<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Analysis of OSX Trojan DNS Changer</title>
	<atom:link href="http://ithreats.net/2008/01/11/analysis-of-osx-trojan-dns-changer/feed/" rel="self" type="application/rss+xml" />
	<link>http://ithreats.net/2008/01/11/analysis-of-osx-trojan-dns-changer/</link>
	<description>What Do You Think Is The Biggest Threat To Mac Users&#039; Security?</description>
	<lastBuildDate>Thu, 24 Nov 2011 17:54:28 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Eesha</title>
		<link>http://ithreats.net/2008/01/11/analysis-of-osx-trojan-dns-changer/#comment-909</link>
		<dc:creator><![CDATA[Eesha]]></dc:creator>
		<pubDate>Fri, 30 Apr 2010 15:53:48 +0000</pubDate>
		<guid isPermaLink="false">http://ithreats.wordpress.com/2008/01/11/analysis-of-osx-trojan-dns-changer/#comment-909</guid>
		<description><![CDATA[I have a mac and i rebooted the whole thing and there is currently nothing sitting in my internet plug ins folder and yet the virus is still there after i erased and re installed everything, pls help??]]></description>
		<content:encoded><![CDATA[<p>I have a mac and i rebooted the whole thing and there is currently nothing sitting in my internet plug ins folder and yet the virus is still there after i erased and re installed everything, pls help??</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cleaner</title>
		<link>http://ithreats.net/2008/01/11/analysis-of-osx-trojan-dns-changer/#comment-384</link>
		<dc:creator><![CDATA[Cleaner]]></dc:creator>
		<pubDate>Thu, 21 May 2009 13:42:44 +0000</pubDate>
		<guid isPermaLink="false">http://ithreats.wordpress.com/2008/01/11/analysis-of-osx-trojan-dns-changer/#comment-384</guid>
		<description><![CDATA[If someone still has the .dmg, could you please send it to me at antoinebis at gmail.com. I would like to test my program.

Thanks !]]></description>
		<content:encoded><![CDATA[<p>If someone still has the .dmg, could you please send it to me at antoinebis at gmail.com. I would like to test my program.</p>
<p>Thanks !</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: How to Get Six Pack Fast</title>
		<link>http://ithreats.net/2008/01/11/analysis-of-osx-trojan-dns-changer/#comment-353</link>
		<dc:creator><![CDATA[How to Get Six Pack Fast]]></dc:creator>
		<pubDate>Wed, 15 Apr 2009 14:50:36 +0000</pubDate>
		<guid isPermaLink="false">http://ithreats.wordpress.com/2008/01/11/analysis-of-osx-trojan-dns-changer/#comment-353</guid>
		<description><![CDATA[Not that I&#039;m totally impressed, but this is a lot more than I expected for when I found a link on SU telling that the info   is awesome. Thanks.]]></description>
		<content:encoded><![CDATA[<p>Not that I&#8217;m totally impressed, but this is a lot more than I expected for when I found a link on SU telling that the info   is awesome. Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Methusela Cebrian Ferrer</title>
		<link>http://ithreats.net/2008/01/11/analysis-of-osx-trojan-dns-changer/#comment-292</link>
		<dc:creator><![CDATA[Methusela Cebrian Ferrer]]></dc:creator>
		<pubDate>Tue, 03 Mar 2009 08:01:49 +0000</pubDate>
		<guid isPermaLink="false">http://ithreats.wordpress.com/2008/01/11/analysis-of-osx-trojan-dns-changer/#comment-292</guid>
		<description><![CDATA[Hi Trenton, Wsearch.net is not related to any malware ... you might want to check this: http://ithreats.net/2008/09/21/wsearchnetunknown-is-it-new-dnschanger/ 

One of the reader&#039;s comment ... 

&quot;This is problem with SMC wireless router/modems. I am an Interent Support Rep and have seen this problem with customer and described on other sites. The problem is that the default search domain on these routers is set to mygateway.net. Changing this to a legitimate search domain is a work around for the problem, but I have seen no explaination for why the default serch domain is set to this. It has been reported for more than one ISP so it not something that just one ISP is doing.&quot;]]></description>
		<content:encoded><![CDATA[<p>Hi Trenton, Wsearch.net is not related to any malware &#8230; you might want to check this: <a href="http://ithreats.net/2008/09/21/wsearchnetunknown-is-it-new-dnschanger/" rel="nofollow">http://ithreats.net/2008/09/21/wsearchnetunknown-is-it-new-dnschanger/</a> </p>
<p>One of the reader&#8217;s comment &#8230; </p>
<p>&#8220;This is problem with SMC wireless router/modems. I am an Interent Support Rep and have seen this problem with customer and described on other sites. The problem is that the default search domain on these routers is set to mygateway.net. Changing this to a legitimate search domain is a work around for the problem, but I have seen no explaination for why the default serch domain is set to this. It has been reported for more than one ISP so it not something that just one ISP is doing.&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: trenton</title>
		<link>http://ithreats.net/2008/01/11/analysis-of-osx-trojan-dns-changer/#comment-290</link>
		<dc:creator><![CDATA[trenton]]></dc:creator>
		<pubDate>Mon, 02 Mar 2009 10:52:48 +0000</pubDate>
		<guid isPermaLink="false">http://ithreats.wordpress.com/2008/01/11/analysis-of-osx-trojan-dns-changer/#comment-290</guid>
		<description><![CDATA[i have the stupid wsearch.net thing and i looked for all the files that you say to remove and i tried to change the dns but its still there i dont know how to remove it i have a mac 10.4.11 and i have no clue how to make it stop i have tried all the things and it seems to be getting worse please help]]></description>
		<content:encoded><![CDATA[<p>i have the stupid wsearch.net thing and i looked for all the files that you say to remove and i tried to change the dns but its still there i dont know how to remove it i have a mac 10.4.11 and i have no clue how to make it stop i have tried all the things and it seems to be getting worse please help</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Methusela Cebrian Ferrer</title>
		<link>http://ithreats.net/2008/01/11/analysis-of-osx-trojan-dns-changer/#comment-254</link>
		<dc:creator><![CDATA[Methusela Cebrian Ferrer]]></dc:creator>
		<pubDate>Wed, 11 Feb 2009 10:20:41 +0000</pubDate>
		<guid isPermaLink="false">http://ithreats.wordpress.com/2008/01/11/analysis-of-osx-trojan-dns-changer/#comment-254</guid>
		<description><![CDATA[Hi Dr Alban, I hope my reply is not too late. To remove type &quot;sudo crontab -r&quot; - however, it would be better to do this without internet connection. Also, don&#039;t forget to check your DNS settings and look for IP address starting with 85.xx.xx.xx and make sure you remove this entry. 

Let me know how it goes.]]></description>
		<content:encoded><![CDATA[<p>Hi Dr Alban, I hope my reply is not too late. To remove type &#8220;sudo crontab -r&#8221; &#8211; however, it would be better to do this without internet connection. Also, don&#8217;t forget to check your DNS settings and look for IP address starting with 85.xx.xx.xx and make sure you remove this entry. </p>
<p>Let me know how it goes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dr Alban</title>
		<link>http://ithreats.net/2008/01/11/analysis-of-osx-trojan-dns-changer/#comment-250</link>
		<dc:creator><![CDATA[Dr Alban]]></dc:creator>
		<pubDate>Tue, 10 Feb 2009 16:13:16 +0000</pubDate>
		<guid isPermaLink="false">http://ithreats.wordpress.com/2008/01/11/analysis-of-osx-trojan-dns-changer/#comment-250</guid>
		<description><![CDATA[Got the DNS Changer but a different type. The IP is 85.255.113.126 and  85.255.112.227

Used terminal and &quot;sudo crontab -l&quot; and found:

* * * * * &quot;/Library/Internet Plug-Ins/QuickTime.xpt&quot;&gt;/dev/null 2&gt;&amp;1

However I can&#039;t remove it. I only get &quot;localized rsrc&quot; is using it and therefore I can&#039;t empty thrash. 

What to do?]]></description>
		<content:encoded><![CDATA[<p>Got the DNS Changer but a different type. The IP is 85.255.113.126 and  85.255.112.227</p>
<p>Used terminal and &#8220;sudo crontab -l&#8221; and found:</p>
<p>* * * * * &#8220;/Library/Internet Plug-Ins/QuickTime.xpt&#8221;&gt;/dev/null 2&gt;&amp;1</p>
<p>However I can&#8217;t remove it. I only get &#8220;localized rsrc&#8221; is using it and therefore I can&#8217;t empty thrash. </p>
<p>What to do?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Methusela Cebrian Ferrer</title>
		<link>http://ithreats.net/2008/01/11/analysis-of-osx-trojan-dns-changer/#comment-243</link>
		<dc:creator><![CDATA[Methusela Cebrian Ferrer]]></dc:creator>
		<pubDate>Sat, 07 Feb 2009 03:35:44 +0000</pubDate>
		<guid isPermaLink="false">http://ithreats.wordpress.com/2008/01/11/analysis-of-osx-trojan-dns-changer/#comment-243</guid>
		<description><![CDATA[I&#039;m glad you made this question. 

This is what we call &quot;DNS Pharming Attack&quot;. So a malware like DNSChanger trojan attempts to modify users DNS settings so that when user type a valid URL they are redirected to a list of websites that belongs to these attackers. As an effect, an innocent/infected user will thought that he/she is clicking a valid website like example, Facebook.com instead its completely loading different page. Pharming provides an attacker a advantage to hijack your browser and may cause disclosure of your private information, browsing behavior, direct to exploit websites, push further malware, push advertisements (so, you&#039;ll find pop-ups coming out from time to time).

For common user perspective, this attack doesn&#039;t seems harmful, however this is where attacker silently takes real advantage of the infection. 

I hope this provides you clear understanding of this threat.]]></description>
		<content:encoded><![CDATA[<p>I&#8217;m glad you made this question. </p>
<p>This is what we call &#8220;DNS Pharming Attack&#8221;. So a malware like DNSChanger trojan attempts to modify users DNS settings so that when user type a valid URL they are redirected to a list of websites that belongs to these attackers. As an effect, an innocent/infected user will thought that he/she is clicking a valid website like example, Facebook.com instead its completely loading different page. Pharming provides an attacker a advantage to hijack your browser and may cause disclosure of your private information, browsing behavior, direct to exploit websites, push further malware, push advertisements (so, you&#8217;ll find pop-ups coming out from time to time).</p>
<p>For common user perspective, this attack doesn&#8217;t seems harmful, however this is where attacker silently takes real advantage of the infection. </p>
<p>I hope this provides you clear understanding of this threat.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Liane</title>
		<link>http://ithreats.net/2008/01/11/analysis-of-osx-trojan-dns-changer/#comment-240</link>
		<dc:creator><![CDATA[Liane]]></dc:creator>
		<pubDate>Thu, 05 Feb 2009 17:41:59 +0000</pubDate>
		<guid isPermaLink="false">http://ithreats.wordpress.com/2008/01/11/analysis-of-osx-trojan-dns-changer/#comment-240</guid>
		<description><![CDATA[Just wondering...what can hackers do with your modified DNS settings?  What do they really get out of it?  In other words, what&#039;s the real point to these trojans...]]></description>
		<content:encoded><![CDATA[<p>Just wondering&#8230;what can hackers do with your modified DNS settings?  What do they really get out of it?  In other words, what&#8217;s the real point to these trojans&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mitch</title>
		<link>http://ithreats.net/2008/01/11/analysis-of-osx-trojan-dns-changer/#comment-126</link>
		<dc:creator><![CDATA[mitch]]></dc:creator>
		<pubDate>Sun, 07 Dec 2008 08:40:26 +0000</pubDate>
		<guid isPermaLink="false">http://ithreats.wordpress.com/2008/01/11/analysis-of-osx-trojan-dns-changer/#comment-126</guid>
		<description><![CDATA[I recently installed it by mistake or I think that I did. I looked in Library-internet plugins and couldn&#039;t find quicktime.xpt or moxillaplug.plugin. I checked DNS and did not see  s1=85.255.115.22 and s2=85.255.112.190 or 64.28.188.220. Did  I dodge a bullet?? When I tried to install, it says installation failed.  What should I look for? How do I know if it installed? How can I get rid of it if I have it?
Thanks.]]></description>
		<content:encoded><![CDATA[<p>I recently installed it by mistake or I think that I did. I looked in Library-internet plugins and couldn&#8217;t find quicktime.xpt or moxillaplug.plugin. I checked DNS and did not see  s1=85.255.115.22 and s2=85.255.112.190 or 64.28.188.220. Did  I dodge a bullet?? When I tried to install, it says installation failed.  What should I look for? How do I know if it installed? How can I get rid of it if I have it?<br />
Thanks.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

