Home Malware Programs Mac Malware Mac Shield

Mac Shield

Posted: June 2, 2011

Mac Shield is a clone of other rogue security programs that attack Mac operating system-based computers. Like many other threats, Mac Shield will pretend to detect infections on your computer, while claiming that the purchase of a registration key is required to delete the detected problems. Along with this basic scam, Mac Shield may hijack your web browser to redirect you to adult websites or send outbound information through your firewall without your consent. Since Mac Shield can't be removed through normal methods, it's strongly suggested that you use a Mac-compatible anti-malware program to delete Mac Shield.

Tracing the Hidden Lineage of Mac Shield

Mac Shield is an updated version of a line of Mac-specific threats that began with entities like MAC Defender and progressed through updated clones like Mac Protector and Mac Security. Since Mac Shield is a recent threat from what is itself a recent group of rogue security programs, you should keep your security software completely updated to have the best chance of deflecting any Mac Shield attacks.

Most rogue security programs in the Mac Shield subgroup are distributed by websites that exploit Search Engine Optimization keywords, to rank themselves highly in search engine results. These websites will tell any visiting computer that their system is infected, before installing Mac Shield or another rogue security program. Avoid trusting any unfamiliar system scanner or any scanner results that you can't verify with the help of independent and high-quality sources.

The Virtual Knife Hidden Behind Mac Shield

After infecting your computer, Mac Shield will join your Login Items and run itself without your permission every time your computer starts. Mac Shield may pretend to scan your computer and find fake infections, or create fake Growl-based warnings like the ones below:

Virus Found
Infected file detected:
Virus: Worm
File: Software Update

Virus Found
Infected file detected:
Virus: Dialer
File: Safari

Unregistered Copy
Sorry, the copy of your program is unregistered. Register to have an ability to cleanup your system.

Virus Found
Infected file detected:
Virus: Worm
File: clri

The system is infected
Your system is infected. It's highly recommended to cleanup your system to protect critical information like credit card numbers, etc.

Other challenges that are associated with Mac Shield infections include browser hijacks that force you to visit pornographic websites. To put an end to Mac Shield problems and clean your computer, you should use a Safe Boot. In Mac-based computers, this can be done by holding Shift down while your computer starts up. This will stop Mac Shield from launching and let you use a good anti-virus software to delete Mac Shield.

Don't make any attempts to remove Mac Shield in the same way that you'd remove a malicious program, unless you have no other options at the time. Mac Shield has no Dock icon for easy removal, and may be difficult to delete by manual methods, unless the techniques are accomplished by an expert.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 ./MacShield.app
    2 ./MacShield.app/Contents
    3 ./MacShield.app/Contents/Info.plist
    4 ./MacShield.app/Contents/MacOS
    5 ./MacShield.app/Contents/MacOS/MacShield
    6 ./MacShield.app/Contents/PkgInfo
    7 ./MacShield.app/Contents/Resources
    8 ./MacShield.app/Contents/Resources/About-Back.png
    9 ./MacShield.app/Contents/Resources/About-Mail.png
    10 ./MacShield.app/Contents/Resources/About-Phone32x32.png
    11 ./MacShield.app/Contents/Resources/About-Ticket.png
    12 ./MacShield.app/Contents/Resources/AboutD.nib
    13 ./MacShield.app/Contents/Resources/AboutMBMI.png
    14 ./MacShield.app/Contents/Resources/CC-Back.png
    15 ./MacShield.app/Contents/Resources/CC-BigOptions.png
    16 ./MacShield.app/Contents/Resources/CC-BigOptionsHover.png
    17 ./MacShield.app/Contents/Resources/CC-BigOptionsPressed.png
    18 ./MacShield.app/Contents/Resources/CC-BigScan.png

Additional Information on Mac Shield

  • The following messages's were detected:
    # Message
    1 The system is infected
    Your system is infected. It's highly recommended to cleanup your system to protect critical information like credit card numbers, etc.
    2 Virus Found
    Infected file detected:
    Virus: Malware
    File: SelfTest.dist
    3 Unregistered Copy
    Sorry, the copy of your program is unregistered. Register to have an ability to cleanup your system.
    4 Virus Found
    Infected file detected:
    Virus: Spyware
    File: Terminal
Loading...