Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

TESEV

macrumors member
Original poster
Jun 1, 2006
76
0
New Orleans, LA
My mom got a previous variant on her iMac. I've since made her a non-administrator. Does this make her safe(r)?

http://www.intego.com/news/ism0806.asp

Integro said:
Exploit: OSX.RSPlug.D Trojan Horse

Discovered: November 18, 2008

Risk: Medium

Description: A new variant of the RSPlug Trojan horse has been found on several pornographic web sites. (See Intego’s Internet Security Memo of October 31, 2007 for more on this Trojan horse.) While this new variant currently performs the same actions as the RSPlug.A Trojan horse, its installer is different: it is a downloader, and it contacts a remote server to download the files it installs. This means that, in the future, the downloader may be able to install other payloads than the one it currently installs.

This new variant, like the initial RSPlug.A Trojan horse, has been found on pornographic web sites. When visiting such a site, a user is alerted that there is a “Video ActiveX Object Error” and is told that their “Browser cannot play this video file.” The alert instructs the user to download the “missing Video ActiveX Object”. If the user clicks OK, a disk image called cleanlive.dmg downloads (this name may be different in the future; with the first version of the RSPlug Trojan horse, a number of different names were found). Depending on the user’s browser settings, this disk image may mount and launch automatically commencing installation. If the user clicks Cancel when the Video ActiveX Object alert displays, however, they receive another alert saying, “Please install new version of Video ActiveX Object.” This alert only allows the user to click OK, returning them to the first alert. The only way to get rid of these alerts is either to download the infected disk image, or quit the browser.
 
I've seen them (actually, I've seen Windows versions that use the same "Video ActiveX Object" message) on some non-porn sites out there. They start with the pornos, but they eventually migrate out to the wider web.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.