Mac Browser Hijack
From ITS Wiki - Information Technology Services - University of Rhode Island
| Macintosh This page is part of a category. To see more pages like this, go to the Macintosh index. |
Currently, a number of pornography websites are distributing a disk image (.dmg) containing the "OSX.RSPlug.A" application under the guise of QuickTime codecs. Users are prompted to download, open, install, and authenticate the disk image with their administrator password. Users who do not provide their administrator password are not at risk.
Removal From OS X 10.5
1. Eject and delete the disk image (.dmg) file.
2. Go to disc/Library/Internet Plug-Ins/ and delete the file named plugins.settings, then empty the trash.
3. Go to Applications/Utilities, and open Terminal. Type the following and provide your admin password when asked.
sudo crontab -r
4. Go to System Preferences and select the Network panel. Go to the DNS Server box, and copy the entries to a note.
5. Retype those same values in the box, then click Apply. Restart the machine. Your DNS files should be rebuilt correctly.
Related Links:
http://www.macnn.com/articles/07/10/31/new.trojan.targets.macs/

