We still seem to be having troubles with the so-called “Mac Defender” malware. We aren’t sure how it’s being delivered — I think, but am not certain, it’s being delivered through a trojan-horse advertisement — but the effect is that it redirects your browser to a site hosted by various machines in the Former Soviet Union, so instead of Pajamas Media content you get a page like the one below.

The "Mac Defender" malware page.

Like almost all examples of the rare Mac malware, this requires at least a little cooperation from your end before it will do anything dastardly to your machine. Apple will have a security update out for this soon, they promise. In the mean time, here’s what to do, drawn from the Apple article I linked:

Right now, if you use Safari as your browser, then open Preferences (Cmd-, or Safari/Preferences) and make sure that Open “safe” files after downloading is not checked, as shown below.

That will prevent the malicious page from actually installing anything on your machine.

If you get the malicious page:

The good news is that mostly the malicious page will only try this rarely, and apparently only once on a machine.

Now, what to do if you didn’t do this?  If you were to click “Okay”, then the web site will download a file called “anti-malware.zip”, and if you had the Open “safe” files box checked, then it tries to go ahead and run an installer.

Don’t do it.  Go to your Downloads folder, find the file and drop it in the Trash, them empty the trash.

If you did let it install, don’t for God’s sake give it your credit card information.

Here’s what Apple recommends if you have somehow installed this malware:

How to remove this malware

If the malware has been installed, we recommend the following actions:

Removal steps

Malware also installs a login item in your account in System Preferences. Removal of the login item is not necessary, but you can remove it by following the steps below.