oh yeah, and a delurk.
Hi,
Long time viewer of these forums, well about a year now, I'm a recent switcher followed my friends and family into the mac world. I've been actively reading posts over the past two weeks now. I believe that I may have a trojan or DNS problem on my MB. Most likely picked it up when the mac was new, most likely from an 'adult' site (please spare me the morality speeches, it's a multi-billion dollar world wide industry, but no one goes there?)
anyway, here's why, my internet surfing on my mb using firefox or safari has come to a crawl. I have to repeatedly reclick links to get them to load. I'm seeing all sort of problems on the status bar at the bottom, ie most ad services (googleads.com, ad.doubleclick.net) seem to freeze everything up.
Sorry this is long, just trying to set the scene, I d/l LS and see a truck load of traffic trying to phone home, now my brother who is a mac guy for years tell me that while macs are known for 'chatter' this is way to excessive.
most of the stuff is coming from /usr/sbin/named I do not know the first thing about unixy stuff. I just opened my first terminal last week. It scares the hell out of me (using a sudo line, and then find out I can crash the whole shooting match with one typo?)
[0x0-0x9b09b].org.mozilla.firefox[1704]: Debugger() was called!
Feb 25 00:16:12 js-macbook [0x0-0x9b09b].org.mozilla.firefox[1704]: Debugger() was called!
Feb 25 00:29:40 js-macbook named[81]: clients-per-query decreased to 22
Feb 25 00:32:08 js-macbook [0x0-0x9b09b].org.mozilla.firefox[1704]: Debugger() was called!
Feb 25 00:49:40 js-macbook named[81]: clients-per-query decreased to 21
Feb 25 00:50:58 js-macbook [0x0-0x9b09b].org.mozilla.firefox[1704]: Debugger() was called!
Feb 25 00:52:21 js-macbook [0x0-0x9b09b].org.mozilla.firefox[1704]: Debugger() was called!
Feb 25 00:56:32 js-macbook login[2611]: DEAD_PROCESS: 2611 ttys000
Feb 25 00:56:48 js-macbook login[2756]: USER_PROCESS: 2756 ttys000
Feb 25 00:57:05 js-macbook named[2767]: starting BIND 9.4.2-P2 -l
Feb 25 00:57:05 js-macbook named[2767]: none:0: open: /private/etc/lwresd.conf: file not found
Feb 25 00:57:05 js-macbook named[2767]: none:0: open: /private/etc/rndc.key: file not found
Feb 25 00:57:05 js-macbook named[2767]: couldn't add command channel 127.0.0.1#953: file not found
Feb 25 00:57:05 js-macbook named[2767]: none:0: open: /private/etc/rndc.key: file not found
Feb 25 00:57:05 js-macbook named[2767]: couldn't add command channel ::1#953: file not found
Feb 25 00:57:05 js-macbook named[2767]: failed to add lwres socket: 127.0.0.1#921: permission denied
Feb 25 00:57:05 js-macbook named[2767]: couldn't open pid file '/private/var/run/lwresd.pid': Permission denied
Feb 25 00:57:05 js-macbook named[2767]: exiting (due to early fatal error)
Feb 25 00:57:18 js-macbook login[2756]: DEAD_PROCESS: 2756 ttys000
Feb 25 01:09:21 js-macbook named[81]: client 192.168.2.1#65164: RFC 1918 response from Internet for 100.1.168.192.in-addr.arpa
Feb 25 01:09:40 js-macbook named[81]: clients-per-query decreased to 20
Feb 25 01:10:49 js-macbook [0x0-0x9b09b].org.mozilla.firefox[1704]: Debugger() was called!
Feb 25 01:12:51 js-macbook [0x0-0x9b09b].org.mozilla.firefox[1704]: Debugger() was called!
Feb 25 01:12:52 js-macbook named[81]: socket: too many open file descriptors
Feb 25 01:13:22: --- last message repeated 3 times ---
Feb 25 01:13:31 js-macbook login[2785]: USER_PROCESS: 2785 ttys000
Feb 25 01:13:48 js-macbook named[81]: client 192.168.2.1#62211: RFC 1918 response from Internet for 1.2.168.192.in-addr.arpa
Feb 25 01:13:48 js-macbook named[81]: client 192.168.2.1#61308: RFC 1918 response from Internet for 1.2.168.192.in-addr.arpa
Feb 25 01:13:48 js-macbook named[81]: client 192.168.2.1#54165: RFC 1918 response from Internet for 100.1.168.192.in-addr.arpa
Feb 25 01:17:51 js-macbook [0x0-0x9b09b].org.mozilla.firefox[1704]: Debugger() was called!
Feb 25 01:23:04 js-macbook [0x0-0x9b09b].org.mozilla.firefox[1704]: Debugger() was called!
Feb 25 01:24:45 js-macbook [0x0-0x9b09b].org.mozilla.firefox[1704]: Debugger() was called!
Feb 25 01:29:40 js-macbook named[81]: clients-per-query decreased to 19
Feb 25 01:28:53 js-macbook [0x0-0x9b09b].org.mozilla.firefox[1704]: Debugger() was called!
Feb 25 01:36:48 js-macbook named[81]: socket: too many open file descriptors
Feb 25 01:37:18: --- last message repeated 3 times ---
Feb 25 01:37:42 js-macbook [0x0-0x9b09b].org.mozilla.firefox[1704]: Debugger() was called!
Feb 25 01:49:40 js-macbook named[81]: clients-per-query decreased to 18
Feb 25 02:01:08 js-macbook named[81]: socket: too many open file descriptors
Feb 25 02:01:38: --- last message repeated 12 times ---
Feb 25 02:01:39 js-macbook kernel[0]: Limiting icmp unreach response from 485 to 250 packets per second
Feb 25 02:09:21 js-macbook named[81]: client 192.168.2.1#65164: RFC 1918 response from Internet for 100.1.168.192.in-addr.arpa
Feb 25 02:09:40 js-macbook named[81]: clients-per-query decreased to 17
Feb 25 02:14:16 js-macbook kernel[0]: IPv6 packet filtering initialized, default to accept, logging disabled
Feb 25 02:29:40 js-macbook named[81]: clients-per-query decreased to 16
Feb 25 02:30:41 js-macbook named[81]: socket: too many open file descriptors
Feb 25 02:31:11: --- last message repeated 3 times ---
Feb 25 02:33:24 js-macbook named[81]: client 192.168.2.1#58726: RFC 1918 response from Internet for 255.1.168.192.in-addr.arpa
Feb 25 02:33:24 js-macbook named[81]: client 192.168.2.1#61703: RFC 1918 response from Internet for 255.1.168.192.in-addr.arpa
Feb 25 02:33:34 js-macbook named[81]: client 192.168.2.1#53867: RFC 1918 response from Internet for 255.2.168.192.in-addr.arpa
Feb 25 02:33:34 js-macbook named[81]: client 192.168.2.1#63900: RFC 1918 response from Internet for 255.2.168.192.in-addr.arpa
these are the last bits of my system.log I do not know how to read this stuff my I'm trying to learn, I also as you have noticed, do not know how to take screen shots yet on a mac. Any and all help would be appreciated, I've tried LS, ClamXAV, and the securemac product, none have done anything.
I know it's not a virus, it has to be a dns or trojan issue or something. I'm not ruling out anything stupid that I did, I realize that if it is a trojan, I let it in. Back in my PC days, I surfed with nothing other than AVG, not saying it's a great program, just saying that I surfing smart.
most of the problems seem to come from named(81)
BTW is there a good reference for mac specific system logs for newbies like myself to go to learn how to trouble shoot these things?
Thanks
FYI, I need to talk to the admins.....my log on name is suppposed to fishinmedic, small little typo there, hence why I'm nervous about playing in a terminal
Hi,
Long time viewer of these forums, well about a year now, I'm a recent switcher followed my friends and family into the mac world. I've been actively reading posts over the past two weeks now. I believe that I may have a trojan or DNS problem on my MB. Most likely picked it up when the mac was new, most likely from an 'adult' site (please spare me the morality speeches, it's a multi-billion dollar world wide industry, but no one goes there?)
anyway, here's why, my internet surfing on my mb using firefox or safari has come to a crawl. I have to repeatedly reclick links to get them to load. I'm seeing all sort of problems on the status bar at the bottom, ie most ad services (googleads.com, ad.doubleclick.net) seem to freeze everything up.
Sorry this is long, just trying to set the scene, I d/l LS and see a truck load of traffic trying to phone home, now my brother who is a mac guy for years tell me that while macs are known for 'chatter' this is way to excessive.
most of the stuff is coming from /usr/sbin/named I do not know the first thing about unixy stuff. I just opened my first terminal last week. It scares the hell out of me (using a sudo line, and then find out I can crash the whole shooting match with one typo?)
[0x0-0x9b09b].org.mozilla.firefox[1704]: Debugger() was called!
Feb 25 00:16:12 js-macbook [0x0-0x9b09b].org.mozilla.firefox[1704]: Debugger() was called!
Feb 25 00:29:40 js-macbook named[81]: clients-per-query decreased to 22
Feb 25 00:32:08 js-macbook [0x0-0x9b09b].org.mozilla.firefox[1704]: Debugger() was called!
Feb 25 00:49:40 js-macbook named[81]: clients-per-query decreased to 21
Feb 25 00:50:58 js-macbook [0x0-0x9b09b].org.mozilla.firefox[1704]: Debugger() was called!
Feb 25 00:52:21 js-macbook [0x0-0x9b09b].org.mozilla.firefox[1704]: Debugger() was called!
Feb 25 00:56:32 js-macbook login[2611]: DEAD_PROCESS: 2611 ttys000
Feb 25 00:56:48 js-macbook login[2756]: USER_PROCESS: 2756 ttys000
Feb 25 00:57:05 js-macbook named[2767]: starting BIND 9.4.2-P2 -l
Feb 25 00:57:05 js-macbook named[2767]: none:0: open: /private/etc/lwresd.conf: file not found
Feb 25 00:57:05 js-macbook named[2767]: none:0: open: /private/etc/rndc.key: file not found
Feb 25 00:57:05 js-macbook named[2767]: couldn't add command channel 127.0.0.1#953: file not found
Feb 25 00:57:05 js-macbook named[2767]: none:0: open: /private/etc/rndc.key: file not found
Feb 25 00:57:05 js-macbook named[2767]: couldn't add command channel ::1#953: file not found
Feb 25 00:57:05 js-macbook named[2767]: failed to add lwres socket: 127.0.0.1#921: permission denied
Feb 25 00:57:05 js-macbook named[2767]: couldn't open pid file '/private/var/run/lwresd.pid': Permission denied
Feb 25 00:57:05 js-macbook named[2767]: exiting (due to early fatal error)
Feb 25 00:57:18 js-macbook login[2756]: DEAD_PROCESS: 2756 ttys000
Feb 25 01:09:21 js-macbook named[81]: client 192.168.2.1#65164: RFC 1918 response from Internet for 100.1.168.192.in-addr.arpa
Feb 25 01:09:40 js-macbook named[81]: clients-per-query decreased to 20
Feb 25 01:10:49 js-macbook [0x0-0x9b09b].org.mozilla.firefox[1704]: Debugger() was called!
Feb 25 01:12:51 js-macbook [0x0-0x9b09b].org.mozilla.firefox[1704]: Debugger() was called!
Feb 25 01:12:52 js-macbook named[81]: socket: too many open file descriptors
Feb 25 01:13:22: --- last message repeated 3 times ---
Feb 25 01:13:31 js-macbook login[2785]: USER_PROCESS: 2785 ttys000
Feb 25 01:13:48 js-macbook named[81]: client 192.168.2.1#62211: RFC 1918 response from Internet for 1.2.168.192.in-addr.arpa
Feb 25 01:13:48 js-macbook named[81]: client 192.168.2.1#61308: RFC 1918 response from Internet for 1.2.168.192.in-addr.arpa
Feb 25 01:13:48 js-macbook named[81]: client 192.168.2.1#54165: RFC 1918 response from Internet for 100.1.168.192.in-addr.arpa
Feb 25 01:17:51 js-macbook [0x0-0x9b09b].org.mozilla.firefox[1704]: Debugger() was called!
Feb 25 01:23:04 js-macbook [0x0-0x9b09b].org.mozilla.firefox[1704]: Debugger() was called!
Feb 25 01:24:45 js-macbook [0x0-0x9b09b].org.mozilla.firefox[1704]: Debugger() was called!
Feb 25 01:29:40 js-macbook named[81]: clients-per-query decreased to 19
Feb 25 01:28:53 js-macbook [0x0-0x9b09b].org.mozilla.firefox[1704]: Debugger() was called!
Feb 25 01:36:48 js-macbook named[81]: socket: too many open file descriptors
Feb 25 01:37:18: --- last message repeated 3 times ---
Feb 25 01:37:42 js-macbook [0x0-0x9b09b].org.mozilla.firefox[1704]: Debugger() was called!
Feb 25 01:49:40 js-macbook named[81]: clients-per-query decreased to 18
Feb 25 02:01:08 js-macbook named[81]: socket: too many open file descriptors
Feb 25 02:01:38: --- last message repeated 12 times ---
Feb 25 02:01:39 js-macbook kernel[0]: Limiting icmp unreach response from 485 to 250 packets per second
Feb 25 02:09:21 js-macbook named[81]: client 192.168.2.1#65164: RFC 1918 response from Internet for 100.1.168.192.in-addr.arpa
Feb 25 02:09:40 js-macbook named[81]: clients-per-query decreased to 17
Feb 25 02:14:16 js-macbook kernel[0]: IPv6 packet filtering initialized, default to accept, logging disabled
Feb 25 02:29:40 js-macbook named[81]: clients-per-query decreased to 16
Feb 25 02:30:41 js-macbook named[81]: socket: too many open file descriptors
Feb 25 02:31:11: --- last message repeated 3 times ---
Feb 25 02:33:24 js-macbook named[81]: client 192.168.2.1#58726: RFC 1918 response from Internet for 255.1.168.192.in-addr.arpa
Feb 25 02:33:24 js-macbook named[81]: client 192.168.2.1#61703: RFC 1918 response from Internet for 255.1.168.192.in-addr.arpa
Feb 25 02:33:34 js-macbook named[81]: client 192.168.2.1#53867: RFC 1918 response from Internet for 255.2.168.192.in-addr.arpa
Feb 25 02:33:34 js-macbook named[81]: client 192.168.2.1#63900: RFC 1918 response from Internet for 255.2.168.192.in-addr.arpa
these are the last bits of my system.log I do not know how to read this stuff my I'm trying to learn, I also as you have noticed, do not know how to take screen shots yet on a mac. Any and all help would be appreciated, I've tried LS, ClamXAV, and the securemac product, none have done anything.
I know it's not a virus, it has to be a dns or trojan issue or something. I'm not ruling out anything stupid that I did, I realize that if it is a trojan, I let it in. Back in my PC days, I surfed with nothing other than AVG, not saying it's a great program, just saying that I surfing smart.
most of the problems seem to come from named(81)
BTW is there a good reference for mac specific system logs for newbies like myself to go to learn how to trouble shoot these things?
Thanks
FYI, I need to talk to the admins.....my log on name is suppposed to fishinmedic, small little typo there, hence why I'm nervous about playing in a terminal