Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

iMAX386

macrumors newbie
Original poster
May 23, 2010
19
0
For the past month I've had something affecting my MBP running 10.6.4 on all my browsers.

I use Firefox 3.6, but the problem happens with Safari too. Problem is two-fold: I'll click a link and it redirects. I also get pop-ups going to different sites, some that seem legit and some that are sketchy. Sometimes the pop-ups never load, but instead get stuck on "waiting for google-analytics." Some of the redirects just stall on the WYCIWYG google intermediate page and any time you press the back button it just reloads the redirect site.

If it's any help, some of the sites it's been going to include:
epoclick.com/?ad=1287694313 (this epoclick one happens a lot, but it ends up in a blank white page every time)

65.60.9.238/click.php?c=f356638201046546cd1180c39600&d=1287713624

younghollywood.com/videos/yhstudio/may/rico--raini-rodriguez.html

results.gugle.com

nhost.282561.get-search-results.com/jump1/?affiliate=nhost&subid=282561&terms=gospel%20publishing%20house&sid=Z461044499%40EzX0YDN1cDNy8VN2gTMfRzMfFzMy8FMzMzNzczN4ITM&a=aubfg&mr=1&rc=0

yellowpages.lycos.com/search?what=Packaging&local=1&src=YBLYC10&utm_source=YBLYC10&utm_medium=cpc&utm_term=Packaging&utm_campaign=YBLYC10

rheumatologychannel.com/arthritis/index.shtml?c1=MVA_CM_NW&source=RON19&kw=Arthritis_Generic&cr5=1CE0144B-

whattoexpect.com/funnel/registration.aspx?xid=ls_reg&utm_source=looksmart-71352-2699&utm_medium=cpc&utm_term=vision%20forum&utm_conte

justluxe.com/lifestyle/landing1.php?ref=JLAdonnontargcpc01&adonVars=apid-113669-aaid-158-acid-189429-alid-7237259-asid-
r.localpages.com/j.php?h=88b5ab7c80cbf9862c19ddbabae2820a&s=c&px=1&wf=1&ai=3000&fm=1880&st=digital+cameras+reviews&tos=1287661177

A white page that says "Found - The document has moved HERE" with the HERE linked to: r.looksmart.com/og/pr=Psr;ro=1;rc=1;digest=00b1d680b22587f336acd188b771bc5a;kid=ffa3518b6dc9f7ba3c3670fc836d1969;t=1287713622;v=8;data=5KMaykQ35IULjdcZ_0hdNbhjBCIvaqrHGsz0eLdGsd5AlHhqOKuS9a6lk0OqdjFyuWnnKVX46CJFHv2sYluG05gHvU-CRdSvx9s9ryleCqnK6-N8yp2fjFRphFS93GNMBM8QyTCRAikRVes7qnfn99n2GrvvpK5CPMr3u1JScI4BX9QPAVVgPA;uh=189x8745049555544395769;la=457294;lm=1533217;ad=742060171;ag=755160473;kw=1047279510;qt=retriever%20training%20forum;vr=4;lt=BM;ip=68.12.226.175;pt=;st=32.24.4.0.0.0.0;os=1772.379.1.0.1.362.3.9;sy=keyword;my=broad;geo=894417;vid=0;subid=155;opi=furx2;ii=4164.7c33.4cc0f356.2dd9;pn=;to=;tc=1;po=1;pc=1;pi=furx2;ts=;rm=;rh=infojay.com|whattoexpect.com/funnel/registration.aspx?xid=ls_reg&utm_source=looksmart-71065-155&utm_medium=cpc&utm_term=retriever%20training%20forum&utm_content=1047279510&utm_campaign=742060171

elocalz.com
spreety.com
craveonline.com
apmex.com

Don't remember installing any rogue software, or clicking yes to any plugins/codecs, but it's apparently something I've invited to my system.

I think it's a problem that's affecting the router because it's also started affecting my old PC that I still have, and my iPhone, which all use my home wifi. On my phone I've noticed on Safari that popups randomly open up going to the same time of addresses that my Mac browsers have been going to. I admit though that I've connected my iPhone to the PC recently and hooked it back to the mac so these 3 devices have had contact outside the wifi. If it's a router affected issue, I'm clueless to the fix.

Tried to find my own fixes and after many google searches I've still got the problem. Switched to Mac back in May so I'm still new to the semantics of Mac, but feel I'm tech savvy enough to be able to fix this.

I've used the following, and each has found no problems:
- ClamXav
- MacScan
- DNSChangerRemoval Tool
- iAntivirus

I've also done the following:
- Cleaned all the private info and cache on FF and Safari.
- Examined the DNS tab on Network in System Preferences, only shows 192.168.1.1
- Done the sudo crontab fix through Terminal for (following these instructions: http://www.ehow.com/how_2128387_remove-osxrspluga-trojan-horse-mac.html)

I have a Windows XP VM running through Fusion 3.1 that I installed around the same time as this problem popped up. The Fusion packaged McAfee program has found nothing upon scanning.

I've tried the following on my Windows VM with nothing incriminating found:
- Spybot S&D
- HijackThis
- Malwarebytes

I'm desperate for help. I've included as much info as I can think of. Thank you to any who respond!
 
Try changing your DNS servers to the following OpenDNS servers:
208.67.222.222
208.67.220.220
 
Did you check the DNS settings on your router? It sounds like a DNS Insertion attack, and usually that's done at the router level. If you can, I'd even say to do a hard reset of the router (look in the instruction manual, usually there's a small paperclip hole that you need to press and hold), and then configure it again fresh, with a very secure password.

jW
 
You most likely are already aware of this but in case you are not, routers require two passwords:

1) a network password to access the wireless network (WPA password)

2) an admin password to protect the firmware from modification (much like password in Mac OS X)

Often infections as you describe are the result of not changing the default admin password for the router.

After you do a hard reset as suggested above, make sure to change the admin password to a secure password if this is the reason for your issue.
 
You can validate if this is a router-based attack by connecting with another computer/iPhone/PS3 browser/etc., and see if you get the same results.

By the way, OP: Good job on trying things BEFORE asking for help! :D

-Aaron-
 
I just want to give you guys a big thank you.

It's been about 24 hours since I did the hard router reset and I've yet to have a pop-up or redirect. I'm still expecting one to show up, but who knows. Changed the router admin password.

Quick clarification: Once these router/DNS attacks are cleared, they're completely gone? Remnants don't linger in the router/computer software that re-attack the router, do they?

This was my first experience with a router-based hijacker.
 
No. Nothing was ever done to your computer, btw. Someone accessed your router from their own computer and changed the DNS settings. Once you reset that router, and assuming they can't get past your new password on the router setup to mess with you again, then you should be set.

jW
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.