MacDailyNews - Where Mac news comes first

 MacDailyNews Poll

Deal of the Day

5 Day Most Commented

Opinion Archive

Current Headlines

Latest Joy of Tech

  • Latest Joy of Tech!

MacNN

AppleInsider

Macworld UK

TUAW

MacRumors

Yahoo! Finance AAPL

iTunes Top 10 Albums

Mac OS X Downloads

Sat, Nov 21, 2009 - 04:04 PM EST  —  AAPL: 199.92 (-0.59, -0.29%)  |  NASDAQ: 2146.04 (-10.78, -0.5%)

SecureMac releases free Mac OS X trojan removal utility
Friday, January 04, 2008 - 11:01 AM EST

SecureMac has released a free utility called DNSChanger Removal Tool to remove the DNSChanger Trojan Horse, also known as OSX.RSPlug.A and OSX/Puper, which has been found on numerous pornographic websites disguising itself as a video codec. Once downloaded and installed, DNSChanger changes the DNS settings on the computer, redirecting websites entered by the user to malicious sites. If personal information is entered on these malicious websites, it can lead to identity theft.

If the DNSChanger trojan horse is detected, DNSChanger Removal Tool will give you the option to remove it. If the DNSChanger trojan horse is detected and removed, you will need to restart your computer to clear out the bad DNS entries added by the DNSChanger Trojan Horse.

More info and download link (174KB) here.

Bookmark and Share

Always -- Free ground shipping with orders over $50 at the Apple Store.

Reader Feedback: = registered.
Unregistered users: Feedback from multiple usernames are subject to deletion. Off-topic and posts from suspected astroturfers will be removed.

Jan 04, 08 - 11:05 am Comment from: David Andrews

Just curious as to why you would need to restart? Surely using lookupd -flushcahe in 10.4 and previous, or the new dscacheutil -flushcache in Leopard would also remove the bad DNS entries.
Maybe I am missing something . . .

Jan 04, 08 - 11:13 am Comment from: granny

Because my granny totally knows how to open up a terminal and enter in those commands...

Jan 04, 08 - 11:14 am Comment from: shen

cool.

now we just need some trojans, and we are all set.

"hey chemist, i am looking for a pack of trojans!"

"damn, just ran out!"

Jan 04, 08 - 11:15 am Comment from: Question

Who is to say that this tool will not do more harm than good?

Think Before You Click applies here as well. People shouldn't install stuff from untrusted sites.

Jan 04, 08 - 11:16 am Comment from: shen

"Because my granny totally knows how to open up a terminal and enter in those commands..."

"the DNSChanger Trojan Horse, also known as OSX.RSPlug.A and OSX/Puper, which has been found on numerous pornographic websites "

what has granny been doing on her Mac?!?

Jan 04, 08 - 11:23 am Comment from: chum

How do you clear out the console? It lists all the websites you've been to, but clearing them through Safari doesn't affect the console.

Jan 04, 08 - 11:26 am Comment from: TowerTone

well, as I remember, removing a Trojan CAN be a sticky situation....

Jan 04, 08 - 11:34 am Comment from: Ignore This

According to MDN, repeatedly (that means over and over and over) no trojans or other baddies can get into our Macs.

So, ignore this - it's just more FUD or... hold your breath here... it might be an invader disguised as a protector.

Oooops, slipped again. Shut my mouth!

Jan 04, 08 - 11:35 am Comment from: Cubert

I hope this Trojan doesn't break my Mac. I guess it all depends on how deeply it penetrates.

wink

Jan 04, 08 - 11:52 am Comment from: GmanMac

@ignore this.

Well that's 1 (maybe) out of what, 150k?

You feel better? I know I do...

Jan 04, 08 - 11:52 am Comment from: w8nc

I downloaded it but I down see the circular impression.

I'm w8n n cn

Jan 04, 08 - 11:55 am Comment from: ooops

down should have been
"don't"

oh crap I can't even type a joke.

w8nc

Jan 04, 08 - 12:13 pm Comment from: smackman

@shen

Great quote. Love that movie.

Jan 04, 08 - 12:20 pm Comment from: @Ignore This

What kind of fool believes that saying the Mac is much safer than Windows means that it is 100% safe?

Jan 04, 08 - 12:23 pm Comment from: Rip Van Winkle

@@Ignore This

"...what a fool believes he sees
No wise man has the power to reason away..."
-The Doobie Bros.

Jan 04, 08 - 12:30 pm Comment from: scanned my machine

no trojan found

how can this be I surfed for porn all day all night
no firewall
no password
all file sharing on

still nothing
damn

I guess if I want all the virus fun I need windows!!!!!!!!!!!!!

Jan 04, 08 - 01:11 pm Comment from: Marcio

I don't suck cocks. I am cool and I've been in a soap opera. Yeah!!

Jan 04, 08 - 01:11 pm Comment from: Beryllium

I find it amusing that you can get this malware from pornographic web sites. It just shows that you cannot always depend on a trojan. wink

Jan 04, 08 - 01:47 pm Comment from: Hot Carl

I've been surfing for hardcore Russian tranny/midget porn for a week straight and still no trojans, darnit...

:(

Jan 04, 08 - 02:07 pm Comment from: qka

Just curious as to why you would need to restart? Surely using lookupd -flushcahe in 10.4 and previous, or the new dscacheutil -flushcache in Leopard would also remove the bad DNS entries.
Maybe I am missing something . . .


Just an educated guess, but it seems likely that this Trojan modifies your private/etc/hosts file. If you modify your private/etc/hosts file, you need to at least logout and log back in for the changes to take effect, although restarting is as comprehensive, and easier to explain to the average users.

I also read that this Trojan installs some cron jobs to reinfect you if you remove some of the other parts of the infection.

Do the commands you mention do this automatically, or do they have to be explicitly invoked? Unix command line is not for the average Mac user. After all, if we wanted to do that, we would be running Linux! smile

/etc/hosts can be modified by users. Among the reasons that you might do this is to block annoying ad and spyware sites. A good source for more info is http://www.mvps.org/winhelp2002/ Yeah, it's Windows oriented, but it does sure block annoying ads on my Mac.

Jan 04, 08 - 02:16 pm Comment from: alansky

It seems highly unlikely that anyone dumb enough to install an unknown program/plug-in would ever hear about this uninstaller, much less download and run it. You really do have to be either dumb as a post or seriously senile to install something like this "
accidentally."

Jan 04, 08 - 02:44 pm Comment from: ../.

Ignore This: According to MDN, repeatedly (that means over and over and over) no trojans or other baddies can get into our Macs.

No one who understands computers ever claims that Trojan horses are impossible for Mac OS X. Back up you claim, show one article on MDN saying that trojans can't be installed on the Mac. By it's very nature, trojans depends on the users for installation. There is no bullet proof solutions yet for user stupidity or negligence.

Try not to argue using a strawman argument. It only makes you look stupid.

Jan 04, 08 - 03:04 pm Comment from: Brau

This trojan is not limited to porn sites! The recent Safari upgrade already showed its worth for me when a site I visited (global warming news) tried to change my DNS server. Safari warned me and asked me if I wanted to continue.

Jan 04, 08 - 03:28 pm Comment from: Lilochris

Just watch Less Porno & U'll be fine.

Jan 04, 08 - 03:37 pm Comment from: Brau

Look up Lilochris - This trojan is not limited to porn sites!

Jan 04, 08 - 06:00 pm Comment from: LorD1776

"Look up Lilochris - This trojan is not limited to porn sites!"

Yes, but Lilochris is.

Jan 04, 08 - 06:05 pm Comment from: LorD1776

"Give it up for politicians who know how to articulate, give a speech and inspire a crowd. Whatever their or party might be."

Geez Freddy, apparently you sure aren't one of them.

Jan 04, 08 - 06:24 pm Comment from: SecureS3X

Trojans is good but I prefer Beyond-Seven.

Jan 04, 08 - 11:09 pm Comment from: KingMel

Apparently Ignore This has also ignored MDN's frequent warnings not to install/authorize the installation of software unless you trust the source of that software. No computer/OS can protect itself from the ineptitude of a clueless user with admin privileges.

Ignore This --- Think Before You Post ®

Jan 05, 08 - 08:41 am Comment from: Old Mac Man Turned Windows User

Been using Mac's for years, always been near 100% secure.

Now there are over 200 vunerabilities last year, one STILL hasn't been fixed, a exploit here and there, a trojan as well.

I might as well stick with my new Windows machine, at least I know it's insecure and that's that.

Instead of flip flopping back and forth with Mac's and Mac OS X "Is it secure? is it not secure?" and having to put up with a rather LIMITED HARDWARE CHOICE.

Been using Windows for about a two weeks now, it's really not bad at all.

It's the quality of software that makes the difference, I use Safari and iTunes on Windows, Open Office/NeoOfficeJ on both machines to get files across.

Windows XP IS NOT ALL THAT BAD.

If Mac OS X is insecure, then what difference does it make with Windows? They both do the job you need it to do.

One is just tied to overpriced hardware and a bunch of cultists.

Beleive me, I know because I was one.

If Apple didn't come out with glossy only mid-range machines, I wouldn't have switched to Windows.

Jan 05, 08 - 09:27 am Comment from: LorD1776

"Beleive me, I know because I was one."

You were and are still ONE. But you were never a Mac user.

Jan 05, 08 - 02:42 pm Comment from: David Lee Andrews

To all the morons who cried about not being able to enter simple commands in the command line. I was not suggesting you all open terminal yourself, and get all freaked out and scared. The trojan remover could have done this for you.
I think you should all be over on the Windows platform with the rest of the fools...

Jan 06, 08 - 10:28 am Comment from: Drunk Cheney

A Trojan removal utility - - - What's her name?

Reader feedback page 1 of 1 pages:

Always -- Free ground shipping with orders over $50 at the Apple Store.

Add Your Feedback:

Register or Login

Name:

Email: (optional)

Emoticons | Allowed HTML Tags

Remember my info   Notify me of follow-up comments?

Please enter the "MDN Magic Word" you see in the image below: