Defend what you create

Other Resources

Close

Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Mac.Trojan.VSearch.7

Added to the Dr.Web virus database: 2016-02-29

Virus description added:

SHA1 c206a19d7fb4a7dbabe3f1a0d9bfa8476356ecb2

A Trojan for OS X that is installed by Mac.Trojan.VSearch.4.

It includes the following components:

DemoInjector.app
change_net_settings.sh
com.pref.net-preferences.plist
com.pref.preferences.plist
install_Injector.sh
readme_inj.txt
uninstall_injector.sh

When the Trojan is installed, it creates a user account that has a random username and the “test. ID = 401” password that is not displayed in the OS X Welcome dialog, and redirects HTTP traffic from all interfaces to the local port 9882. Mac.Trojan.VSearch.7 uses this port to launch a proxy server that injects a JavaScript script into all webpages browsed by the victim. The Trojan receives the script via the URL that looks as follows:

 http://domain/sm/mu?id=machine_id&d=dist_channel_id&cl=click_id

The Trojan gets the parameters necessary for its normal work from /Library/Preferences/com.appName.preferences.plist, where appName is an application name generated randomly.

The script injected into webpages displays advertisements, sends statistics to the server, and collects the user’s Web search queries transmitting them to servers, a list of which is incorporated into the script:

www.google.
www.bing.
.ask.
search.whitesmoke
thesmartsearch

News about the Trojan

Curing recommendations


macOS

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number

The Russian developer of Dr.Web anti-viruses
Doctor Web has been developing anti-virus software since 1992
Dr.Web is trusted by users around the world in 200+ countries
The company has delivered an anti-virus as a service since 2007
24/7 tech support

Dr.Web © Doctor Web
2003 — 2021

Doctor Web is the Russian developer of Dr.Web anti-virus software. Dr.Web anti-virus software has been developed since 1992.

2-12А, 3rd street Yamskogo polya, Moscow, Russia, 125124