<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: New OS X Malcode: Not Just a DNSChanger</title>
	<atom:link href="http://ddos.arbornetworks.com/2008/11/new-os-x-malcode-not-just-a-dnschanger/feed/" rel="self" type="application/rss+xml" />
	<link>http://ddos.arbornetworks.com/2008/11/new-os-x-malcode-not-just-a-dnschanger/</link>
	<description>A weblog dedicated to educating the community on security threats that matter</description>
	<lastBuildDate>Sun, 29 Jan 2012 02:23:23 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: New spin on OSX/RSPlug Mac malware &#124; Naked Security</title>
		<link>http://ddos.arbornetworks.com/2008/11/new-os-x-malcode-not-just-a-dnschanger/comment-page-1/#comment-271297</link>
		<dc:creator>New spin on OSX/RSPlug Mac malware &#124; Naked Security</dc:creator>
		<pubDate>Mon, 18 Oct 2010 09:18:32 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/?p=527#comment-271297</guid>
		<description>[...] will soon add detection for a new Mac Trojan, nicely described by Jose Nazario of Arbor Networks. It will be detected as OSX/Jahlav-A. The Trojan comes as a key generator application MacAccess in [...]</description>
		<content:encoded><![CDATA[<p>[...] will soon add detection for a new Mac Trojan, nicely described by Jose Nazario of Arbor Networks. It will be detected as OSX/Jahlav-A. The Trojan comes as a key generator application MacAccess in [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: matt</title>
		<link>http://ddos.arbornetworks.com/2008/11/new-os-x-malcode-not-just-a-dnschanger/comment-page-1/#comment-186218</link>
		<dc:creator>matt</dc:creator>
		<pubDate>Fri, 19 Dec 2008 08:47:24 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/?p=527#comment-186218</guid>
		<description>update: i downloaded the DNSChangerRemovalTool

My DNS is back to normal but I still have this Adobe Flash in my cron search.  after reading several articles tonite, it does seem like that that cron is either wrongly accused of wrong doin or indeed is part of the culprit. Anyone know for sure.. and if it is bad? how do i get rid of that?!</description>
		<content:encoded><![CDATA[<p>update: i downloaded the DNSChangerRemovalTool</p>
<p>My DNS is back to normal but I still have this Adobe Flash in my cron search.  after reading several articles tonite, it does seem like that that cron is either wrongly accused of wrong doin or indeed is part of the culprit. Anyone know for sure.. and if it is bad? how do i get rid of that?!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: matt</title>
		<link>http://ddos.arbornetworks.com/2008/11/new-os-x-malcode-not-just-a-dnschanger/comment-page-1/#comment-186199</link>
		<dc:creator>matt</dc:creator>
		<pubDate>Fri, 19 Dec 2008 07:17:33 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/?p=527#comment-186199</guid>
		<description>I fell for it  - its definitely this macaccess installer Osxjahlava trojan and now have no idea what to do
(btw - i got this thru trying to download a firefox plugin for craigslist called Clpicview

In trying to fix this situation,  i keep coming across sites that describe it but no resource for fixin and removing it

i also come across sites claiming to be able to fix it if you buy their software

there are other sites that mention an online scan but upon careful readin it looks like its for uploading files to be scanned and screened? which makes sense cause i cant imagine an online service that remote fixes and eliminates this trojan for me.

virus barrier apparently does the trick but the trail version only allows you to detect and not fix it? and i dont want to buy the program because im afraid to use my computer to buy anything nor do i want to wait to tomorrow to fix it!

i dont know who to trust and worse, i dont even know what kind of danger I&#039;m in.

can anyone help me?</description>
		<content:encoded><![CDATA[<p>I fell for it  &#8211; its definitely this macaccess installer Osxjahlava trojan and now have no idea what to do<br />
(btw &#8211; i got this thru trying to download a firefox plugin for craigslist called Clpicview</p>
<p>In trying to fix this situation,  i keep coming across sites that describe it but no resource for fixin and removing it</p>
<p>i also come across sites claiming to be able to fix it if you buy their software</p>
<p>there are other sites that mention an online scan but upon careful readin it looks like its for uploading files to be scanned and screened? which makes sense cause i cant imagine an online service that remote fixes and eliminates this trojan for me.</p>
<p>virus barrier apparently does the trick but the trail version only allows you to detect and not fix it? and i dont want to buy the program because im afraid to use my computer to buy anything nor do i want to wait to tomorrow to fix it!</p>
<p>i dont know who to trust and worse, i dont even know what kind of danger I&#8217;m in.</p>
<p>can anyone help me?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nicholas Ptacek</title>
		<link>http://ddos.arbornetworks.com/2008/11/new-os-x-malcode-not-just-a-dnschanger/comment-page-1/#comment-182805</link>
		<dc:creator>Nicholas Ptacek</dc:creator>
		<pubDate>Mon, 01 Dec 2008 18:33:57 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/?p=527#comment-182805</guid>
		<description>Greetings,
I was wondering if it would be possible for you to send us samples of the new DNSChanger variant for OS X for further analysis.  Thank you for your time and assistance!</description>
		<content:encoded><![CDATA[<p>Greetings,<br />
I was wondering if it would be possible for you to send us samples of the new DNSChanger variant for OS X for further analysis.  Thank you for your time and assistance!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cw</title>
		<link>http://ddos.arbornetworks.com/2008/11/new-os-x-malcode-not-just-a-dnschanger/comment-page-1/#comment-182798</link>
		<dc:creator>cw</dc:creator>
		<pubDate>Mon, 01 Dec 2008 17:40:51 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/?p=527#comment-182798</guid>
		<description>It doesn&#039;t matter if this is &quot;LAME&quot; - people WILL fall for it. I work in a .edu environment and there are all kinds of people clicking on everything under the sun. It&#039;s a hard problem to solve and it&#039;s not easily solved with technology. In the meanwhile, messages like this from Jose who has time to perform this analysis are useful to us and others that lack the time &amp; resources to do as much analysis as we&#039;d like to.</description>
		<content:encoded><![CDATA[<p>It doesn&#8217;t matter if this is &#8220;LAME&#8221; &#8211; people WILL fall for it. I work in a .edu environment and there are all kinds of people clicking on everything under the sun. It&#8217;s a hard problem to solve and it&#8217;s not easily solved with technology. In the meanwhile, messages like this from Jose who has time to perform this analysis are useful to us and others that lack the time &amp; resources to do as much analysis as we&#8217;d like to.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

