Manually remove the newly found OSX/OpinionSpy spyware

Jun 03, '10 07:30:00AM

Contributed by: MacUser06

[crarko adds: OK, there are some serious questions raised about the procedure described below. I suggest waiting for further corroboration before trusting it.]

Here is some background on the recent announcement about a piece of malware which has been found to affect Macs. The spyware in question is called OSX/OpinionSpy and it’s a new variant of Windows spyware that has existed since 2008.

This link (to The Guardian) offers a manual method to remove the spyware which was installed with the screen savers from 7art, or other infected applications which may have been installed.

To see if you're affected, run Activity Monitor (in /Applications/Utilities) and set it to show All Processes in the dropdown menu. Look for a process called 'PremierOpinion' which will be owned by root. If it's there, you've been affected.

To summarize the removal procedure:

The submitter expresses thanks to Paul Mortgaat on the X4U mailing list for pointing out this tip.

[crarko adds: Thankfully, I haven't tested this one. I've removed one step in this procedure until it can be verified as not making the problem worse. And take a look at the procedure mentioned in this comment as a more comprehensive operation.]

Comments (22)


Mac OS X Hints
http://hints.macworld.com/article.php?story=20100603055412831