Thursday, January 31, 2008

Malware Retailers Includes Trojan for Mac

As I mentioned last time, it is possible that these retailers will also include binary for Mac.

Now it's confirmed, as I was surfing my webmaster account this morning, I went to "Galleries" page (this contains thousand of links to different porn sites) and noticed the name of the codec it is trying to install "qazcodec4481.exe". I reckon one of the installer of Trojan DNS Changer is "qazcodec1000.dmg".

The installation strategy of this malware always looks like this.

Beware of this trick!