Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Safari 5.1 suddenly cannot connect to server when accessing Google?

I have always had my homepage set to www.google.co.uk but all of a sudden when I launch Safari 5.1 it's throwing up there error message 'Safari can't connect to the server', any ideas?

iMac 24" intel, Mac OS X (10.6.4)

Posted on Aug 7, 2011 3:27 AM

Reply
68 replies

Aug 7, 2011 3:01 PM in response to Linc Davis

Here are the results Linc:


Ping has started…


PING www.google.co.uk (91.224.160.26): 56 data bytes

Request timeout for icmp_seq 0

Request timeout for icmp_seq 1

Request timeout for icmp_seq 2

92 bytes from jt.altushost.com (217.170.19.60): Destination Host Unreachable

Vr HL TOS Len ID Flg off TTL Pro cks Src Dst

4 5 00 5400 6b9c 0 0000 37 01 1110 10.0.1.3 91.224.160.26


92 bytes from jt.altushost.com (217.170.19.60): Destination Host Unreachable

Vr HL TOS Len ID Flg off TTL Pro cks Src Dst

4 5 00 5400 167f 0 0000 37 01 662d 10.0.1.3 91.224.160.26


Request timeout for icmp_seq 3

Request timeout for icmp_seq 4

Request timeout for icmp_seq 5

92 bytes from jt.altushost.com (217.170.19.60): Destination Host Unreachable

Vr HL TOS Len ID Flg off TTL Pro cks Src Dst

4 5 00 5400 1ece 0 0000 37 01 5dde 10.0.1.3 91.224.160.26


92 bytes from jt.altushost.com (217.170.19.60): Destination Host Unreachable

Vr HL TOS Len ID Flg off TTL Pro cks Src Dst

4 5 00 5400 68f3 0 0000 37 01 13b9 10.0.1.3 91.224.160.26


Request timeout for icmp_seq 6

Request timeout for icmp_seq 7

Request timeout for icmp_seq 8

92 bytes from jt.altushost.com (217.170.19.60): Destination Host Unreachable

Vr HL TOS Len ID Flg off TTL Pro cks Src Dst

4 5 00 5400 78f4 0 0000 37 01 03b8 10.0.1.3 91.224.160.26



--- www.google.co.uk ping statistics ---

10 packets transmitted, 0 packets received, 100.0% packet loss

Aug 7, 2011 3:21 PM in response to macboydesign

You have a serious problem, and it has nothing to do with Safari. Your connection requests to Google are being hijacked.


Open the Network preference pane in System Preferences and click the Advanced button. In the sheet that opens, select the DNS tab. What are the addresses of your DNS servers?


Next, launch the TextEdit application and select File > Open. Navigate in the open-file dialog to the top level of your startup volume. Press the key combination Command-Option-period. Files that are invisible in the Finder will now appear in the dialog. Navigate to /private/etc/hosts and click Open. Post the contents of the hosts file.

Aug 7, 2011 3:42 PM in response to macboydesign

They are cable.virginmedia.net


That's not what you saw in the preference pane. I'd like to know the numerical IP addresses of the DNS servers. I'd also like to see the contents of the hosts file, please. I'm not using Lion myself, so if the hosts file is not where I said it was, I don't know where it is. I'm pretty sure it is there. My time for dealing with this is limited. Without the information I asked for, I can't help you.


Why would someone hijack my google requests?


Not for any reason that's in your best interest.

Aug 7, 2011 4:34 PM in response to macboydesign

the DNS server IP is 10.0.1.1


That's the address of your router. Open its settings and find the addresses of the public DNS servers it uses. The information is not private. You've already disclosed who your ISP is.


The instructions you gave me for TextEdit didnt work


Launch the Terminal application and copy or drag -- do not type -- the following text into the window, then press return.


cat /etc/hosts


Post the lines of output that appear below what you entered. You can then quit Terminal.

Aug 8, 2011 9:48 PM in response to macboydesign

macboydesign wrote:


I have always had my homepage set to www.google.co.uk but all of a sudden when I launch Safari 5.1 it's throwing up there error message 'Safari can't connect to the server', any ideas?

You have been infected by malware that you downloaded and installed. The download was probably called "FlashPlayer.pkg". If you still have it please don't trash it quite yet. For the benefit of others in this community can you please upload it to http://www.virustotal.com. If the results do not show anything in the status column next to ClamAV can you also upload it to http://cgi.clamav.net/sendvirus.cgi and in the description box include the keyword "macos". If you know the name of the site where you downloaded it from, that would also be useful. Then you trash it so you won't be tempted to run it again.



A description of this malware along with instructions on fixing it can be found here: http://www.f-secure.com/v-descs/trojan_bash_qhost_wb.shtml



Thanks in advance and let us know how it goes.

Aug 9, 2011 11:51 AM in response to MadMacs0

Amazing!! Worked a treat, opened the hosts file and all of the entires were there, unbelieveable. Still have the culprit file which I will upload to the site you gave me. Not sure where I got it, think it may have been a graphic design site that told me I wasnt running the latest version of Flash which should have made me immediately suspicious seeing as all of my apps are up-to-date but nonetheless all sorted. Thanks so much to everyone for their help on this. Would you recommend any good software to protect me in future plus any apps to give my macs a spring clean?

Thanks again


J

Aug 9, 2011 12:46 PM in response to macboydesign

Still have the culprit file which I will upload to the site you gave me.

Great! and if you can get back to us with the VirusTotal ID that will help us find the sample quicker.

Not sure where I got it, think it may have been a graphic design site that told me I wasnt running the latest version of Flash which should have made me immediately suspicious seeing as all of my apps are up-to-date but nonetheless all sorted.

That matches up with what we heard earlier today from another user. Unfortunately the site he visited had been cleaned up already.

Would you recommend any good software to protect me in future plus any apps to give my macs a spring clean?

It's not clear that you actually need anything right now. Only the F-Secure AV software would have identified this one in your case and Apple's XProtect system was updated late yesterday to catch it. Most others will be updated some time today based on your help. Most folks in the forum currently recommend the same thing or one of the freeware offerings that are available if you feel you must. I do uncompensated tech support for the ClamXav forum so I tend to be partial to that.


As far as Cleaners are conserned I'm a firm believer in not using any of them. They tend to do more harm than good and the Mac OS does a reasonable job in taking care of itself. Use the advise found at Randy Singer's Macintosh OS X Routine Maintenance and you should be fine. If you find that you need something special done there is freeware that can do the job just as well as any commercial product out there. Most are listed in that same article.

Aug 9, 2011 12:52 PM in response to MadMacs0

Thanks very much again for all your help, im quite particular about my mac, that one blindsided me. Ohhh, I uploaded the software then did a secure trash of it but didnt get the upload ID im afraid im sorry. I guess with viruses etc. I became lax because Macs are so seldom victims of these things. Anyway, thanks again, very much appreciated

Safari 5.1 suddenly cannot connect to server when accessing Google?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.