Wednesday, October 11, 2017

Malware MacDefender Removal experience

At least the following steps:
  1. Remove the malware browser plug-in (eg: OptiBuy), which will always try to get malware MacDefender/MacSecurity/MacProtector back.
  2. Stop MacDefender process via Activity Monitor, and then remove related programs from applications folder if any.
  3. System Preference ->Accounts->Login Items->remove MacDefender
  4. Remove OptiBuy from /Applications/;/Library/LaunchDaemons;/Library/Application Support; I also checked /System/Library/LaunchDaemons. When a user logs in, a per-user launchd is started, it loads list found in //System/Library/LaunchAgents, /Library/LaunchAgents, and the user's individual Library/LaunchAgents directory.
Based on timestamp, I also removed a suspected .ini file, though I am not sure it is related, however I don't believe Mac OS uses ini file anyway.