New variant of RSPlug trojan making the rounds

Our friends at Intego sent out an alert this morning, warning users about a new variant of the RSPlug trojan horse, found on several adult websites. The risk to users is classified as "medium."
RSPlug trojans, themselves a form of DNSChanger, change local DNS settings to redirect to phishing sites for banks, PayPal, and eBay. All these trojans must be downloaded at the user's request, and an administrator password has to be supplied.
When visiting certain sites, the user is alerted that there is a "Video ActiveX Object Error" and is told that their "Browser cannot play this video file." The alert instructs the user to download the "missing Video ActiveX Object." If the user clicks OK, a disk image called "cleanlive.dmg" downloads (which may change in the future). Depending on the user's browser settings, this disk image may mount and installation may automatically start.
Intego VirusBarrier X5 users are, as you might imagine, already protected. Updating your virus definitions today will improve detection.
And, as always, be careful where you put your mouse online.
Share
Categories
Our friends at Intego sent out an alert this morning, warning users about a new variant of the RSPlug trojan horse, found on several adult...
Add a Comment
Just wondering: I use OpenDNS on my network. Would the DNS switcheroo that the Trojan attempts still work?
November 19 2008 at 12:56 PM Report abuse Permalink rate up rate down ReplyBIG QUESTION: What is installed???
Wouldn't it be better to explain where and what this "trojan" is??? That would make it easier to check if your system is infected.
Unless TUAW wants to sell Anti-Virus Software for Intego. ; )
All the more reason to actually read (and comprehend) those pop-up and alert boxes before blindly clicking OK and typing in your password.
November 18 2008 at 6:09 PM Report abuse Permalink rate up rate down Replydarwinian, anuller is french for cancel, so i'm guessing the person who took the screenshot is french ;)
i work for an apple reseller in australia, and we sell intego products. almost nobody buys them (although the paranoid ones still do) after i explain to them how the admin password works: if your computer asks you for a password, it's modifying how the computer works. if you're not a) installing software, or b) unlocking a system preference pane, cancel immediately, cos something fishy is going on
in other news, i can't spell annuler correctly.
November 18 2008 at 4:14 PM Report abuse Permalink rate up rate down ReplyI'm happy with Apple's security overall but having "Open 'safe' files after downloading" checked by default in Safari is just dumb, dumb, dumb. They even put the word "safe" in quotes--they KNOW there's no such thing as an always-safe filetype!
November 18 2008 at 3:40 PM Report abuse Permalink rate up rate down ReplyOK, so what's the URL? I want to know what happens if you click Annuler. :)
November 18 2008 at 3:32 PM Report abuse Permalink rate up rate down ReplyWell, isn't Intego themselves just producing these "viruses" ? Or at least paying someone to make them so they can sell more of their products. Just a thought.
November 18 2008 at 3:30 PM Report abuse Permalink rate up rate down ReplyWait.... you guys have anti virus for OSX?
November 18 2008 at 3:19 PM Report abuse Permalink rate up rate down ReplyHere comes a fresh barrage of Stockholm Syndrome victims citing this as "evidence" that OS X is "just as insecure" as Windows. If my eyes were rolling any harder they'd pop out of their sockets.
November 18 2008 at 1:57 PM Report abuse Permalink rate up rate down ReplyWhich version of OS X and which version of Windows?
November 18 2008 at 1:59 PM Report abuse Permalink rate up rate down ReplyIntego? Let me know when someone reputable reports this.
November 18 2008 at 1:42 PM Report abuse Permalink rate up rate down ReplyHot Apps on TUAW
Deals of the Day
more deals- Altec Lansing Octiv Duo iDock for $48 + free shipping
- Used Apple iMac 17" Core Duo 1.83GHz for $430 + $28 s&h
- Lounge Deluxe Stand for iPhone / iPod touch for $28 + $8 s&h
- Brookstone Surround-Sound Earbuds for $14 + $7 s&h
- Refurbished Skullcandy Tokidoki Smokin' Buds Mic'd Headset for $5 + $2 s&h
- Stitchway Backup Battery for iPod / iPhone for $5 + free shipping
Software Updates
more updates- EFI Firmware Update brings Lion Internet Recovery to 2010-model Macs
- OS X Lion 10.7.3 released with Safari 5.1.3, Wi-Fi bug fix
- Aperture updated to 3.2.2, addresses Photo Stream issue
- Apple updates Keynote to address Lion issues
- Google Search app gets new look on iPad
- Apple releases Apple TV Software Update 4.4.3



23 Comments