 |
 |
 |
 |
#474209 - 07/07/09 03:23 PM
Google Hijacked...
|
New User
Registered: 07/07/09
Posts: 8
|
Hi, I am running Leopard 10.5.4, and everything has been running fine until recently. Within the last week or so, certain websites have been hijacked, with the most frequent one being google (I use firefox, but it happens in safari as well). I've downloaded and run every virus scan and malware scan that I can find, but none of them find anything. It seems like a trojan clicker like you would find on a PC with websites redirecting to random search sites, but like I said, I can't find anything wrong when I scan. Please help, this is getting so frustrating!
Thanks in advance, Dan
|
|
Top
|
|
|
|
|
 |
 |
 |
 |
 |
 |
 |
 |
#474221 - 07/07/09 07:44 PM
Re: Google Hijacked...
[Re: djackson3693]
|
MacAuthor
Registered: 12/27/01
Posts: 2217
Loc: Los Angeles, CA, USA
|
Do you have any plugins installed? If yes, try to disable them. Is Google toolbar installed? If yes, I would get rid of it too. From a general standpoint, I would update your OS to 10.5.7, Safari to 4.0 and Firefox to 3.5. You can also try to trash the respective plist files for Firefox and Safari.
_________________________
Alex 2.66 GHz 17" MacBook Pro, 4 GB RAM, OS 10.5.7, Office 2008, TimeWarner Cable
|
|
Top
|
|
|
|
|
 |
 |
 |
 |
 |
 |
 |
 |
#474262 - 07/08/09 02:24 PM
Re: Google Hijacked...
[Re: tacit]
|
New User
Registered: 07/07/09
Posts: 8
|
sure...for example, I searched on google for "symantec" the first two hits worked fine, but the third one down ( http://security.symantec.com) redirected to this: http://simplesearchresults.com/search.ph...crKSUlJLzYsMgMAwhich then redirects again to one of any number or random search/shopping websites. as I may have already mentioned, it is also affecting my gmail, and I've recently found out that Youtube is also affected (both have apparently bad security certificates and both run by google...hmmm). unfortunately, I was previously able to bypass many of the redirects by simply searching using yahoo instead of google, but within the last few days it seems yahoo has also been affected. the other main site that it redirects to, as I've mentioned, looks like this: http://www.topdaofinder.com/check/?sid=9...cbb11&did=4I looked briefly for a link that will redirect to that, but I haven't found one for a while. the simplesearch one comes up more.
|
|
Top
|
|
|
|
|
 |
 |
 |
 |
 |
 |
 |
 |
#474410 - 07/11/09 12:35 AM
Re: Google Hijacked...
[Re: djackson3693]
|
MacGuru
Registered: 10/14/99
Posts: 12002
Loc: Portland, Oregon, USA
|
sure...for example, I searched on google for "symantec" the first two hits worked fine, but the third one down ( http://security.symantec.com) redirected to this: http://simplesearchresults.com/search.php?s=1&q=K67MTcwrSU3mNOBMTjJJNU1NMk8pLMwxyjRIScrKSUlJLzYsMgMA That is definitely consistent with infection by the OSX/Zlob, aka DNSchanger, Trojan. The fact that the DNSchanger disinfection program you've run doesn't turn up anything is worrying. The Zlob gang has recently been stepping up their Mac malware efforts, and I've just recently noticed them creating Mac-only attack domains. When you open the Terminal and run cat /etc/resolv.conf what does it say? Can you give us the name server addresses it's coming up with? (Don't worry, this won't compromise your security. Name server addresses are addresses of computers run by your ISP, not the address of your computer.)
|
|
Top
|
|
|
|
|
 |
 |
 |
 |
 |
 |
 |
 |
#474411 - 07/11/09 12:53 AM
Re: Google Hijacked...
[Re: tacit]
|
New User
Registered: 07/07/09
Posts: 8
|
Here's what I got: Last login: Sat Jul 11 03:39:17 on console dan-jacksons-mac-pro:~ danjackson$ cat /etc/resolv.conf nameserver 87.118.92.205 nameserver 87.118.93.205 nameserver 192.168.2.1 dan-jacksons-mac-pro:~ danjackson$ A computer is infected if theres an address that starts with 85 right? Also, the laptop's fan is now running almost permanently and quite loudly, as if the laptop were overheating. I can't help but assume that the two issues are connected...I'm slowly losing my patience and my mind
|
|
Top
|
|
|
|
|
 |
 |
 |
 |
|
|