How do I remove DNS Changer from osx 10.4.11 Several Attempts so far documented. (screenshots attached)

Hi


So I am trying to remove DNSChanger from 10.4.11


The normal warning is popping up when I browse the web: seen here

User uploaded file

I've tried running the DNSChangerRemovalTool downloaded from CNET but it didn't do the trick as shown below:

User uploaded file

I've tried Avast free antivirus for Mac but alas not good with 10.4

User uploaded file

I've tried Avira.....but no joy again!

User uploaded file

Finally....I've tried Comodo....Which said it was compatible with 10.4 but still came up with the old warning.

User uploaded file



Do you think that the virus is disabling all these antivirus scans and dns removal tool scans from working?


Anyone have any ideas?! Will post updates!


Thanks!!!

MacBook, Mac OS X (10.4.11)

Posted on Jul 4, 2012 12:54 PM

Reply
4 replies

Jul 4, 2012 3:01 PM in response to WrjLewis

Navigate to /Library/Internet Plug-Ins/ and look for either plugins.settings or AdobeFlash. If you find either drag them to the desktop.


Now check for a root level cron job. Open the Terminal app (found in /Applications/Utilities/), copy and paste:

sudo crontab -l

and hit return. Enter your admin password (you will not see any typing) and hit return.

If you see this output, it means you’ve got the malware:


* * * * * "/Library/Internet Plug-Ins/plugins.settings">/dev/null 2>&1

or

* * * * * "/Library/Internet Plug-Ins/AdobeFlash">/dev/null 2>&1


If you see anything else, stop and come back here before proceeding


To remove this part, go back to the Terminal app, copy and paste:

sudo crontab -r

and provide your admin password when asked. This deletes the root cron job that checks the DNS Server settings. You can prove it worked by typing sudo crontab -l (that's an ell not a one); you should see the message “crontab: no crontab for root.”


Open your Network System Preferences panel, go to the DNS Server box, and copy the entries you can see to a Stickies note, TextEdit document, or memorize them. Now retype those same values in the box, then click Apply.


Reboot your Mac.


If you struck out on all those things, the problem could be with your router.

Jul 5, 2012 12:00 AM in response to WrjLewis

WrjLewis wrote:


Do you think that the virus is disabling all these antivirus scans and dns removal tool scans from working?

No (DNSChanger is a Trojan, not a virus, by the way), your obsolete OS is preventing it. All the vendors you mentioned are former Windows A-V providers who are new to the Mac market, so it's not surprising that they didn't release a version for your Mac.


ClamXav v2.2.1 might help confirm the presence of the malware (12 variants), but I know that it won't remove all of it.


Sophos Anti-Virus for Mac Home Edition says it's compatible and has been around for awhile. They have a blog article here http://nakedsecurity.sophos.com/2011/11/10/. Looks like it detects OSX/RSPlug-A, -B, -Gen and -F installers but may not remove the Trojan itself.


The government site at http://www.dcwg.org/ has some useful information.

Jul 5, 2012 9:25 AM in response to MadMacs0

MadMacs0 - what a useful gentleman you are (assuming you are a man, with most humble apologies if you are not).


My Internet Plug-ins folder is empty, but following the sudo crontab advice I nonetheless had this come up:


* * * * * "/Library/Internet Plug-Ins/QuickTime.xpt">/dev/null 2>&1


This is neither the Adobe nor the Plug-ins one.


And I still apparently have a DNS Changer issue. Any advice for me to follow would be most gratefully received...

Jul 5, 2012 10:51 AM in response to wjrcbrown

wjrcbrown wrote:


MadMacs0 - what a useful gentleman you are (assuming you are a man, with most humble apologies if you are not).

I am, in fact, a man.

My Internet Plug-ins folder is empty, but following the sudo crontab advice I nonetheless had this come up:


* * * * * "/Library/Internet Plug-Ins/QuickTime.xpt">/dev/null 2>&1


This is neither the Adobe nor the Plug-ins one.


And I still apparently have a DNS Changer issue. Any advice for me to follow would be most gratefully received...

I responded to your other thread. It sounds like you were looking in the wrong Internet Plug-ins folder. The one you want can be found by starting at the root level of your hard drive instead of your home folder.


The file you need to get rid of is "QuickTime.xpt".

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

How do I remove DNS Changer from osx 10.4.11 Several Attempts so far documented. (screenshots attached)

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.