How to remove OSX.Trojan.iServices.A, iServices.B
OK, so you found your way to Blorge after downloading and installing the iWork ‘09 (OSX.Trojan.iServices.A) trojan to get a shot of morning-after medicine and now you once again find yourself itchy in places you did not know could itch (pirated Adobe Photoshop CS4, didn’t ya). Come on in—we have got the stuff you need.
Late, late last night Nevada (USA) time, the guys and gals at SecureMac finished updating of their iServices Trojan Removal Tool and released version 1.1. Because the company has not updated their site to reflect the changes (found via MacUpdate), here is a slice of revised spin from the ReadMe file:
This tool is in response to a new spyware trojan horse (OSX.Trojan.iServices.A and OSX.Trojan.iServices.B) in the wild that comes bundled with pirated copies of software, such as iWork 09 and Adobe Photoshop CS4.
See also:
— Intego discovers iServices trojan in Photoshop serializer
— How to remove the iWork ‘09 trojan
— Pirated iWork 09 installation may infect thieves with trojan
— VirusBarrier X5
What was that? “Quit the yackety yack and give us the link”?
Well, OK. To get your very own copy of iWorkServices Trojan Removal Tool v1.1, wash your hands and then click here.
Related Posts:

This tool is in response to a new spyware trojan horse (OSX.Trojan.iServices.A and OSX.Trojan.iServices.B) in the wild that comes bundled with pirated copies of software, such as iWork 09 and Adobe Photoshop CS4.
January 30th, 2009
A simple question: As I understand it the “iWorkServices Trojan Removal Tool v1.1″ (and v1.2) remove the trojan and stops it from doing any further damage. Are you all cured after that or does it remain any security problems with the actual system? (i.e do you need to re-install a clean OS to be safe?)
January 30th, 2009
To date, these two trojans have only been observed facilitating DDoS network denial attacks (on somebody, somewhere, but not spreading itself). Further, how and where the malware installs itself and then moves to establish its DDoS attack mechanism is pretty well documented. However, cured is as cured does, so the only way to be 100% sure is scrub all of your discs down to 1s and 0s.