malware/Trojan/google hack?! HELP

Joined
Oct 10, 2008
Messages
7
Reaction score
0
Points
1
right first post here so here goes!

On our network we have macs and pcs all of which were having a problem when following links from google... So I have now hard reset our router and am in the process of reintroducing each computer to the network after vigarous virus checks... My MacBook was first to go back on network a d the problem remains... Virus barrier has picked up nothing...

Please help as our network cannot be fully reinstated until I have figured out the cause of this problem and how go solve it.

Kind regards.
 

rman


Retired Staff
Joined
Dec 24, 2002
Messages
12,637
Reaction score
168
Points
63
Location
Los Angeles, California
Your Mac's Specs
14in MacBook Pro M1 Max 32GB 2TB
For someone to help you, you need to give out a little more information on the nature of the problem.

Because you state that this problem exists on both OS X and windows, it may not be what you are suggesting.
 
Joined
Oct 22, 2007
Messages
8,967
Reaction score
287
Points
83
Location
London
Your Mac's Specs
Mac Mini Core i7 2012 | White 2009 MacBook 2 Ghz | 733 Mhz G4 Quicksilver
Are you talking about DNS redirects links going to the wrong sites

If so check your routers DNS servers, the problem may be there
 
OP
T
Joined
Oct 10, 2008
Messages
7
Reaction score
0
Points
1
Thanks Rman I'll try and give a little more detail.

Firstly this is a problem that our computers only suffer with when using our network. Friends and public wifi spots are fine and uninfected.

Although the problem was present on Pcs and Macs on the network, it is now only worrying me on the macs as all pcs on the network have had a fresh installation + security update and are awaiting the problem to be resolved on our macs before being reintroduced to network.

The issue on the macs is now this - when following a link on google, instead of taking me to the requested site I see the address bar at the top of firefox scan through various sites and eventually end of at a random page.

This random page usually includes my original google search term but bears no relevance to requested page - ie band's myspace page.

I have done some online research into this and have found various pages: -

The first seems to come to the conclusion that the problem we are having is a trojan named - OSX.RSPlug.A.
How to Remove the OSX.RSPlug.A Trojan Horse from your Mac | eHow.com
However the solution detailed on the page does not solve the problem.

-Virus Barrier has found no problems.
-There is no file entitled 'plugin.settings' in the Internet Plug-Ins folder
-I have opened Terminal and followed the insturctions from the page: -

Type in "sudo crontab -l" (the letter L, and minus the quotes), hit Return, and enter your administrator password when asked. If it returns with anything other than "crontab: no crontab for root", you are most likely infected.

And my mac does return with "crontab: no crontab for root"

This makes it seem as if I am not suffering from the problem but the redirects on google, ONLY WHEN USING OUR NETWORK, still continue?

The second page I have found on this subject/problem is this: -
Macworld | First Look: Trojan Horse warning: What you need to know

This page again talks of the same solution, by deleting plugin.settings file (which is not present on my macbook) and then checking by doing the same terminal check which my macbook passed.

However this page does advise you to check in System Preferences/Network/Advanced and then viewing the DNS tab. Here, the pages says you should have no grey DNS servers listed. I have three?!

Is there a way to check where each one of them is being received by?

Why would I have three?

How do I remove any of them as they all have greyed out minus buttons?

Many thanks to anyone that can help with this.
 
OP
T
Joined
Oct 10, 2008
Messages
7
Reaction score
0
Points
1
Are you talking about DNS redirects links going to the wrong sites

If so check your routers DNS servers, the problem may be there

How would I go about doing this? What would I be looking for when viewing the router settings?

Many thanks.
 
Joined
Oct 22, 2007
Messages
8,967
Reaction score
287
Points
83
Location
London
Your Mac's Specs
Mac Mini Core i7 2012 | White 2009 MacBook 2 Ghz | 733 Mhz G4 Quicksilver
Contact your ISP and ask them for the addresses of the DNS servers they use

If you routers DNS settings are in any way different, then it may be that the router has been hijacked and no amount of cleaning up any Mac or PC is going to cure the problem

The OSX.RSPlug.A Trojan got a lot of press, but users had to take active steps to install it, and grant it admin privileges (in the false belief they could then see a saucy video), so in reality it didn't ever infect many machines
 

dtravis7


Retired Staff
Joined
Jan 4, 2005
Messages
30,133
Reaction score
703
Points
113
Location
Modesto, Ca.
Your Mac's Specs
MacMini M-1 MacOS Monterey, iMac 2010 27"Quad I7 , MBPLate2011, iPad Pro10.5", iPhoneSE
Can you take a screen shot of the network panel on the DNS Tab and post it? If you do not know how to do a screen shot in osx, let us know. I have 2 grayed out entries but they are the default DNS that comes from my ISP and is in the router. The 2 entries that I can edit are OPEN DNS that I added.

I have no issues at all with any DNS redirects here. If I can see what the IP of the grayed out servers are I could do a trace and see what they are.
 
OP
T
Joined
Oct 10, 2008
Messages
7
Reaction score
0
Points
1
Hi dtravis7,

Since your post I have traced the DNS Servers and the results are this...

DNS servers 1 & 2 trace info comes back as this: -

Network name : UKRTELEGROUP
Infos : UkrTeleGroup Ltd.
Country : Ukraine (UA)

DNS Server No.3 comes back as this: -

Network name : UK-CABLEINET-20000211
Infos : Cable Internet Ltd
Infos : PROVIDER Local Registry
Country : United Kingdom (GB)

Now as I am in the U.K currently it seems odd to have two of the three DNS servers pointing to Ukraine?!
 

dtravis7


Retired Staff
Joined
Jan 4, 2005
Messages
30,133
Reaction score
703
Points
113
Location
Modesto, Ca.
Your Mac's Specs
MacMini M-1 MacOS Monterey, iMac 2010 27"Quad I7 , MBPLate2011, iPad Pro10.5", iPhoneSE
Can you check your router and view the DNS there? See if the Ukraine servers show up in the routers DNS info.
 
OP
T
Joined
Oct 10, 2008
Messages
7
Reaction score
0
Points
1
Hi dtravis7,

Thanks for your continued help -

I have checked in the router settings and ONLY the Ukraine DNS servers show in my router?!
 
Joined
Oct 22, 2007
Messages
8,967
Reaction score
287
Points
83
Location
London
Your Mac's Specs
Mac Mini Core i7 2012 | White 2009 MacBook 2 Ghz | 733 Mhz G4 Quicksilver
I take it you are not in the Ukraine

I would strongly suspect those Ukciane DNS servers to be the root of the problem

Try and delete them at thr router and replace them with the ones your ISP uses or the open DNS servers

https://www.opendns.com/smb/start/router/
 

Shop Amazon


Shop for your Apple, Mac, iPhone and other computer products on Amazon.
We are a participant in the Amazon Services LLC Associates Program, an affiliate program designed to provide a means for us to earn fees by linking to Amazon and affiliated sites.
Top