t work that way. I doubt the think even exists. A Blatant Lie.
Just when you thought it was safe to put away those 90’s records….
AY! MACARENA!
Think about this…
At the end of the 1990’s, nearly every drugstore in America bought one of those totally automated fully self contained film developing and print processing machines as a way of providing service & additional revenue for each brick & Mortar store. It was the wave of the future. easy, inexpensive pictures for all…
Then, slowly but surely, the digital camera caught on. people could easily take photos, edit & decide whether to keep, discard or print the image. the printer companies began making newer & better models of home printers to assist amateur photogs print their masterpieces.
In less than 10 years, the entire photography industry has been turned upside down, with professional photographers using digital cameras as their main gear and even disposable film cameras cost more than cheap digicams.
Those behemoths resting quietly inside your local pharmacy know the lesson of premature obsolesence all too well.
Let’s hope that Symantec will also follow the same road…
If some of you have proof that Symantec wrote this proof of concept file infecting virus, then you should contact the Federal Trade Commission to complain. Short of that, some of you are suffering from conspiracy laden bunker mentality.
Working with some well known and extremely large corporate clients, I know of no security vulnerabilities in Symantec’s security software for Mac OS X (Symantec AntiVirus for Macintosh 10), or that it is a “huge resource hog.” Concrete proof otherwise is always appreciated.
George Mandell –
http://www.zdnet.com.au/news/security/soa/Norton_Anti_Virus_makes_Mac_OS_X_less_secure_/0,130061744,139229157,00.htm
http://secunia.com/advisories/18131/
http://www.theregister.co.uk/2005/05/10/symantec_mac_false_alarm/
They have patched it, but its a moot point because Mac OS X users don’t need it – if they do need AV software, the open source Clam AV is a better alternative IMO.
dogfriend:
Why rely on sketchy and poorly written articles?
A potential “vulnerability” dating back to December 2005 and specific to RAR compressed files? On Mac OS X it resolved automatically by Symantec through updated virus definitions. (And why scan compressed files in the first place?) It was a potential vulnerability never demonstrated in Symantec’s Mac OS X software (consumer or enterprise).
If Mac OS X has had security vulnerabilities which Apple provided patches for, then is it valid to say that “it has been documented that Mac OS X is a security risk”? Of course not.
While you may be able to argue (badly) that Mac OS X consumer don’t need any security software: Governmental, education, corporate and enterprise Mac OS X users do need and in most cases are required (by policy or law) to have security software, regardless of platform.
ClamAV is a nice (and free) alternative in some situations and scenarios. In fact, I have a busy mail gateway that uses ClamAV for preliminary scanning. However, it can’t compare to commercial offerings in a large number of ways regardless of platform.
And your concrete proof that Symantec’s Mac OS X security offerings are “huge resource” hogs?
Gosh, George, I’m not really sure if you’re playing devil’s advocate or astroturfing for Symantec.
I can’t go back and edit my eariler post, so I’ll restate it:
It has already been documented that this program (NAV for Mac) might be : a) A security risk and has been reported by many other users to be b) a huge resource hog.
Also, refer back to the very first comment in this thread by typhoon:
“Gosh I hate Symantec! They suck.
You know, they’re only hope is to get switchers because 99.99999% of Mac users HATE that company.
Who’s with me?!”
I’m with the 99.99999% on this topic. Why? Because they have been crying wolf for a couple of years now. Someday they will be right, but no one will be listening.
I love this site. It’s probably the best source for Mac news ever since MacMinute’s founder/editor abandoned MacMinute…
I’m a born and raised Mac fanatic – but the blatant bias and blind opposition to anything negative (no matter how true or untrue it may be) is just so repulsive. It gives Mac users a bad name. The editorials on this site following the articles as well as the user comments completely live up to the negative stereotype of Mac users being blind fanboys/girls who think Apple can do no wrong and that anyone who says anything negative about Apple must be a an idiot.
I’ve been wanting to say this for a while, and it was this article that really irked me to the point of saying something.
If there is a threat to the platform, wouldn’t it be more wise to learn about it and how to fix any potential threat instead of shitting all over the messenger? If my Mac is vulnerable, I want to know about it.
Comments and editorials like the one at the end of this article are the reason why Mac users aren’t taken seriously, and I regret that.
Yes, it would be good to find out about any threat to the platform.
The problem is that if you read the report by Symantec, there is no useful information about exactly what the virus does, how the virus might get onto any user’s machine or how it can be contained (except for the recommendation to run Symantec (Norton) AV).
Symantec has no credibility with Mac users because their warnings appear to be self-serving. And they have done this before. Several times.
Symantec, McAfee et al have been parasitizing Microsoft for decades. Now Microsoft wants to regain control over Window’s security problem and prohibit third-party software accessing the Windows OS. Additionally, Microsoft is determined to reduce if not reverse the prevalence of pirated copies of Windows. If Microsoft is successful, Microsoft will dramatically reduce the number of rogue PCs at risk, further reducing the potential profits for Symantec, McAfee et al. Symantec, McAfee et al need to drum up new business and FUD is the only marketing tool they know or trust.
This is an example of to much free market, just bring up a negative idea to make profit on fighting that idea ! Like an armes race: Syndicates.. do love it.
Symantec and Norton have built businesses on the back of the failure of Microsoft to build decent software.
Good luck to them in that endeavour.
What I loathe them for is their efforts to create the perception that OSX is just another Windows. It is not and never likely to be. So they can keep their grubby, parasitic business on the dark side and leave us to spend our money on better things…
You’re defending the indefensible.
Symantec’s goodwill exists only in the mind of the computer neophyte who is ignorant of its history — the damage it has caused to computers, and from there to businesses and the files on thousands of home machines. For you to deny this is like denying 2+2=4, and to demand proof that 2+2=4 is absurd. No one has to prove the world is round.
Symantec fled the Mac platform, except for its anti-virus load of horse dump — after it royally screwed up with a utilities program that was so damaging Symantec wouldn’t fix it. Mac users didn’t abandon Symantec; Symantec abandoned Mac users after years of charging more for less and less. (Does your memory extend back to OS 9, 8 and 7?)
Now it’s in real trouble because Windows users hate it, too. Even Microsoft wants it to keep its incompetent, grasping fingers off its code. Yay Microsoft.
Symantec’s history is replete with FUD and misinformation, so it’s no stretch for people who have had more than enough experience with it to suspect it writes viruses to flog its flawed product. Symantec could discover a cure for cancer, and no one would believe it.
I believe I had an ACTUAL VIRUS on my Mac! I don’t think it was that Macarena thing though. To get rid of the virus I gently cleaned the keyboard and mouse with at paper towel and some Windex. I’m feeling much better now and I hope to prevent any further virus attacks by asking the rest of my family members to was their hands before using the Mac.
I hope this helps anyone who fears getting viruses on their Mac.
Thank You
P.S. I don’t think anti-bacterial Kleenex would help. Bacteria is different from viruses. I’ve heard that Spy-Ware is also different from viruses too… but I wouldn’t know.
@ George Mandell:
I agree with the poster who wrote, “You’re defending the indefensible.”
Back when NUM was published by Peter Norton and not by Symantec, it was a good product. I used NUM in the 80s on Mac OS 6 and 7. But in the early OS 9 era, NUM 3.x began corrupting the directory structure of Mac HFS+ volumes and it was a very ugly mess. Many people lost time and data. Symantec did little or nothing to remedy the problem. Most Mac users who have been around that long have a very bitter taste in their mouths with regard to Symantec.
NAV for Mac is a crappy product. If you’ve ever looked at Symantec’s virus dictionary, it will eventually strike you that the product is not scanning your Mac for Mac viruses — it’s scanning for *Windows* viruses! All 72935 of them!
So the question arises, George Mandell: Why should I pay my perfectly good money to Symantec on a Mac program that offers no me no benefit whatsoever and does nothing but waste my valuable CPU cycles scanning for 73000 Windows virii that cannot affect me?
I too suspect that Symantec is trying to cook up Mac virii in their lab in order to create a need for their product. They’ve got to be feeling a bit panicked right now — on the one side, Microsoft is trying to cut off their kernel access and edge them out of the Windows security business. On the other side, you have a tarnished track record on the Mac and a distinct lack of need for your product.
Think about it Mr. Mandell. How can it be that there’s a “proof of concept” virus that affects 0-49 computers in 0-2 sites, has a low geographic spread, low replication in the wild and is easy to remove, but only using NAV? Doesn’t that kinda reek to you?
If George Bush and the Republicans can sell us a war by “manufacturing” WMD in Iraq, then you damned well better believe that Symantec will try to sell Mac users antivirus protection by manufacturing viruses for the Mac. It’s the truth, George.
A correction to my post above.
re: NUM corrupting HFS+ partitions — it was OS 8 when HFS+ was introduced, not OS 9, and the version was NUM 3.5.x.
The problem was that HFS+ was a brand-new disk format. Old disk-repair methods didn’t work with HFS+. NUM version 3.52 and on would recognize HFS+ and refuse to repair it, but NUM 3.51 and earlier didn’t even *recognize* that it was a new disk format and would attempt to repair it, doing irreparable damage.
Since the total installed base of NUM was 3.51 or lower, many many Mac users lost their entire drive contents. Symantec made no effort to notify its users not to run NUM 3.51 or earlier on HFS+ volumes, and they were very slow to come out with a fix.
The bad news spread by first-hand experience and by word-of-mouth that NUM would corrupt your hard drive, not repair it. As a result, Mac users began staying away from Symantec products in droves. This is an attitude that they are only encouraging to this day by spreading FUD about Mac viruses.
My $0.02 worth.
Sorry, I know this is off-topic and long-winded, but…
One last clarification for George Mandell’s benefit as to why Mac users disparage Symantec with such unity.
In early 1998, all new Macs from Apple — G3’s, servers, Powerbooks — were being shipped with Mac OS 8.1, with HFS+ enabled by default. At that time, NUM 3.5 was still on the shelves at retailers and at all the mail-order houses. There was no indication on the packaging that NUM 3.5 would not work with HFS+ and Symantec did nothing to warn its existing user base or new users of the incompatibility.
Thousands of new Mac owners purchased and installed NUM 3.5 on their shiny new Macs, ran it… and discovered that it had completely and irrecoverably trashed their hard disk.
http://www.user-groups.net/UGNetwork/News/9807/norton2.html
Symantec eventually released NUM 3.5.2, which would recognize but not repair HFS+. It was a long time — I mean, months and months — before NUM worked with HFS+. By the time they got a working version out, the damage was done.
MW: “george” — no kidding! How do they DO that??
I just put in a call to NORAD. They have 26 minutes left on the planet….
Symantec [sic] Simiantechs. A bit lower in the evolutionary scale, eh? Like the Seattle Times.
Take very important file. Move to trash. Empty trash and confirm. Your file is gone. Vulnerability now reality.
EOF
“If there is a threat to the platform, wouldn’t it be more wise to learn about it and how to fix any potential threat instead of shitting all over the messenger? If my Mac is vulnerable, I want to know about it”
Your Mac isn’t vulnerable, so quit worrying. But if you want to know about the next virus Symantec cooks up in its “lab,” post your email address and I’ll let you know.
Here is a good article on the current virus warning by Symantec:
http://arstechnica.com/journals/apple.ars/2006/11/4/5858/p1
I have never had a Mac virus going back to 1995. I have never known anyone who had a virus on a Mac.
I do use ClamXAV. Once I did find a virus on my Powerbook. It was a Windows virus that was in the virtual disc used for Virtual PC. I erased it and reinstalled Virtual PC.
Another lab built virus from an antivirus company. This is starting to get interesting. I think the real story here is are the anitirus companies actually creating viruses to make more money on there antivirus software?
And here again on the Mac side it is only a concept which hasn’t afflicted any real user on a Mac and like the others probably never will.
What’s to defend?
I’m glad Symantec got out of the utilities market and instead focused on security and backup. I never used Symantec’s utilities because there were (and continue to be) so many other companies that produced far superior products (like DiskWarrior at the time).
It’s like staying mad at Apple for dropping the Newton so they could focus on their “core competencies.” I don’t agree with Apple’s move, but it’s water under the bridge, and Apple is a completely different company 7 years later.
It appears that Symantec added information to their malware encyclopedia as soon as they had some information, instead of the information they may have wanted. Since Macarena is not “in the wild” I’m not sure how important it is to study it further or develop detailed removal instructions.
A security researcher at Symantec, Peter Ferrie, wrote on the 2nd that he would be posting additional information:
http://www.symantec.com/enterprise/security_response/weblog/2006/11/do_the_macarena.html
Did Symantec write this PoC? If anyone has evidence to support this claim, then by all means post it here and be sure to contact the Federal Trade Commision (FTC) so they can investigate.
If such evidence exists, I’ll be sure to stop recommending Symantec to my corporate and enterprise clients and instead move to Sophos, Intego or some other company for Mac OS X security.