Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Malware on my G5?

Hi. I'm having a chronically reoccurring problem w/ one of the sites that I use and I think it may be the result of malware that has found its way onto my G5.

The site is myspace and I use it for my band's website. Things will be fine for a day or two, sometimes longer and then the problems will start again.

Here is what happens. I will bring up my myspace page and either one of the modules on the page will not display or takes forever to load. Or I will get a message saying Safari cannot connect to the myspace server or if it does come up, clicking on a link on the page which should allow me to navigate within my site will take me to an incorrect location (some other myspace website). *Eventually I am redirected to a "myspace profile" that appears to be a singles/adult oriented page. It is always the same page and once it comes up I am not able to go anywhere else within my site or myspace without being redirected back to this page.*

I have tried emptying the cache, deleting cookies, having a new "clean" cookies.plist file generated, repairing permissions, logging in from a different account, using a different browser and for a while, sometimes the problem seems to have gone away but it always comes back. *I have also tried using Little Snitch and denying connection to the host name of the page that I am being redirected to and for a while that seemed to work but no longer. In addition I've scanned my G5 using ClamXAV and nothing was found. I'm currently trying out MacScan 2.7 and scanning for spyware.*

Myspace is not able to help me and suggests that I have malware on my computer. Could ClamXAV be missing something that maybe a heavier duty program might find? I'm running OS X 10.4.11 on a dual 2.3 Ghz PowerPC G5. If anyone has any ideas or suggestions as to how I might proceed at this point I would be very grateful.

Posted on Oct 11, 2010 1:08 PM

Reply
Question marked as Best reply

Posted on Oct 11, 2010 1:49 PM

DNS poisoning, myspace infected with malware.
I notice Google brings up some topics on MySpace forum.

I'd download the latest build of Firefox 4.0b8 and add NoScript and FlashBlock.
http://ftp.mozilla.org/pub/mozilla.org/firefox/nightly/

Hosts file
http://www.mvps.org/winhelp2002/hosts.htm

http://www.macintouch.com/security.html

http://www.google.com/#sclient=psy&num=10&hl=en&q=malwarednsredirect

Twitter has been hacked in the recent past.

Apple probably hasn't updated Safari for 10.4.11 so you might want to use something else, Private Browser mode in FF for one, turn off plug-ins.

As for MacScan.... I'd use the demo of Intego but installing AV on PPC Mac? NO.
6 replies
Question marked as Best reply

Oct 11, 2010 1:49 PM in response to stopmotion

DNS poisoning, myspace infected with malware.
I notice Google brings up some topics on MySpace forum.

I'd download the latest build of Firefox 4.0b8 and add NoScript and FlashBlock.
http://ftp.mozilla.org/pub/mozilla.org/firefox/nightly/

Hosts file
http://www.mvps.org/winhelp2002/hosts.htm

http://www.macintouch.com/security.html

http://www.google.com/#sclient=psy&num=10&hl=en&q=malwarednsredirect

Twitter has been hacked in the recent past.

Apple probably hasn't updated Safari for 10.4.11 so you might want to use something else, Private Browser mode in FF for one, turn off plug-ins.

As for MacScan.... I'd use the demo of Intego but installing AV on PPC Mac? NO.

Oct 11, 2010 2:06 PM in response to stopmotion

Many/most Social Networking sites are hacked regularly.

See if you might have this malware redirecting DNS queries...

http://macmegasite.com/node/3924

http://www.ehow.com/how2128387remove-osxrspluga-trojan-horse-mac.html

How to fix...

http://www.macosxhints.com/article.php?story=20071031114140862

Get MacScan...

http://www.apple.com/downloads/macosx/networking_security/macscan.html

Malware list....

http://x704.net/bbs/viewtopic.php?f=6&t=4479

Nasty Nasty ! 1023.dmg...

http://x704.net/bbs/viewtopic.php?f=12&t=2178

Then... Try putting these numbers in Network>TCP/IP>DNS Servers, for the Interface you connect with...

208.67.222.222
208.67.220.220

Then Apply

DNS Servers are a bit like Phone books where you look up a name and it gives you the phone number, in our case, you put in apple.com and it comes back with 17.149.160.49 behind the scenes. 🙂

These Servers have been patched to guard against DNS poisoning, and are faster/more reliable than most ISP's DNS Servers.

Oct 11, 2010 6:46 PM in response to BDAqua

Thanks to both of you for the links and your suggestions. I downloaded a trial version of VirusBarrier by Intego for Tiger, ran it and 0 viruses were found. I did a manual search for the malware redirecting DNS queries and it did not show up. Also did the search through Terminal which came up negative. I already had tried MacScan which found 0 spyware. I changed the numbers for my DNS Servers as suggested. Things seem to be okay now and I'll see how it goes. Appreciate all the info.

Malware on my G5?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.