Skip to Content

New variant of RSPlug trojan making the rounds


Our friends at Intego sent out an alert this morning, warning users about a new variant of the RSPlug trojan horse, found on several adult websites. The risk to users is classified as "medium."

RSPlug trojans, themselves a form of DNSChanger, change local DNS settings to redirect to phishing sites for banks, PayPal, and eBay. All these trojans must be downloaded at the user's request, and an administrator password has to be supplied.

When visiting certain sites, the user is alerted that there is a "Video ActiveX Object Error" and is told that their "Browser cannot play this video file." The alert instructs the user to download the "missing Video ActiveX Object." If the user clicks OK, a disk image called "cleanlive.dmg" downloads (which may change in the future). Depending on the user's browser settings, this disk image may mount and installation may automatically start.

Intego VirusBarrier X5 users are, as you might imagine, already protected. Updating your virus definitions today will improve detection.

And, as always, be careful where you put your mouse online.



Categories

Security

Our friends at Intego sent out an alert this morning, warning users about a new variant of the RSPlug trojan horse, found on several adult...
 

Add a Comment

*0 / 3000 Character Maximum

23 Comments

Filter by:
NotAwesome

Just wondering: I use OpenDNS on my network. Would the DNS switcheroo that the Trojan attempts still work?

November 19 2008 at 12:56 PM Report abuse rate up rate down Reply
Tice

BIG QUESTION: What is installed???

Wouldn't it be better to explain where and what this "trojan" is??? That would make it easier to check if your system is infected.

Unless TUAW wants to sell Anti-Virus Software for Intego. ; )

November 19 2008 at 8:40 AM Report abuse rate up rate down Reply
Sir. Poopy Pants

All the more reason to actually read (and comprehend) those pop-up and alert boxes before blindly clicking OK and typing in your password.

November 18 2008 at 6:09 PM Report abuse rate up rate down Reply
Laurence

darwinian, anuller is french for cancel, so i'm guessing the person who took the screenshot is french ;)

i work for an apple reseller in australia, and we sell intego products. almost nobody buys them (although the paranoid ones still do) after i explain to them how the admin password works: if your computer asks you for a password, it's modifying how the computer works. if you're not a) installing software, or b) unlocking a system preference pane, cancel immediately, cos something fishy is going on

November 18 2008 at 4:12 PM Report abuse rate up rate down Reply
1 reply to Laurence's comment
Laurence

in other news, i can't spell annuler correctly.

November 18 2008 at 4:14 PM Report abuse rate up rate down Reply
brian

I'm happy with Apple's security overall but having "Open 'safe' files after downloading" checked by default in Safari is just dumb, dumb, dumb. They even put the word "safe" in quotes--they KNOW there's no such thing as an always-safe filetype!

November 18 2008 at 3:40 PM Report abuse rate up rate down Reply
Rowan

OK, so what's the URL? I want to know what happens if you click Annuler. :)

November 18 2008 at 3:32 PM Report abuse rate up rate down Reply
fannar

Well, isn't Intego themselves just producing these "viruses" ? Or at least paying someone to make them so they can sell more of their products. Just a thought.

November 18 2008 at 3:30 PM Report abuse rate up rate down Reply
manny0

Wait.... you guys have anti virus for OSX?

November 18 2008 at 3:19 PM Report abuse rate up rate down Reply
Shunnabunich

Here comes a fresh barrage of Stockholm Syndrome victims citing this as "evidence" that OS X is "just as insecure" as Windows. If my eyes were rolling any harder they'd pop out of their sockets.

November 18 2008 at 1:57 PM Report abuse rate up rate down Reply
2 replies to Shunnabunich's comment
balls

Which version of OS X and which version of Windows?

November 18 2008 at 1:59 PM Report abuse rate up rate down Reply
Shunnabunich

Exactly.

November 18 2008 at 2:12 PM Report abuse rate up rate down Reply
Simon Arch

Intego? Let me know when someone reputable reports this.

November 18 2008 at 1:42 PM Report abuse rate up rate down Reply
Buy an ad here

Hot Apps on TUAW

Tweets

© 2012 AOL Inc. All Rights Reserved.