SecureMac releases free Mac OS X trojan removal utility

SecureMac has released a free utility called DNSChanger Removal Tool to remove the DNSChanger Trojan Horse, also known as OSX.RSPlug.A and OSX/Puper, which has been found on numerous pornographic websites disguising itself as a video codec. Once downloaded and installed, DNSChanger changes the DNS settings on the computer, redirecting websites entered by the user to malicious sites. If personal information is entered on these malicious websites, it can lead to identity theft.

If the DNSChanger trojan horse is detected, DNSChanger Removal Tool will give you the option to remove it. If the DNSChanger trojan horse is detected and removed, you will need to restart your computer to clear out the bad DNS entries added by the DNSChanger Trojan Horse.

More info and download link (174KB) here.

33 Comments

  1. “Because my granny totally knows how to open up a terminal and enter in those commands…”

    “the DNSChanger Trojan Horse, also known as OSX.RSPlug.A and OSX/Puper, which has been found on numerous pornographic websites “

    what has granny been doing on her Mac?!?

  2. According to MDN, repeatedly (that means over and over and over) no trojans or other baddies can get into our Macs.

    So, ignore this – it’s just more FUD or… hold your breath here… it might be an invader disguised as a protector.

    Oooops, slipped again. Shut my mouth!

  3. I find it amusing that you can get this malware from pornographic web sites. It just shows that you cannot always depend on a trojan. ” width=”19″ height=”19″ alt=”wink” style=”border:0;” />

  4. Just curious as to why you would need to restart? Surely using lookupd -flushcahe in 10.4 and previous, or the new dscacheutil -flushcache in Leopard would also remove the bad DNS entries.
    Maybe I am missing something . . .

    Just an educated guess, but it seems likely that this Trojan modifies your private/etc/hosts file. If you modify your private/etc/hosts file, you need to at least logout and log back in for the changes to take effect, although restarting is as comprehensive, and easier to explain to the average users.

    I also read that this Trojan installs some cron jobs to reinfect you if you remove some of the other parts of the infection.

    Do the commands you mention do this automatically, or do they have to be explicitly invoked? Unix command line is not for the average Mac user. After all, if we wanted to do that, we would be running Linux! ” width=”19″ height=”19″ alt=”smile” style=”border:0;” />

    /etc/hosts can be modified by users. Among the reasons that you might do this is to block annoying ad and spyware sites. A good source for more info is http://www.mvps.org/winhelp2002/ Yeah, it’s Windows oriented, but it does sure block annoying ads on my Mac.

  5. It seems highly unlikely that anyone dumb enough to install an unknown program/plug-in would ever hear about this uninstaller, much less download and run it. You really do have to be either dumb as a post or seriously senile to install something like this “
    accidentally.”

  6. Ignore This: According to MDN, repeatedly (that means over and over and over) no trojans or other baddies can get into our Macs.

    No one who understands computers ever claims that Trojan horses are impossible for Mac OS X. Back up you claim, show one article on MDN saying that trojans can’t be installed on the Mac. By it’s very nature, trojans depends on the users for installation. There is no bullet proof solutions yet for user stupidity or negligence.

    Try not to argue using a strawman argument. It only makes you look stupid.

  7. This trojan is not limited to porn sites! The recent Safari upgrade already showed its worth for me when a site I visited (global warming news) tried to change my DNS server. Safari warned me and asked me if I wanted to continue.

  8. Apparently Ignore This has also ignored MDN’s frequent warnings not to install/authorize the installation of software unless you trust the source of that software. No computer/OS can protect itself from the ineptitude of a clueless user with admin privileges.

    Ignore This — Think Before You Post ®

  9. Been using Mac’s for years, always been near 100% secure.

    Now there are over 200 vunerabilities last year, one STILL hasn’t been fixed, a exploit here and there, a trojan as well.

    I might as well stick with my new Windows machine, at least I know it’s insecure and that’s that.

    Instead of flip flopping back and forth with Mac’s and Mac OS X “Is it secure? is it not secure?” and having to put up with a rather LIMITED HARDWARE CHOICE.

    Been using Windows for about a two weeks now, it’s really not bad at all.

    It’s the quality of software that makes the difference, I use Safari and iTunes on Windows, Open Office/NeoOfficeJ on both machines to get files across.

    Windows XP IS NOT ALL THAT BAD.

    If Mac OS X is insecure, then what difference does it make with Windows? They both do the job you need it to do.

    One is just tied to overpriced hardware and a bunch of cultists.

    Beleive me, I know because I was one.

    If Apple didn’t come out with glossy only mid-range machines, I wouldn’t have switched to Windows.

  10. To all the morons who cried about not being able to enter simple commands in the command line. I was not suggesting you all open terminal yourself, and get all freaked out and scared. The trojan remover could have done this for you.
    I think you should all be over on the Windows platform with the rest of the fools…

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.