Text Size

Mac OS X trojan removal tool debuts

updated 06:45 pm EST, Thu January 3, 2008

Trojan removal tool

SecureMac has announced a free Trojan Detection Tool dubbed DNSChanger Removal Tool. DNSChanger Removal Tool detects and removes latest spyware targeting Mac OS X: DNSChanger Trojan (also known as OSX.RSPlug.A Trojan Horse). This trojan attacks users attempting to play a fake video file. Affected systems are used to hijack some Web requests that lead users to other phishing sites, or simply display ads for other pornographic websites to generate ad revenue. Phishing attacks may lead users to believe they are surfing to eBay, Paypal, or various banks when in fact they are accessing specially-crafted mockups designed to retrieve usernames and passwords for those sites. Upon attempting to play the video, the victim receives the following message: "Quicktime Player is unable to play movie file. Please click here to download new version of codec."

The user's DNS records are modified, redirecting incoming internet traffic through the attacker's servers, where it can be hijacked and injected with malicious websites and pornographic advertisements. The trojan also installs a watchdog process that ensures the victim's DNS records stay modified on a minute-by-minute basis.

The trojan is rated as a critical risk by Intego, and is known to affect Mac OS X 10.4 Tiger as well as Mac OS X 10.5 Leopard. Intego is testing prior versions of Mac OS X, but believes them to be vulnerable as well.

SecureMac's DNSChanger Removal Tool allows users to check to see if the trojan has been installed on their computer; if it has, the software helps to identify and remove the offending file. After a system reboot, the users' DNS records will be repaired.

 
Previous Comments

Find one?

01/03, 07:15pm reply

Anybody find one? My computer was clean.

maccam

Fresh-Faced Recruit

Joined: Sep 2005

+1

nope..

01/03, 07:22pm reply

mine was clean too ;)

eldarkus

Fresh-Faced Recruit

Joined: Feb 2004

0

nope...

01/03, 07:34pm reply

Me three! I'm clean!

gskibum3

Fresh-Faced Recruit

Joined: Nov 2006

0

No trojans...

01/03, 07:49pm reply

No Trojans so I'll have to use Durex although I did find a horse's head in my bed. Man I need to stop drinking...

Feathers

Forum Regular

Joined: Oct 1999

0

nope..

01/03, 08:03pm reply

Me too, clean!

Guest

Fresh-Faced Recruit

Joined: Nov 1999

0

Nice PR Stunt

01/03, 08:16pm reply

I'm Clean, but then it wants you to visit the store and buy the MacScan.

Cool PR.

MiMiC

Fresh-Faced Recruit

Joined: Jun 2007

0

Testudio...

01/03, 09:20pm reply

As you don't use anti-virus on your Macs, I'll assume you have this trojan. Or is it this week you do use anti-virus, and then next week you'll be back to not using it when the story your commenting on makes it convenient to take that position.

gskibum3

Fresh-Faced Recruit

Joined: Nov 2006

0

What if...

01/03, 09:21pm reply

...the software IS a trojan?

Eriamjh

Addicted to MacNN

Joined: Oct 2001

0

it was a matter of time

01/03, 10:30pm reply

oh man, i miss my PPC days...

24klogos

Forum Regular

Joined: Feb 2006

0

okay

01/03, 11:15pm reply

Is it just me or is the site down?

unhappyending

Fresh-Faced Recruit

Joined: Feb 2007

0

Popular News