<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1155203086394184661</id><updated>2010-02-25T16:13:36.684-08:00</updated><title type='text'>iAntiVirus Blog</title><subtitle type='html'>Blog discussing the latest discoveries and research involving viruses, spyware and malware on Mac OS X systems.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.iantivirus.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default'/><link rel='alternate' type='text/html' href='http://blog.iantivirus.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default?start-index=26&amp;max-results=25'/><author><name>NSArchitect</name><uri>http://www.blogger.com/profile/10052529130215654134</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>73</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1155203086394184661.post-1563733997442334159</id><published>2010-02-04T18:53:00.000-08:00</published><updated>2010-02-04T23:25:32.878-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Exploit.OSX.Snid.b'/><category scheme='http://www.blogger.com/atom/ns#' term='(CVE-2009-3867)'/><title type='text'>Cross-Platform Exploit Affects Mac Users</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/_me98LqjebtU/S2uQpORB9qI/AAAAAAAAABM/UEllpR74S-E/s1600-h/sun+java.bmp"&gt;&lt;img id="BLOGGER_PHOTO_ID_5434596413231199906" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 200px; CURSOR: hand; HEIGHT: 200px" alt="" src="http://3.bp.blogspot.com/_me98LqjebtU/S2uQpORB9qI/AAAAAAAAABM/UEllpR74S-E/s200/sun+java.bmp" border="0" /&gt;&lt;/a&gt;A new exploit code has been seen in the wild that attacks Windows, Unix, Linux, and Mac OSX systems. Given this ambitious range of targets, the exploit itself is rather old-style and short, but effective.&lt;br /&gt;&lt;br /&gt;It takes advantage of a buffer overflow vulnerability in Sun’s Java Runtime Environment. It occurs when a specially crafted file://URL argument is passed to the getSoundbank() function that can allow a remote attacker to execute arbitrary code.&lt;br /&gt;&lt;br /&gt;PC Tools iAntivirus detects the exploit code as Exploit.OSX.Snid.b in the latest database.&lt;br /&gt;&lt;br /&gt;The said vulnerability (CVE-2009-3867) is discussed &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3867"&gt;here &lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Users are highly advised to upgrade to the latest versions from the following link:&lt;br /&gt;http://java.sun.com/&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1155203086394184661-1563733997442334159?l=blog.iantivirus.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/1563733997442334159'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/1563733997442334159'/><link rel='alternate' type='text/html' href='http://blog.iantivirus.com/2010/02/cross-platform-exploit-affects-mac.html' title='Cross-Platform Exploit Affects Mac Users'/><author><name>Mylene Villacorte</name><uri>http://www.blogger.com/profile/07329643360109257929</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10838500839504016865'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_me98LqjebtU/S2uQpORB9qI/AAAAAAAAABM/UEllpR74S-E/s72-c/sun+java.bmp' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-1155203086394184661.post-1565899506924131699</id><published>2009-11-24T15:35:00.000-08:00</published><updated>2009-11-24T17:05:55.882-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='iPhone'/><category scheme='http://www.blogger.com/atom/ns#' term='worm'/><title type='text'>iKee iPhone Worm Strikes Again!</title><content type='html'>PC Tools' Malware Research Center received a sample of an iPhone worm that is strikingly similar with the iKee worm that displays an image of Rick Astley, and was originally intended as a prank. This one, however, has an added functionality of using compromised iPhones in a Botnet, a network of infected computers and devices that can be controlled by hackers to perform malicious activities.&lt;br /&gt;&lt;br /&gt;Like Worm.iPhoneOS.Ikee which we blogged about a &lt;a href="http://blog.iantivirus.com/2009/11/iphone-worm-found-rickrollin-in-wild.html"&gt;few weeks ago&lt;/a&gt;, it scans a range of IP addresses mostly from the Netherlands, and Australia.&lt;br /&gt;&lt;br /&gt;The worm then attempts to log in to all jailbroken iPhones with SSH installed using the default password, and copies itself to the compromised device.&lt;br /&gt;&lt;br /&gt;Once active in the iPhone, the worm will change the default password found in the file, /etc/master.passwd. This is necessary for the attacker to prevent the victim from logging in.&lt;br /&gt;&lt;br /&gt;The worm will then download and install all necessary application packages it needs to perform its malicious activities such as sending sensitive information it gathered to the remote server, and providing botnet functionality to the compromised devices.&lt;br /&gt;&lt;br /&gt;This worm connects to a command &amp;amp; control center running at 92.61.38.16 in Lithuania.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_lqswCgKLeDU/Swx71cPPB-I/AAAAAAAAAHA/NWL9eKkUH9s/s1600/ikee.b.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 47px;" src="http://3.bp.blogspot.com/_lqswCgKLeDU/Swx71cPPB-I/AAAAAAAAAHA/NWL9eKkUH9s/s400/ikee.b.png" alt="" id="BLOGGER_PHOTO_ID_5407833410608498658" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;PC Tools advises its customers not to jailbreak their iPhones due to the security risks involved. Not only does it open to a lot of vulnerabilities for hackers to exploit, it also violates your warranty.&lt;br /&gt;&lt;br /&gt;Apple has already issued a brief statement regarding this latest threat as published on &lt;a href="http://www.loopinsight.com/2009/11/23/apple-responds-to-reports-of-new-iphone-worm/"&gt;The Loop&lt;/a&gt;:&lt;p style="font-style: italic;" class="quote"&gt;&lt;span style="font-size:85%;"&gt;"The worm affects only a very specific set of iPhone users who have jail broken their iPhones and hacked it with unauthorized software," Apple spokesperson, Natalie Harrison, told The Loop. "As we've said before, the vast majority of customers do not jailbreak their iPhones, and for good reason. These hacks not only violate the warranty, they will also cause the iPhone to become unstable and not work reliably."&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1155203086394184661-1565899506924131699?l=blog.iantivirus.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/1565899506924131699'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/1565899506924131699'/><link rel='alternate' type='text/html' href='http://blog.iantivirus.com/2009/11/ikee-iphone-worm-strikes-again.html' title='iKee iPhone Worm Strikes Again!'/><author><name>Erwin Varona</name><uri>http://www.blogger.com/profile/08398258419133331070</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='02305845984697575807'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_lqswCgKLeDU/Swx71cPPB-I/AAAAAAAAAHA/NWL9eKkUH9s/s72-c/ikee.b.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-1155203086394184661.post-1393165531592076053</id><published>2009-11-11T14:21:00.000-08:00</published><updated>2009-11-11T15:01:22.785-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='jailbroken'/><category scheme='http://www.blogger.com/atom/ns#' term='iPhone'/><category scheme='http://www.blogger.com/atom/ns#' term='info stealer'/><title type='text'>Info Stealer targets Jailbroken iPhones</title><content type='html'>A week has barely passed since the first iPhone worm (Worm.iPhoneOS.Ikee) came ‘rickrolling’ into our collective awareness, and now we already have its first official copycat!&lt;br /&gt;&lt;br /&gt;A new Trojan has been spotted employing the very same technique employed by the ikee worm to break into jailbroken iPhones.  It scans a network (a home, office, or public wifi network would suffice) for the presence of jailbroken iPhones still running SSH.  Enabling SSH is a common step in jailbreaking as these allows the user to login to the phone remotely and execute shell  commands.  And, as should be common knowledge by now, all iPhones have the same default root password that users neglect to change after jailbreaking them.&lt;br /&gt;&lt;br /&gt;What this new Trojan lacks in originality of technique, however, it more than makes up for with a more vicious payload.  Whereas the ikee worm contents itself with changing the iPhone wallpaper, this new Trojan will steal data from compromised devices!  This means all SMS and contacts list stored in vulnerable phones are up for grabs!&lt;br /&gt;&lt;br /&gt;While these new iPhone malwares are breaking news, we should realize that the SSH vulnerability it exploits is really nothing new.  It has been there ever since the first jailbroken iPhone.  In fact, before ikee, Ars Technica ran an article &lt;a href="http://arstechnica.com/apple/news/2009/11/dutch-hacker-holds-jailbroken-iphones-hostage-for-5.ars"&gt; article &lt;/a&gt; on their site about a ‘ransomware’ spreading in the Netherlands.  It scans networks for iPhones with SSH enabled, then sends the owners the following SMS message:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_me98LqjebtU/Svs5_0vFZTI/AAAAAAAAAA8/rEDV6VCdjdA/s1600-h/iphone.JPG"&gt;&lt;img style="cursor: pointer; width: 214px; height: 320px;" src="http://2.bp.blogspot.com/_me98LqjebtU/Svs5_0vFZTI/AAAAAAAAAA8/rEDV6VCdjdA/s320/iphone.JPG" alt="" id="BLOGGER_PHOTO_ID_5402975946611713330" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;When you visit his site, he then charges you €5 for instructions on how to secure your phone, information that is actually available to anyone for free.&lt;br /&gt;&lt;br /&gt;So lets all learn the lesson here.  First, there are very real risks to jailbreaking.  Second, and more important, never use default passwords, whether for your combination locks at home or for your digital devices.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1155203086394184661-1393165531592076053?l=blog.iantivirus.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/1393165531592076053'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/1393165531592076053'/><link rel='alternate' type='text/html' href='http://blog.iantivirus.com/2009/11/info-stealer-targets-jailbroken-iphones.html' title='Info Stealer targets Jailbroken iPhones'/><author><name>Mylene Villacorte</name><uri>http://www.blogger.com/profile/07329643360109257929</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10838500839504016865'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_me98LqjebtU/Svs5_0vFZTI/AAAAAAAAAA8/rEDV6VCdjdA/s72-c/iphone.JPG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-1155203086394184661.post-5225459661230644860</id><published>2009-11-09T15:55:00.000-08:00</published><updated>2009-11-09T19:05:53.539-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='iPhone'/><category scheme='http://www.blogger.com/atom/ns#' term='worm'/><title type='text'>iPhone Worm Found Rickrollin' in the Wild</title><content type='html'>A new worm targeting Apple's iPhone has been headlining the news as of late. This iPhone worm, dubbed as Ikee, has been infecting Jailbroken iPhones (hacked iphones allowing installation of applications outside of iTunes) all over Australia, and infected users found themselves having iPhones with a photo of Rick Astley as its wallpaper, and a message stating that "ikee is never going to give you up". This is actually a very popular prank among internet users and is known as Rickrolling.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_lqswCgKLeDU/Svitw9aecjI/AAAAAAAAAGw/-wicpu7ejYw/s1600-h/photo.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 267px; height: 400px;" src="http://4.bp.blogspot.com/_lqswCgKLeDU/Svitw9aecjI/AAAAAAAAAGw/-wicpu7ejYw/s400/photo.jpg" alt="" id="BLOGGER_PHOTO_ID_5402258809661846066" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;This worm specifically targets Jailbroken phones with a root login password still set to the default password &lt;span style="font-style: italic;"&gt;alpine&lt;/span&gt;. This opens a hole for hackers to exploit since Jailbroken phones use an SSH daemon which allows for remote connections.&lt;br /&gt;&lt;br /&gt;In the case of Ikee, the worm scans a hardcoded list of IP ranges belonging to several Australian Telecom companies for vulnerable iPhones. Once a vulnerable iPhone has been found, the worm copies several files including a copy of itself to the iPhone, and changes its wallpaper to a photo of Rick Astley. It then disables the SSH service to prevent reinfection, and calls for another scan on the network to look for other vulnerable iPhones.&lt;br /&gt;&lt;br /&gt;Jailbroken iPhones obviously pose some serious risks. If you have decided to do so, make sure you have changed your SSH password (instructions for changing the password can be found &lt;a href="http://cydia.saurik.com/password.html"&gt;here&lt;/a&gt; courtesy of Cydia) and be aware that you have a greater risk of getting infected than non - Jailbroken iPhones.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1155203086394184661-5225459661230644860?l=blog.iantivirus.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/5225459661230644860'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/5225459661230644860'/><link rel='alternate' type='text/html' href='http://blog.iantivirus.com/2009/11/iphone-worm-found-rickrollin-in-wild.html' title='iPhone Worm Found Rickrollin&apos; in the Wild'/><author><name>Erwin Varona</name><uri>http://www.blogger.com/profile/08398258419133331070</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='02305845984697575807'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_lqswCgKLeDU/Svitw9aecjI/AAAAAAAAAGw/-wicpu7ejYw/s72-c/photo.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-1155203086394184661.post-7415067981696301601</id><published>2009-10-29T16:38:00.000-07:00</published><updated>2009-10-29T17:24:39.368-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='loselose'/><category scheme='http://www.blogger.com/atom/ns#' term='game'/><title type='text'>Entertainment in exchange for loss of data!</title><content type='html'>There’s a new game available for download on the internet called &lt;strong&gt;Loose/Loose&lt;/strong&gt;. It has the look and feel of the arcad&lt;a href="http://1.bp.blogspot.com/_me98LqjebtU/SuooUc-74hI/AAAAAAAAAAM/xlfxIlvBrhM/s1600-h/lose1.jpg"&gt;&lt;/a&gt;e classics from the 80s like Space Invaders and Missile Command.&lt;br /&gt;&lt;br /&gt;The following snapshot shows a lone silver airship at the bottom of the screen battling multicolored alien ships descending down on him:&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;p align="center"&gt;&lt;a href="http://3.bp.blogspot.com/_me98LqjebtU/SuouVxbvf9I/AAAAAAAAAA0/lj3rDWaDUMQ/s1600-h/lose1.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5398178054938787794" style="WIDTH: 191px; CURSOR: hand; HEIGHT: 320px" alt="" src="http://3.bp.blogspot.com/_me98LqjebtU/SuouVxbvf9I/AAAAAAAAAA0/lj3rDWaDUMQ/s320/lose1.jpg" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div&gt;But wait…if we zoom a little closer on those alien ships that have been shot and that has exploded into a hundred tiny pieces and…are those words spelling out file types names (wav) !? &lt;/div&gt;&lt;div align="center"&gt;&lt;a href="http://2.bp.blogspot.com/_me98LqjebtU/SuopD9y-hVI/AAAAAAAAAAU/xFFZJgKI6TE/s1600-h/lose2.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5398172251461682514" style="WIDTH: 274px; CURSOR: hand; HEIGHT: 300px" alt="" src="http://2.bp.blogspot.com/_me98LqjebtU/SuopD9y-hVI/AAAAAAAAAAU/xFFZJgKI6TE/s320/lose2.jpg" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;Apparently, this seemingly innocent and nostalgic piece of software comes with a nasty twist. Each of those alien enemy ships represent an actual file chosen at random in your hard drive. Destroy an alien ship and you delete the file it represents permanently! Entertainment in exchange for loss of data!&lt;br /&gt;&lt;br /&gt;The game’s creator, Zach Gage, is a digital mixed media artist who has lately been active in developing applications for the iphone. Based on his web page, he seem to want us to consider this video game as a testament to our modern age’s increasing acceptance of technology as a ‘given’ in our lives…how it has become as mundane and ingrained to us as our day to day tasks.&lt;br /&gt;&lt;br /&gt;As quoted from his site:&lt;/div&gt;&lt;div&gt;&lt;em&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;/em&gt; &lt;/div&gt;&lt;div&gt;&lt;em&gt;&lt;span style="font-size:85%;"&gt;Why do we assume that because we are given a weapon an awarded for using it, that doing so is right?&lt;br /&gt;By way of exploring what it means to kill in a video-game, Lose/Lose broaches bigger questions. As technology grows, our understanding of it diminishes, yet, at the same time, it becomes increasingly important in our lives. At what point does our virtual data become as important to us as physical possessions? If we have reached that point already, what real objects do we value less than our data? What implications does trusting something so important to something we understand so poorly have?&lt;/span&gt;&lt;/em&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;&lt;br /&gt;And so the big question: is this a philosophical piece of art, or is it an amusing Trojan with a cruel payload? There seem to be no social engineering involved, and Mr. Gage gives ample warning to anyone who downloads his game:&lt;/div&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;a href="http://2.bp.blogspot.com/_me98LqjebtU/SuoqgDo5A3I/AAAAAAAAAAc/1TTU0vIjNaI/s1600-h/lose3.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5398173833577956210" style="WIDTH: 340px; CURSOR: hand; HEIGHT: 289px" alt="" src="http://2.bp.blogspot.com/_me98LqjebtU/SuoqgDo5A3I/AAAAAAAAAAc/1TTU0vIjNaI/s320/lose3.jpg" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;And then again:&lt;/div&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;a href="http://3.bp.blogspot.com/_me98LqjebtU/Suot3f9lKEI/AAAAAAAAAAs/5RoUQHCMG-U/s1600-h/lose4.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5398177534852802626" style="WIDTH: 208px; CURSOR: hand; HEIGHT: 320px" alt="" src="http://3.bp.blogspot.com/_me98LqjebtU/Suot3f9lKEI/AAAAAAAAAAs/5RoUQHCMG-U/s320/lose4.jpg" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;Technically, however, a Trojan is defined as a piece of software that pretends to be a normal application while doing something entirely different from its intended purpose and without the user’s permission. We believe Loose/Loose falls (if not perfectly) into this definition and so we detect it as &lt;strong&gt;Application.OSX.Loselose.A&lt;/strong&gt;.&lt;br /&gt;&lt;br /&gt;We know he has completely declared the games intentions, but it’s too easy to succumb to one’s curiosity and just play the game before understanding of what’s happening sinks in to our consciousness. And released in the wild, taken out of the context the author intended it to be, it is not hard to imagine someone getting aversely affected by the payload (and getting your data deleted is about as averse as it can get). Bottom line, it’s better to be strict when your important files are concerned.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1155203086394184661-7415067981696301601?l=blog.iantivirus.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/7415067981696301601'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/7415067981696301601'/><link rel='alternate' type='text/html' href='http://blog.iantivirus.com/2009/10/entertainment-in-exchange-for-loss-of.html' title='Entertainment in exchange for loss of data!'/><author><name>Mylene Villacorte</name><uri>http://www.blogger.com/profile/07329643360109257929</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10838500839504016865'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_me98LqjebtU/SuouVxbvf9I/AAAAAAAAAA0/lj3rDWaDUMQ/s72-c/lose1.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-1155203086394184661.post-8190842073604157344</id><published>2009-09-10T17:23:00.000-07:00</published><updated>2009-09-11T13:57:51.140-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='snow leopard'/><category scheme='http://www.blogger.com/atom/ns#' term='adobe'/><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerabilities'/><title type='text'>Apple Provides an Update for Snow Leopard</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_lqswCgKLeDU/SqmhUD34tuI/AAAAAAAAAGo/H79DuaCNcFo/s1600-h/snow_leopard.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 200px;" src="http://4.bp.blogspot.com/_lqswCgKLeDU/SqmhUD34tuI/AAAAAAAAAGo/H79DuaCNcFo/s200/snow_leopard.jpg" alt="" id="BLOGGER_PHOTO_ID_5380008595879933666" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://support.apple.com/kb/DL930"&gt;Mac OS X 10.6.1&lt;/a&gt; was released earlier today which includes general operating system fixes that improves the compatibility, stability, and security of your Mac. The most notable among the fixes in 10.6.1 is an update to the Adobe Flash Player plugin that comes with the 1st release of Snow Leopard, which as many of us may have noticed, &lt;a href="http://www.computerworld.com/s/article/9137481/Snow_Leopard_downgrades_Flash_to_vulnerable_version"&gt;have downgraded the version of Adobe Flash Player&lt;/a&gt; after installation resulting into your Mac to have a vulnerable copy of the Flash player.&lt;br /&gt;&lt;br /&gt;Adobe posted a few days ago in its &lt;a href="http://www.adobe.com/support/security/bulletins/apsb09-10.html"&gt;Security Bulletin&lt;/a&gt; all the details about this vulnerability, and how you can update to the latest version of Flash Player. If you haven't done so, then we highly recommend to update your Snow Leopard's Flash to 10.0.32.18, which is the latest version. Just choose  &lt;span style="font-weight: bold;"&gt;Sofware Update&lt;/span&gt; from the &lt;strong&gt;Apple Logo &lt;/strong&gt;menu to check for available updates via the Internet, and choose this update for a safer browsing experience.&lt;strong&gt;&lt;/strong&gt;&lt;strong&gt;&lt;/strong&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1155203086394184661-8190842073604157344?l=blog.iantivirus.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/8190842073604157344'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/8190842073604157344'/><link rel='alternate' type='text/html' href='http://blog.iantivirus.com/2009/09/apple-provides-update-for-snow-leopard.html' title='Apple Provides an Update for Snow Leopard'/><author><name>Erwin Varona</name><uri>http://www.blogger.com/profile/08398258419133331070</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='02305845984697575807'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_lqswCgKLeDU/SqmhUD34tuI/AAAAAAAAAGo/H79DuaCNcFo/s72-c/snow_leopard.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-1155203086394184661.post-1332108988700762455</id><published>2009-08-25T16:18:00.000-07:00</published><updated>2009-08-25T23:33:34.148-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='2009 threats'/><category scheme='http://www.blogger.com/atom/ns#' term='RSPlug'/><title type='text'>More Variants of RSPlug Discovered</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_lqswCgKLeDU/SpR7enSpMGI/AAAAAAAAAGg/2PD578m9FuU/s1600-h/mac_alert.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 200px; height: 163px;" src="http://2.bp.blogspot.com/_lqswCgKLeDU/SpR7enSpMGI/AAAAAAAAAGg/2PD578m9FuU/s200/mac_alert.jpg" alt="" id="BLOGGER_PHOTO_ID_5374056021233315938" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;PC Tools' Malware Research Team recently discovered quite a few variants of a DNS changing trojan called RSPlug in the wild.&lt;br /&gt;&lt;br /&gt;Three strains of this ubiquitous Trojan have been discovered masquerading as a Foxit Reader PDF viever, a Quicktime Pro update, and a Flash Player installer. PC Tools iAntivirus detect these variants as Trojan.OSX.RSPlug.O, Trojan.OSX.RSPlug.P, and Trojan.OSX.RSPlug.Q respectively.&lt;br /&gt;&lt;br /&gt;Like all the other variants, these newly discovered trojan variants pose as legitimate software in order to lure users to download and run them on their computer.  This will enable the trojan to change the DNS settings on the compromised computer and redirect the user to phishing websites and such.&lt;br /&gt;&lt;br /&gt;We highly advise iAntivirus users to Smart Update for the latest protection in Mac threats, and to avoid untrusted websites in the Internet, which may harbor such malicious files.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1155203086394184661-1332108988700762455?l=blog.iantivirus.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/1332108988700762455'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/1332108988700762455'/><link rel='alternate' type='text/html' href='http://blog.iantivirus.com/2009/08/more-variants-of-rsplug-discovered.html' title='More Variants of RSPlug Discovered'/><author><name>Erwin Varona</name><uri>http://www.blogger.com/profile/08398258419133331070</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='02305845984697575807'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_lqswCgKLeDU/SpR7enSpMGI/AAAAAAAAAGg/2PD578m9FuU/s72-c/mac_alert.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-1155203086394184661.post-8730371963156524907</id><published>2009-07-21T23:36:00.000-07:00</published><updated>2009-07-22T00:34:59.656-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='2009 threats'/><category scheme='http://www.blogger.com/atom/ns#' term='RSPlug'/><title type='text'>Say No to Software Piracy</title><content type='html'>A new variant of the RSPlug Trojan horse, aptly named by PC Tools as Trojan.OSX.RSPlug.N, was spotted in a &lt;a href="http://en.wikipedia.org/wiki/Warez"&gt;warez&lt;/a&gt; web site masquerading as a keygen (serial number generator) for the Mac OS X Leopard.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_lqswCgKLeDU/Sma2uc9HwXI/AAAAAAAAAFg/DeWjfIRZmrE/s1600-h/rsplug.n.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 322px; height: 400px;" src="http://1.bp.blogspot.com/_lqswCgKLeDU/Sma2uc9HwXI/AAAAAAAAAFg/DeWjfIRZmrE/s400/rsplug.n.png" alt="" id="BLOGGER_PHOTO_ID_5361173315593945458" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Unwary Mac users looking to save a few bucks on a pirated Mac OS X will most likely get infected by this Trojan horse, but if you're keen enough, you'll notice that this keygen, particularly the details in the web site as seen in the picture above, is pretty odd and dubious. First, Mac OS X Leopard was never available for AMD processors as it only supports Intel, and PowerPC processors. Second, it doesn't make use of a serial number, so this keygen would be of no use for users who doesn't want to pay for legitimate software. &lt;span style="font-style: italic;"&gt;Ehem&lt;/span&gt;, we shouldn't be supporting software piracy and downloading keygens in the first place.&lt;br /&gt;&lt;br /&gt;Anyway, this new version of RSPlug is essentially the same in terms of function like the other variants. Read a detailed description of the RSPlug trojan &lt;a href="http://blog.iantivirus.com/2009/06/from-porn-and-warez-to-game-sites.html"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;PC Tools iAntivirus has updated their database to protect its users from Trojan.OSX.RSPlug.N, so Smart Update now for utmost protection on the latest threats!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1155203086394184661-8730371963156524907?l=blog.iantivirus.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/8730371963156524907'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/8730371963156524907'/><link rel='alternate' type='text/html' href='http://blog.iantivirus.com/2009/07/say-no-to-software-piracy.html' title='Say No to Software Piracy'/><author><name>Erwin Varona</name><uri>http://www.blogger.com/profile/08398258419133331070</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='02305845984697575807'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_lqswCgKLeDU/Sma2uc9HwXI/AAAAAAAAAFg/DeWjfIRZmrE/s72-c/rsplug.n.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-1155203086394184661.post-7806845566215457737</id><published>2009-07-18T16:47:00.000-07:00</published><updated>2009-07-18T17:17:31.507-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerabilities'/><category scheme='http://www.blogger.com/atom/ns#' term='Firefox'/><title type='text'>Mozilla Firefox Memory Corruption Vulnerability Fixed in 3.5.1</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_lqswCgKLeDU/SmJgUe63UsI/AAAAAAAAAFY/ZD_gmNk98dM/s1600-h/firefox_logo.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 102px; height: 105px;" src="http://1.bp.blogspot.com/_lqswCgKLeDU/SmJgUe63UsI/AAAAAAAAAFY/ZD_gmNk98dM/s400/firefox_logo.png" alt="" id="BLOGGER_PHOTO_ID_5359952411537920706" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Mozilla recently announced a &lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-41.html"&gt;bug in Firefox 3.5's Just-In-Time (JIT) compiler&lt;/a&gt; in which an error in its escape() function could lead the browser into a corrupt state, thereby allowing attackers to run arbitrary code such as installing malware.&lt;br /&gt;&lt;br /&gt;Earlier versions of Firefox which does not support the JIT compiler are not affected. However, this is considered a critical vulnerability as there are already reports of an &lt;a href="http://www.h-online.com/security/First-Zero-Day-Exploit-for-Firefox-3-5--/news/113761"&gt;exploit code for this security flaw in the wild&lt;/a&gt;. Mozilla, after learning about this security issue, quickly posted a &lt;a href="http://blog.mozilla.com/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/"&gt;workaround solution&lt;/a&gt; until a fix has been provided.&lt;br /&gt;&lt;br /&gt;Fortunately for us Firefox users, Mozilla has already released Firefox 3.5.1 to resolve this issue. PC Tools' Malware Research Team highly advises users to update to this new version ASAP.&lt;br /&gt;&lt;br /&gt;Mozilla Firefox 3.5.1 can be downloaded &lt;a href="http://www.mozilla.com/en-US/firefox/3.5.1/"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1155203086394184661-7806845566215457737?l=blog.iantivirus.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/7806845566215457737'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/7806845566215457737'/><link rel='alternate' type='text/html' href='http://blog.iantivirus.com/2009/07/mozilla-firefox-memory-corruption.html' title='Mozilla Firefox Memory Corruption Vulnerability Fixed in 3.5.1'/><author><name>Erwin Varona</name><uri>http://www.blogger.com/profile/08398258419133331070</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='02305845984697575807'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_lqswCgKLeDU/SmJgUe63UsI/AAAAAAAAAFY/ZD_gmNk98dM/s72-c/firefox_logo.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-1155203086394184661.post-3773195905012747754</id><published>2009-07-09T16:16:00.000-07:00</published><updated>2009-07-09T16:53:50.979-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Safari'/><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerabilities'/><title type='text'>Safari Update Now Available for Download</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_lqswCgKLeDU/SlZ7Byc7uZI/AAAAAAAAAFQ/R2qgN6VpldI/s1600-h/safari.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 128px; height: 128px;" src="http://3.bp.blogspot.com/_lqswCgKLeDU/SlZ7Byc7uZI/AAAAAAAAAFQ/R2qgN6VpldI/s400/safari.png" alt="" id="BLOGGER_PHOTO_ID_5356604077456996754" border="0" /&gt;&lt;/a&gt;Apple has released Safari version 4.0.2 for Mac OSX 10.4 and 10.5, Windows XP, Vista, and 7 beta which, according to the release notes,  improves the stability of its Nitro JavaScript engine, and also includes two security fixes.&lt;br /&gt;&lt;br /&gt;The said security fixes addresses the issue on &lt;a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-1724"&gt;Webkit's handling on the parent and top objects&lt;/a&gt; which may result in a cross-site scripting attack when visiting a maliciously crafted website, as well as its &lt;a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-1725"&gt;handling of numeric character references&lt;/a&gt; which causes memory corruption. Apple has posted a knowledge base article on these two vulnerabilities, and more information can be found &lt;a href="http://support.apple.com/kb/HT3666"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;This 40MB update is available via Software Update, or by manual download in the Apple &lt;a href="http://www.apple.com/safari/download/"&gt;website&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1155203086394184661-3773195905012747754?l=blog.iantivirus.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/3773195905012747754'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/3773195905012747754'/><link rel='alternate' type='text/html' href='http://blog.iantivirus.com/2009/07/safari-update-now-available-for.html' title='Safari Update Now Available for Download'/><author><name>Erwin Varona</name><uri>http://www.blogger.com/profile/08398258419133331070</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='02305845984697575807'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_lqswCgKLeDU/SlZ7Byc7uZI/AAAAAAAAAFQ/R2qgN6VpldI/s72-c/safari.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-1155203086394184661.post-6911494153020448759</id><published>2009-07-02T22:39:00.000-07:00</published><updated>2009-07-08T23:51:06.048-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='2009 threats'/><category scheme='http://www.blogger.com/atom/ns#' term='RSPlug'/><title type='text'>Lady Gaga's Latest Album leads to Malware Download</title><content type='html'>The RSPlug trojan horse seems to be spawning quite rapidly the past few months. After only a few days when a variant of this trojan horse was spotted on a gaming website, our Malware Research Team discovered a newer variant of this threat lurking in a website offering free "music" downloads.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_lqswCgKLeDU/Sk2oiTN9sKI/AAAAAAAAAFI/EHTbFhoxirY/s1600-h/Picture+4.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 397px;" src="http://2.bp.blogspot.com/_lqswCgKLeDU/Sk2oiTN9sKI/AAAAAAAAAFI/EHTbFhoxirY/s400/Picture+4.png" alt="" id="BLOGGER_PHOTO_ID_5354120839241248930" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;This new variant, which iAntivirus detects as Trojan.OSX.RSPlug.M, disguises itself as one of the many music album downloads available in the website like Lady Gaga's latest album pictured above. All music album links in the website will lead Mac users to download disk images containing RSPlug.M. Windows users, however, are led to download its Windows executable counterpart which &lt;a href="http://www.pctools.com/internet-security/"&gt;PCTools Internet Security&lt;/a&gt; for Windows detects as Trojan.Alureon.a.&lt;br /&gt;&lt;br /&gt;This new variant exhibits the same behavior just like the others. The only notable difference is a slight modification in the code to evade Antivirus scanners.&lt;br /&gt;&lt;br /&gt;Mac users should be wary when downloading music from untrusted sources. It's also worth mentioning that digital music doesn't normally come as a disk image file (.dmg), and this alone should raise one's suspicion that the file being downloaded is not legit.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1155203086394184661-6911494153020448759?l=blog.iantivirus.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/6911494153020448759'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/6911494153020448759'/><link rel='alternate' type='text/html' href='http://blog.iantivirus.com/2009/07/lady-gagas-latest-album-leads-to.html' title='Lady Gaga&apos;s Latest Album leads to Malware Download'/><author><name>Erwin Varona</name><uri>http://www.blogger.com/profile/08398258419133331070</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='02305845984697575807'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_lqswCgKLeDU/Sk2oiTN9sKI/AAAAAAAAAFI/EHTbFhoxirY/s72-c/Picture+4.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-1155203086394184661.post-5940261641372478696</id><published>2009-06-25T17:43:00.000-07:00</published><updated>2009-07-08T23:51:32.522-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='2009 threats'/><category scheme='http://www.blogger.com/atom/ns#' term='RSPlug'/><title type='text'>From Porn and Warez to Game Sites</title><content type='html'>The Malware Research Team found a new variant of the Trojan.OSX.RSPlug threat masquerading as a gaming software. Previous versions of this threat were mostly found on sleazy porn, and warez sites. Malware writers responsible for this threat took a different route this time targeting unsuspecting gamers.&lt;br /&gt;&lt;br /&gt;The new variant which PC Tools iAntivirus detects as Trojan.OSX.RSPlug.k were discovered in this website:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_lqswCgKLeDU/SkQh1Xnu-HI/AAAAAAAAAEY/_CNrU-nizqA/s1600-h/Picture+1.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 266px;" src="http://2.bp.blogspot.com/_lqswCgKLeDU/SkQh1Xnu-HI/AAAAAAAAAEY/_CNrU-nizqA/s400/Picture+1.png" alt="" id="BLOGGER_PHOTO_ID_5351439457980446834" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;The threat is disguised as a DMG (Mac Disk Image) file of a game whose file name is as follows:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_lqswCgKLeDU/SkQjDcW2EoI/AAAAAAAAAEg/tKIA8cRk-6k/s1600-h/Picture+3.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 157px; height: 107px;" src="http://2.bp.blogspot.com/_lqswCgKLeDU/SkQjDcW2EoI/AAAAAAAAAEg/tKIA8cRk-6k/s400/Picture+3.png" alt="" id="BLOGGER_PHOTO_ID_5351440799281582722" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Clicking on the link pointing to the said malicious file will download it onto the unsuspecting user's computer and is automatically executed.&lt;br /&gt;&lt;br /&gt;Like most RSPlug variants, this one also displays the MacCinema installation window:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_lqswCgKLeDU/SkQjgzVtLcI/AAAAAAAAAEo/R_OExcgCdHc/s1600-h/Picture+4.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 285px;" src="http://3.bp.blogspot.com/_lqswCgKLeDU/SkQjgzVtLcI/AAAAAAAAAEo/R_OExcgCdHc/s400/Picture+4.png" alt="" id="BLOGGER_PHOTO_ID_5351441303667027394" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;This threat pretends to install a legitimate program on the user's computer, but silently runs malicious BASH scripts that are packaged in the DMG file in the background. Moreover, these scripts are found to be encoded in UUencode using the SED command.&lt;br /&gt;&lt;br /&gt;Here's a screen capture of one of the said BASH scripts:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_lqswCgKLeDU/SkQ-tgARLRI/AAAAAAAAAE4/Iuc3B9tysfk/s1600-h/Picture+5.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 387px;" src="http://2.bp.blogspot.com/_lqswCgKLeDU/SkQ-tgARLRI/AAAAAAAAAE4/Iuc3B9tysfk/s400/Picture+5.png" alt="" id="BLOGGER_PHOTO_ID_5351471208629087506" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;These scripts are further encoded (in three layers), and further decoding the script will reveal a PERL script with a HTTP GET request for another PERL script called generator.pl:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_lqswCgKLeDU/SkRA5KmM9SI/AAAAAAAAAFA/8DIt4KOZ8tA/s1600-h/Picture+6.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 366px;" src="http://3.bp.blogspot.com/_lqswCgKLeDU/SkRA5KmM9SI/AAAAAAAAAFA/8DIt4KOZ8tA/s400/Picture+6.png" alt="" id="BLOGGER_PHOTO_ID_5351473608064300322" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Like the previous variants, the PERL script that is being retrieved via the HTTP GET request also changes the user's DNS server using SCUTIL commands resulting into the user being redirected to phishing or malicious sites.&lt;br /&gt;&lt;br /&gt;PC Tools iAntivirus recommends its users to Smart Update to our latest database for full protection against this threat.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1155203086394184661-5940261641372478696?l=blog.iantivirus.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/5940261641372478696'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/5940261641372478696'/><link rel='alternate' type='text/html' href='http://blog.iantivirus.com/2009/06/from-porn-and-warez-to-game-sites.html' title='From Porn and Warez to Game Sites'/><author><name>Erwin Varona</name><uri>http://www.blogger.com/profile/08398258419133331070</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='02305845984697575807'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_lqswCgKLeDU/SkQh1Xnu-HI/AAAAAAAAAEY/_CNrU-nizqA/s72-c/Picture+1.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-1155203086394184661.post-5459571256037304277</id><published>2009-02-12T23:31:00.000-08:00</published><updated>2009-02-12T23:33:18.579-08:00</updated><title type='text'>iAntiVirus in the Boston Globe</title><content type='html'>Came across &lt;a href="http://www.boston.com/business/technology/articles/2009/02/12/dont_give_crooks_a_key_to_your_computer/"&gt;this&lt;/a&gt; article yesterday which mentions iAntiVirus.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1155203086394184661-5459571256037304277?l=blog.iantivirus.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/5459571256037304277'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/5459571256037304277'/><link rel='alternate' type='text/html' href='http://blog.iantivirus.com/2009/02/iantivirus-in-boston-globe.html' title='iAntiVirus in the Boston Globe'/><author><name>NSArchitect</name><uri>http://www.blogger.com/profile/10052529130215654134</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='14683075901525580227'/></author></entry><entry><id>tag:blogger.com,1999:blog-1155203086394184661.post-4250651750141408947</id><published>2009-02-12T23:29:00.001-08:00</published><updated>2009-02-12T23:30:27.756-08:00</updated><title type='text'>Apple security update available</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_7dsFHfVnnA8/SZUhiqqwdcI/AAAAAAAAACo/uGp3FRQAetE/s1600-h/SUP.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 233px;" src="http://2.bp.blogspot.com/_7dsFHfVnnA8/SZUhiqqwdcI/AAAAAAAAACo/uGp3FRQAetE/s320/SUP.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5302181015751521730" /&gt;&lt;/a&gt;&lt;br /&gt;Please run software update to get it right away!&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1155203086394184661-4250651750141408947?l=blog.iantivirus.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/4250651750141408947'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/4250651750141408947'/><link rel='alternate' type='text/html' href='http://blog.iantivirus.com/2009/02/apple-security-update-available.html' title='Apple security update available'/><author><name>NSArchitect</name><uri>http://www.blogger.com/profile/10052529130215654134</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='14683075901525580227'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_7dsFHfVnnA8/SZUhiqqwdcI/AAAAAAAAACo/uGp3FRQAetE/s72-c/SUP.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-1155203086394184661.post-3309960988637436996</id><published>2009-01-21T18:50:00.001-08:00</published><updated>2009-01-21T18:50:58.817-08:00</updated><title type='text'>New database</title><content type='html'>Hi everyone,&lt;br /&gt;&lt;br /&gt;We've just released a new version of the virus database for iAntiVirus.&lt;br /&gt;If you haven't got Smart Update set to automatic then please run it manually to ensure you have the latest protection available!&lt;br /&gt;&lt;br /&gt;Detections - updated/new:&lt;br /&gt;Trojan.OSX.DNSChanger.E&lt;br /&gt;Exploit. Trojan.MacOS.Tweesh.a&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1155203086394184661-3309960988637436996?l=blog.iantivirus.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/3309960988637436996'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/3309960988637436996'/><link rel='alternate' type='text/html' href='http://blog.iantivirus.com/2009/01/new-database.html' title='New database'/><author><name>NSArchitect</name><uri>http://www.blogger.com/profile/10052529130215654134</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='14683075901525580227'/></author></entry><entry><id>tag:blogger.com,1999:blog-1155203086394184661.post-6419330326082341118</id><published>2009-01-21T16:25:00.000-08:00</published><updated>2009-01-21T16:32:16.942-08:00</updated><title type='text'>QuickTime 7.6</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_7dsFHfVnnA8/SXe-gzqE7lI/AAAAAAAAACg/3Rz53hRI5V0/s1600-h/qt76.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 16px; height: 16px;" src="http://1.bp.blogspot.com/_7dsFHfVnnA8/SXe-gzqE7lI/AAAAAAAAACg/3Rz53hRI5V0/s320/qt76.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5293909357829090898" /&gt;&lt;/a&gt;&lt;br /&gt;Apple has released an update for QuickTime, amongst the changes are security fixes.&lt;div&gt;Please run Apple Software Update to get it!&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This update addresses heap overflows, buffer overflows, memory corruption issues and others - all of which may lead to arbitrary code execution.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Official information &lt;a href="http://support.apple.com/kb/HT3403"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1155203086394184661-6419330326082341118?l=blog.iantivirus.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/6419330326082341118'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/6419330326082341118'/><link rel='alternate' type='text/html' href='http://blog.iantivirus.com/2009/01/quicktime-76.html' title='QuickTime 7.6'/><author><name>NSArchitect</name><uri>http://www.blogger.com/profile/10052529130215654134</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='14683075901525580227'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_7dsFHfVnnA8/SXe-gzqE7lI/AAAAAAAAACg/3Rz53hRI5V0/s72-c/qt76.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-1155203086394184661.post-3684689973704137437</id><published>2009-01-07T17:39:00.001-08:00</published><updated>2009-01-07T17:41:23.697-08:00</updated><title type='text'>iAntiVirus v1.3 is available</title><content type='html'>iAntiVirus v1.3 has passed testing and is now available!&lt;div&gt;You can grab it from &lt;a href="http://www.iantivirus.com/download"&gt;here&lt;/a&gt; or run a Smart Update to upgrade.&lt;/div&gt;&lt;div&gt;Changes in this version have been mentioned in a &lt;a href="http://blog.iantivirus.com/2008/12/iantivirus-v13-in-testing.html"&gt;previous post&lt;/a&gt;.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1155203086394184661-3684689973704137437?l=blog.iantivirus.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/3684689973704137437'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/3684689973704137437'/><link rel='alternate' type='text/html' href='http://blog.iantivirus.com/2009/01/iantivirus-v13-is-available.html' title='iAntiVirus v1.3 is available'/><author><name>NSArchitect</name><uri>http://www.blogger.com/profile/10052529130215654134</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='14683075901525580227'/></author></entry><entry><id>tag:blogger.com,1999:blog-1155203086394184661.post-3869916102882088689</id><published>2008-12-15T16:01:00.000-08:00</published><updated>2008-12-15T17:07:47.724-08:00</updated><title type='text'>Mac OS X Update - 10.5.6</title><content type='html'>Apple has released an update for OS X - it addresses several severe security issues.  &lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-weight: bold;"&gt;Please run a Software Update and grab it today!&lt;/span&gt;&lt;div&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_7dsFHfVnnA8/SUb9CrMexHI/AAAAAAAAACY/x1jMZWc8Ht8/s1600-h/update.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 294px; height: 320px;" src="http://1.bp.blogspot.com/_7dsFHfVnnA8/SUb9CrMexHI/AAAAAAAAACY/x1jMZWc8Ht8/s320/update.png" alt="" id="BLOGGER_PHOTO_ID_5280185835535123570" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-weight: bold;"&gt;Security Issues addressed&lt;/div&gt;&lt;ul&gt;&lt;li&gt;Apple Type Services (ATS) server PDF embedded font handling issue (CVE-ID: CVE-2008-4236)&lt;/li&gt;&lt;li&gt;Arbitrary code execution in BOM (CVE-ID: CVE-2008-4217)&lt;/li&gt;&lt;li&gt;Heap buffer overflow in CoreGraphics' handling of color spaces (CVE-ID: &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3623"&gt;CVE-2008-3623&lt;/a&gt;)&lt;/li&gt;&lt;li&gt;Possible user credential disclosure in Safari (CVE-ID: &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3170"&gt;CVE-2008-3170&lt;/a&gt;)&lt;/li&gt;&lt;li&gt;Enhanced download validation capability, previously warnings were not displayed for all unsafe download content types, this allowed for arbitrary code/command execution (CVE-ID: CVE-2008-4234)&lt;/li&gt;&lt;li&gt;Multiple vulnerabilities in the Adobe Flash player plugin (CVE-IDs: &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4818"&gt;CVE-2008-4818&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4819"&gt;CVE-2008-4819&lt;/a&gt;, CVE-2008-4820, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4821"&gt;CVE-2008-4821&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4822"&gt;CVE-2008-4822&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4823"&gt;CVE-2008-4823&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4824"&gt;CVE-2008-4824&lt;/a&gt;)&lt;/li&gt;&lt;li&gt;Local privilege escalation issue due to integer overflows in the kernel's i386_get_ldt and i386_get_ldt system calls (affects Intel based machines only) (CVE-ID: CVE-2008-4218)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Infinite loop when an exception occurs in a program (or dylib) which resides on an NFS share (CVE-ID: CVE-2008-4219)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Integer overflow in the LibSystem inet_net_pton function -&gt; this could affect any program which uses that function (CVE-ID: CVE-2008-4220)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Memory corruption issue in the strptime function of LibSystem (CVE-ID: CVE-2008-4221)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Multiple integer overflows in the strfmon function of LibSystem (CVE-ID: &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1391"&gt;CVE-2008-1391&lt;/a&gt;)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Per host configuration in managed client system installs sometimes incorrectly identifies the system (CVE-ID: CVE-2008-4237)&lt;/li&gt;&lt;li&gt;natd infinite loop due to a maliciously crafted TCP packet -&gt; only affects systems with the  Internet Sharing service enabled (CVE-ID: CVE-2008-4222)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Authentication bypass in Podcast Producer (OS X server only) (CVE-ID: CVE-2008-4223)&lt;/li&gt;&lt;li&gt;Input validation issue when handling malformed UDF volumes, ISO files.  Opening a malformed volume may cause an unexpected syustem shutdown. (CVE-ID: CVE-2008-4224)&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Information from Apple &lt;a href="http://support.apple.com/kb/HT3338"&gt;here&lt;/a&gt; .&lt;br /&gt;&lt;br /&gt;Note: All CVE IDs will be linked to their respective pages once they become available.&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1155203086394184661-3869916102882088689?l=blog.iantivirus.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/3869916102882088689'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/3869916102882088689'/><link rel='alternate' type='text/html' href='http://blog.iantivirus.com/2008/12/mac-os-x-update-1056.html' title='Mac OS X Update - 10.5.6'/><author><name>NSArchitect</name><uri>http://www.blogger.com/profile/10052529130215654134</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='14683075901525580227'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_7dsFHfVnnA8/SUb9CrMexHI/AAAAAAAAACY/x1jMZWc8Ht8/s72-c/update.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-1155203086394184661.post-7553540441803791580</id><published>2008-12-10T16:31:00.001-08:00</published><updated>2008-12-10T16:33:34.997-08:00</updated><title type='text'>Snow Leopard</title><content type='html'>Just a quick note to let you all know that we're testing iAntiVirus on Snow Leopard, and apart from a minor installer issue there have been no problems so far! :)&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1155203086394184661-7553540441803791580?l=blog.iantivirus.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/7553540441803791580'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/7553540441803791580'/><link rel='alternate' type='text/html' href='http://blog.iantivirus.com/2008/12/snow-leopard.html' title='Snow Leopard'/><author><name>NSArchitect</name><uri>http://www.blogger.com/profile/10052529130215654134</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='14683075901525580227'/></author></entry><entry><id>tag:blogger.com,1999:blog-1155203086394184661.post-1067361217321961607</id><published>2008-12-10T16:22:00.001-08:00</published><updated>2008-12-10T16:42:20.614-08:00</updated><title type='text'>iAntiVirus v1.3 - in testing</title><content type='html'>Hi everyone,&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;It's been quite a while since I've posted on this blog, but that's because I've been busy working on the next version of iAntVirus!  The upcoming version has interface improvements, a smaller footprint, and a number of under-the-hood enhancements which will allow really cool additions and new features further down the line... &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Here are some screenshots:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 227px;" src="http://2.bp.blogspot.com/_7dsFHfVnnA8/SUBeDXkGdtI/AAAAAAAAAB4/Ymjnu9sMgM0/s320/eula.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5278322175236273874" /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_7dsFHfVnnA8/SUBe2xfSJ0I/AAAAAAAAACI/eeSQLS7uSFc/s1600-h/main.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 238px;" src="http://4.bp.blogspot.com/_7dsFHfVnnA8/SUBe2xfSJ0I/AAAAAAAAACI/eeSQLS7uSFc/s320/main.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5278323058368718658" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_7dsFHfVnnA8/SUBe3sqVdvI/AAAAAAAAACQ/T20f0bh6pHo/s1600-h/history.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 238px;" src="http://2.bp.blogspot.com/_7dsFHfVnnA8/SUBe3sqVdvI/AAAAAAAAACQ/T20f0bh6pHo/s320/history.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5278323074252764914" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1155203086394184661-1067361217321961607?l=blog.iantivirus.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/1067361217321961607'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/1067361217321961607'/><link rel='alternate' type='text/html' href='http://blog.iantivirus.com/2008/12/iantivirus-v13-in-testing.html' title='iAntiVirus v1.3 - in testing'/><author><name>NSArchitect</name><uri>http://www.blogger.com/profile/10052529130215654134</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='14683075901525580227'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_7dsFHfVnnA8/SUBeDXkGdtI/AAAAAAAAAB4/Ymjnu9sMgM0/s72-c/eula.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-1155203086394184661.post-1513397802592218093</id><published>2008-11-02T21:16:00.000-08:00</published><updated>2008-11-02T21:21:05.736-08:00</updated><title type='text'>iAntiVirus 1.2 available</title><content type='html'>We've just released iAntiVirus v1.2 on Smart Update and on the &lt;a href="http://www.iantivirus.com/"&gt;website&lt;/a&gt;.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;v1.2 contains the following:&lt;/div&gt;&lt;div&gt;- Addressed time machine incompatibility issue&lt;/div&gt;&lt;div&gt;- Enhanced quarantine functionality (now much faster)&lt;/div&gt;&lt;div&gt;- Various other enhancements&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Please get the update and leave your comments on the &lt;a href="http://www.pctools.com/forum/forumdisplay.php?f=66"&gt;forum&lt;/a&gt;, thanks!&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1155203086394184661-1513397802592218093?l=blog.iantivirus.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/1513397802592218093'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/1513397802592218093'/><link rel='alternate' type='text/html' href='http://blog.iantivirus.com/2008/11/iantivirus-12-available.html' title='iAntiVirus 1.2 available'/><author><name>NSArchitect</name><uri>http://www.blogger.com/profile/10052529130215654134</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='14683075901525580227'/></author></entry><entry><id>tag:blogger.com,1999:blog-1155203086394184661.post-7955630035686627516</id><published>2008-10-10T03:18:00.000-07:00</published><updated>2008-10-10T03:20:40.218-07:00</updated><title type='text'>iAntiVirus v1.1 is now available!</title><content type='html'>&lt;p&gt;iAntiVirus v1.1 was released recently.  Please run a Smart Update or download the package from &lt;a href="http://iantivirus.com"&gt;iantivirus.com &lt;/a&gt;&lt;/p&gt;&lt;p&gt;More information available on the &lt;a href="http://www.pctools.com/forum/showthread.php?t=54191"&gt;forum&lt;/a&gt;.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1155203086394184661-7955630035686627516?l=blog.iantivirus.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/7955630035686627516'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/7955630035686627516'/><link rel='alternate' type='text/html' href='http://blog.iantivirus.com/2008/10/iantivirus-v11-is-now-available.html' title='iAntiVirus v1.1 is now available!'/><author><name>NSArchitect</name><uri>http://www.blogger.com/profile/10052529130215654134</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='14683075901525580227'/></author></entry><entry><id>tag:blogger.com,1999:blog-1155203086394184661.post-5118481406095201509</id><published>2008-10-02T01:09:00.000-07:00</published><updated>2008-10-02T01:35:58.717-07:00</updated><title type='text'>iAntiVirus 1.1 is coming!</title><content type='html'>iAntiVirus v1.1 is currently undergoing internal testing.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Some changes in v1.1:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;- New scheduled scan type - allows you to specify a scheduled normal or quick scan.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;- Updated scan engine which should improve scan speed (it was already fast! :)) and resolves an issue reported on the &lt;a href="http://www.pctools.com/forum/forumdisplay.php?f=66"&gt;forum&lt;/a&gt;.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;- New database with updated signatures and new signatures for 3 exploits .&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;- Scan progress now displays more information about child objects being scanned (e.g in v1.0 status might say "Scanning /Users/pctools/Downloads/huge_file.zip" for a long time, in v1.1 it will be displayed as "Scanning /Users/pctools/Downloads/huge_file.zip//(updates for every filename in the archive)".&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;- Scan complete alert - if you've kept the dock icon hidden, a slideup will alert you once a scan has completed (if the dock icon is visible then it will simply bounce, as previously).&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;We'll make an announcement here once v1.1 has been confirmed ok by our QA team, so please check back shortly! &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1155203086394184661-5118481406095201509?l=blog.iantivirus.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/5118481406095201509'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/5118481406095201509'/><link rel='alternate' type='text/html' href='http://blog.iantivirus.com/2008/10/iantivirus-11-is-coming.html' title='iAntiVirus 1.1 is coming!'/><author><name>NSArchitect</name><uri>http://www.blogger.com/profile/10052529130215654134</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='14683075901525580227'/></author></entry><entry><id>tag:blogger.com,1999:blog-1155203086394184661.post-4821477217535478946</id><published>2008-09-24T22:18:00.001-07:00</published><updated>2008-09-24T22:21:18.551-07:00</updated><title type='text'>iAntiVirus 1.0</title><content type='html'>Hi everyone,&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;iAntiVirus 1.0 has passed internal testing and is now available on Smart Update.&lt;/div&gt;&lt;div&gt;Please run Smart Update to get this release!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Thanks to everyone who helped test beta 3.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1155203086394184661-4821477217535478946?l=blog.iantivirus.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/4821477217535478946'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/4821477217535478946'/><link rel='alternate' type='text/html' href='http://blog.iantivirus.com/2008/09/iantivirus-10.html' title='iAntiVirus 1.0'/><author><name>NSArchitect</name><uri>http://www.blogger.com/profile/10052529130215654134</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='14683075901525580227'/></author></entry><entry><id>tag:blogger.com,1999:blog-1155203086394184661.post-1746061788175203241</id><published>2008-09-23T17:40:00.000-07:00</published><updated>2008-09-23T17:43:32.644-07:00</updated><title type='text'>iAntiVirus 1.0 (non-beta!)</title><content type='html'>iAntiVirus 1.0 - not a beta, but the full release is currently in internal testing and should be confirmed ok for public use shortly.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Thanks to everyone who gave comments, suggestions and reported issues ( well 1 issue! :) ) with iAntiVirus 1.0 beta 3.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Once the full 1.0 release has been confirmed ok, it will be announced here first so please check back shortly.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1155203086394184661-1746061788175203241?l=blog.iantivirus.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/1746061788175203241'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1155203086394184661/posts/default/1746061788175203241'/><link rel='alternate' type='text/html' href='http://blog.iantivirus.com/2008/09/iantivirus-10-non-beta.html' title='iAntiVirus 1.0 (non-beta!)'/><author><name>NSArchitect</name><uri>http://www.blogger.com/profile/10052529130215654134</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='14683075901525580227'/></author></entry></feed>