The trojan is installed when Apple users install the infected pirated copy of iWork '09, the iWorkServices package is installed as a system-wide startup item, it leaves your Mac OS X operating system wide open to hackers to do whatever they want, and is hard to remove.
This is not a virus—it cannot spread from one Mac to another on its own. It’s also not a remote exploit; the user must download and install a pirated copy of iWork ‘09 to become infected. To check if you’ve been infected, look in /System/Library/StartupItems for an item named iWorkServices. If it exists, you’ve been infected with this Trojan horse.
Once infected, the clean-up process may be quite painful. As the Trojan horse has the ability to install additional components, it’s not sufficient to remove the known pieces. Instead, the safest recovery method starts with a reformat and a clean install of OS X. Because the Trojan may also modify installed applications (this is possible because the Trojan is running as root), programs should be reinstalled from their master discs, not from backups. Finally, the user should copy over their data files from backups.