<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: New OS X Malcode: Not Just a DNSChanger</title>
	<atom:link href="http://asert.arbornetworks.com/2008/11/new-os-x-malcode-not-just-a-dnschanger/feed/" rel="self" type="application/rss+xml" />
	<link>http://asert.arbornetworks.com/2008/11/new-os-x-malcode-not-just-a-dnschanger/</link>
	<description>A weblog dedicated to educating the community on security threats that matter</description>
	<lastBuildDate>Mon, 08 Mar 2010 22:35:14 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: matt</title>
		<link>http://asert.arbornetworks.com/2008/11/new-os-x-malcode-not-just-a-dnschanger/comment-page-1/#comment-186218</link>
		<dc:creator>matt</dc:creator>
		<pubDate>Fri, 19 Dec 2008 08:47:24 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/?p=527#comment-186218</guid>
		<description>update: i downloaded the DNSChangerRemovalTool

My DNS is back to normal but I still have this Adobe Flash in my cron search.  after reading several articles tonite, it does seem like that that cron is either wrongly accused of wrong doin or indeed is part of the culprit. Anyone know for sure.. and if it is bad? how do i get rid of that?!</description>
		<content:encoded><![CDATA[<p>update: i downloaded the DNSChangerRemovalTool</p>
<p>My DNS is back to normal but I still have this Adobe Flash in my cron search.  after reading several articles tonite, it does seem like that that cron is either wrongly accused of wrong doin or indeed is part of the culprit. Anyone know for sure.. and if it is bad? how do i get rid of that?!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: matt</title>
		<link>http://asert.arbornetworks.com/2008/11/new-os-x-malcode-not-just-a-dnschanger/comment-page-1/#comment-186199</link>
		<dc:creator>matt</dc:creator>
		<pubDate>Fri, 19 Dec 2008 07:17:33 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/?p=527#comment-186199</guid>
		<description>I fell for it  - its definitely this macaccess installer Osxjahlava trojan and now have no idea what to do
(btw - i got this thru trying to download a firefox plugin for craigslist called Clpicview

In trying to fix this situation,  i keep coming across sites that describe it but no resource for fixin and removing it

i also come across sites claiming to be able to fix it if you buy their software

there are other sites that mention an online scan but upon careful readin it looks like its for uploading files to be scanned and screened? which makes sense cause i cant imagine an online service that remote fixes and eliminates this trojan for me.

virus barrier apparently does the trick but the trail version only allows you to detect and not fix it? and i dont want to buy the program because im afraid to use my computer to buy anything nor do i want to wait to tomorrow to fix it!

i dont know who to trust and worse, i dont even know what kind of danger I&#039;m in.

can anyone help me?</description>
		<content:encoded><![CDATA[<p>I fell for it  &#8211; its definitely this macaccess installer Osxjahlava trojan and now have no idea what to do<br />
(btw &#8211; i got this thru trying to download a firefox plugin for craigslist called Clpicview</p>
<p>In trying to fix this situation,  i keep coming across sites that describe it but no resource for fixin and removing it</p>
<p>i also come across sites claiming to be able to fix it if you buy their software</p>
<p>there are other sites that mention an online scan but upon careful readin it looks like its for uploading files to be scanned and screened? which makes sense cause i cant imagine an online service that remote fixes and eliminates this trojan for me.</p>
<p>virus barrier apparently does the trick but the trail version only allows you to detect and not fix it? and i dont want to buy the program because im afraid to use my computer to buy anything nor do i want to wait to tomorrow to fix it!</p>
<p>i dont know who to trust and worse, i dont even know what kind of danger I&#8217;m in.</p>
<p>can anyone help me?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nicholas Ptacek</title>
		<link>http://asert.arbornetworks.com/2008/11/new-os-x-malcode-not-just-a-dnschanger/comment-page-1/#comment-182805</link>
		<dc:creator>Nicholas Ptacek</dc:creator>
		<pubDate>Mon, 01 Dec 2008 18:33:57 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/?p=527#comment-182805</guid>
		<description>Greetings,
I was wondering if it would be possible for you to send us samples of the new DNSChanger variant for OS X for further analysis.  Thank you for your time and assistance!</description>
		<content:encoded><![CDATA[<p>Greetings,<br />
I was wondering if it would be possible for you to send us samples of the new DNSChanger variant for OS X for further analysis.  Thank you for your time and assistance!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cw</title>
		<link>http://asert.arbornetworks.com/2008/11/new-os-x-malcode-not-just-a-dnschanger/comment-page-1/#comment-182798</link>
		<dc:creator>cw</dc:creator>
		<pubDate>Mon, 01 Dec 2008 17:40:51 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/?p=527#comment-182798</guid>
		<description>It doesn&#039;t matter if this is &quot;LAME&quot; - people WILL fall for it. I work in a .edu environment and there are all kinds of people clicking on everything under the sun. It&#039;s a hard problem to solve and it&#039;s not easily solved with technology. In the meanwhile, messages like this from Jose who has time to perform this analysis are useful to us and others that lack the time &amp; resources to do as much analysis as we&#039;d like to.</description>
		<content:encoded><![CDATA[<p>It doesn&#8217;t matter if this is &#8220;LAME&#8221; &#8211; people WILL fall for it. I work in a .edu environment and there are all kinds of people clicking on everything under the sun. It&#8217;s a hard problem to solve and it&#8217;s not easily solved with technology. In the meanwhile, messages like this from Jose who has time to perform this analysis are useful to us and others that lack the time &amp; resources to do as much analysis as we&#8217;d like to.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cheapRoc</title>
		<link>http://asert.arbornetworks.com/2008/11/new-os-x-malcode-not-just-a-dnschanger/comment-page-1/#comment-181606</link>
		<dc:creator>cheapRoc</dc:creator>
		<pubDate>Wed, 26 Nov 2008 03:12:09 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/?p=527#comment-181606</guid>
		<description>Congrats, this is the lamest excuse for malware on the Mac if I&#039;ve ever seen one. Its a shell script, which sets up crontab with some executable... which all of this has to be run by the users, mounting a disk image, launching the installer and giving it sudo access.

I think I used to write more impressive DOS trojans in Pascal for Renegade BBS software back in 1992... please this is LAME!</description>
		<content:encoded><![CDATA[<p>Congrats, this is the lamest excuse for malware on the Mac if I&#8217;ve ever seen one. Its a shell script, which sets up crontab with some executable&#8230; which all of this has to be run by the users, mounting a disk image, launching the installer and giving it sudo access.</p>
<p>I think I used to write more impressive DOS trojans in Pascal for Renegade BBS software back in 1992&#8230; please this is LAME!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Interesting Information Security Bits for 11/25/2008 at Infosec Ramblings</title>
		<link>http://asert.arbornetworks.com/2008/11/new-os-x-malcode-not-just-a-dnschanger/comment-page-1/#comment-181543</link>
		<dc:creator>Interesting Information Security Bits for 11/25/2008 at Infosec Ramblings</dc:creator>
		<pubDate>Tue, 25 Nov 2008 22:51:06 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/?p=527#comment-181543</guid>
		<description>[...] Some nastiness that preys on Mac OS X. Not anything new, but worth noting. New OS X Malcode: Not Just a DNSChanger &#124; Security to the Core &#124; Arbor Networks Security [...]</description>
		<content:encoded><![CDATA[<p>[...] Some nastiness that preys on Mac OS X. Not anything new, but worth noting. New OS X Malcode: Not Just a DNSChanger | Security to the Core | Arbor Networks Security [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Experiencia Personal</title>
		<link>http://asert.arbornetworks.com/2008/11/new-os-x-malcode-not-just-a-dnschanger/comment-page-1/#comment-181454</link>
		<dc:creator>Experiencia Personal</dc:creator>
		<pubDate>Tue, 25 Nov 2008 17:26:28 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/?p=527#comment-181454</guid>
		<description>Hi, i have been infected by this troyan or a similar one. I was able to clean it, but it drove me crazy.</description>
		<content:encoded><![CDATA[<p>Hi, i have been infected by this troyan or a similar one. I was able to clean it, but it drove me crazy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Experiencia Personal &#187; Más sobre el troyano en Mac OS X</title>
		<link>http://asert.arbornetworks.com/2008/11/new-os-x-malcode-not-just-a-dnschanger/comment-page-1/#comment-181453</link>
		<dc:creator>Experiencia Personal &#187; Más sobre el troyano en Mac OS X</dc:creator>
		<pubDate>Tue, 25 Nov 2008 17:22:33 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/?p=527#comment-181453</guid>
		<description>[...] foro de Macurium me ha comentado que en una página se habla más sobre este tema. Esta página es Arbor Networks, una empresa dedicada a la seguridad en [...]</description>
		<content:encoded><![CDATA[<p>[...] foro de Macurium me ha comentado que en una página se habla más sobre este tema. Esta página es Arbor Networks, una empresa dedicada a la seguridad en [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: About recent OSX Trojan &#171; Threat Researcher</title>
		<link>http://asert.arbornetworks.com/2008/11/new-os-x-malcode-not-just-a-dnschanger/comment-page-1/#comment-181298</link>
		<dc:creator>About recent OSX Trojan &#171; Threat Researcher</dc:creator>
		<pubDate>Tue, 25 Nov 2008 08:06:31 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/?p=527#comment-181298</guid>
		<description>[...] ArborNetworks: New OS X Malcode: Not Just a DNSChanger [...]</description>
		<content:encoded><![CDATA[<p>[...] ArborNetworks: New OS X Malcode: Not Just a DNSChanger [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
