The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.
 Next page →

    Did NBR give me a virus on my Mac?!?!

    Discussion in 'Apple and Mac OS X' started by PopRoxMimo3, Sep 23, 2010.

  1. PopRoxMimo3

    PopRoxMimo3 Notebook Deity

    Reputations:
    82
    Messages:
    1,090
    Likes Received:
    1
    Trophy Points:
    56
  2. Nick

    Nick Professor Carnista

    Reputations:
    3,870
    Messages:
    4,089
    Likes Received:
    649
    Trophy Points:
    181
    Of course they gave you a virus, they're evil, and want SS number, credit card password(they already have the number), and your PayPal password.
    BEWARE OF NBR, THEY ARE TRYING TO STEAL OUR LIVES

    Naw, just kidding, maybe NBR is infected or something
     
    Last edited by a moderator: May 8, 2015
  3. PopRoxMimo3

    PopRoxMimo3 Notebook Deity

    Reputations:
    82
    Messages:
    1,090
    Likes Received:
    1
    Trophy Points:
    56
    I knew it!!!!

    No but seriously i click on nbr and that dialog box pops up, hit cancel and the fake scan happens.
     
  4. pbcustom98

    pbcustom98 Goldmember

    Reputations:
    405
    Messages:
    1,654
    Likes Received:
    0
    Trophy Points:
    55
    That isn't NBR. it has the wrong IP.


    mbp:~ Daniel$ ping _www.notebookreview.com_
    PING _www.notebookreview.com_ (75.126.235.189): 56 data bytes
    64 bytes from 75.126.235.189: icmp_seq=0 ttl=113 time=51.862 ms
    64 bytes from 75.126.235.189: icmp_seq=1 ttl=113 time=50.021 ms
    64 bytes from 75.126.235.189: icmp_seq=2 ttl=113 time=49.965 ms
    64 bytes from 75.126.235.189: icmp_seq=3 ttl=113 time=50.288 ms
    64 bytes from 75.126.235.189: icmp_seq=4 ttl=113 time=49.689 ms
    64 bytes from 75.126.235.189: icmp_seq=5 ttl=113 time=56.774 ms
    64 bytes from 75.126.235.189: icmp_seq=6 ttl=113 time=50.096 ms
    ^C
    --- _/www.notebookreview.com_ ping statistics ---
    7 packets transmitted, 7 packets received, 0.0% packet loss
    round-trip min/avg/max/stddev = 49.689/51.242/56.774/2.353 ms
    mbp:~ Daniel$
     
  5. doh123

    doh123 Without ME its just AWESO

    Reputations:
    996
    Messages:
    3,727
    Likes Received:
    1
    Trophy Points:
    106
    If I was you... and your serious.. and that picture is really from your computer... and you didn't go to that IP address and port on purpose... I'd check to see if I had some malware changing my DNS settings to hacker server.
     
  6. DboogieC

    DboogieC Notebook Deity

    Reputations:
    580
    Messages:
    1,010
    Likes Received:
    0
    Trophy Points:
    0
    mac and virus ? i thought id never see the day !
     
  7. Greg

    Greg Notebook Nobel Laureate

    Reputations:
    7,857
    Messages:
    16,212
    Likes Received:
    58
    Trophy Points:
    466
    You need to ping forum.notebookreview.com to get the IP address for the forum. That being said I'm reporting this thread to see if we can get any input from the admins.
     
  8. pbcustom98

    pbcustom98 Goldmember

    Reputations:
    405
    Messages:
    1,654
    Likes Received:
    0
    Trophy Points:
    55
    good call. this me pinging forum.notebookreview.com


    Last login: Thu Sep 23 19:10:07 on console
    mbp:~ Daniel$ ping _forum.notebookreview.com_
    PING forum.notebookreview.com (67.228.47.50): 56 data bytes
    64 bytes from 67.228.47.50: icmp_seq=0 ttl=52 time=56.256 ms
    64 bytes from 67.228.47.50: icmp_seq=1 ttl=52 time=57.109 ms
    64 bytes from 67.228.47.50: icmp_seq=2 ttl=52 time=59.593 ms
    64 bytes from 67.228.47.50: icmp_seq=3 ttl=52 time=59.505 ms
    64 bytes from 67.228.47.50: icmp_seq=4 ttl=52 time=54.638 ms
    ^C
    --- _forum.notebookreview.com_ ping statistics ---
    5 packets transmitted, 5 packets received, 0.0% packet loss
    round-trip min/avg/max/stddev = 54.638/57.420/59.593/1.911 ms
    mbp:~ Daniel$

    I inserted underscores before and after the url so it doesnt change it to links.
     
  9. PopRoxMimo3

    PopRoxMimo3 Notebook Deity

    Reputations:
    82
    Messages:
    1,090
    Likes Received:
    1
    Trophy Points:
    56
    How do i go about pinging? i mean what do i do?

    I use a linksys wrt54g route/wireless point. the thing popped up when it was plugged in
     
  10. Kaelang

    Kaelang Requires more Witcher.

    Reputations:
    717
    Messages:
    1,210
    Likes Received:
    0
    Trophy Points:
    55
    Pinging forum.notebookreview.com [67.228.47.50] with 32 bytes of data:
    Reply from 67.228.47.50: bytes=32 time=43ms TTL=51
    Reply from 67.228.47.50: bytes=32 time=46ms TTL=51
    Reply from 67.228.47.50: bytes=32 time=44ms TTL=51
    Reply from 67.228.47.50: bytes=32 time=43ms TTL=51
     
  11. jubbing

    jubbing Notebook Deity

    Reputations:
    243
    Messages:
    852
    Likes Received:
    1
    Trophy Points:
    31
    You're kidding right? Mac's aren't virus free anymore lol.
     
  12. Xirurg

    Xirurg ORLY???

    Reputations:
    3,189
    Messages:
    7,375
    Likes Received:
    3
    Trophy Points:
    206
    ^ so cool,right?
     
  13. pjshots

    pjshots Notebook Consultant

    Reputations:
    23
    Messages:
    124
    Likes Received:
    0
    Trophy Points:
    30
    Its fake people! A scam to get you to download a piece of spyware. I see these sometimes on other users machines, don't know how they appear but can do when you visit sites.

    Besides.... Since when does a mac call its disks Local Disk C, Local Disk D, etc?!
     
  14. Jervis961

    Jervis961 Hall monitor

    Reputations:
    558
    Messages:
    952
    Likes Received:
    0
    Trophy Points:
    30
    I also noticed that the trojans are Windows ones (Win32). Typical scare tactic to trick people into a scam. I know a few people who have fallen for it.
     
  15. fgielow

    fgielow Notebook Enthusiast

    Reputations:
    0
    Messages:
    44
    Likes Received:
    0
    Trophy Points:
    15
    Code:
    fernando@Gielow:~$ nslookup 187.36.73.182
    
    Non-authoritative answer:
    182.73.36.187.in-addr.arpa	name = bb2449b6.virtua.com.br.
    
    Authoritative answers can be found from:
    


    Apparently it is a scam hosted by someone from brazil (not me lol), who uses NET Virtua as their ISP.

    Or is my guessing wrong?
     
  16. GadgetsNut

    GadgetsNut Notebook Evangelist

    Reputations:
    187
    Messages:
    493
    Likes Received:
    15
    Trophy Points:
    31
    Yeah it's a fake. My Network Places? Control Panel??? This is one of those fake popups for Windows, you click on it and THEN your system will be infested. Many people fall for this - I've had to help a few clean their systems.

    Whoever wrote it wasn't sophisticated enough to detect OSX and show a popup "customized" for the Mac ;)

     
  17. doh123

    doh123 Without ME its just AWESO

    Reputations:
    996
    Messages:
    3,727
    Likes Received:
    1
    Trophy Points:
    106
    I had one pop up one time that made it look like a Windows Xp Explorer window and a test virus scan that ran through saying it found all types of problems... funny since I was on OSX and had no VM running or anything, but if I had been on XP it would have looked real.
     
  18. fgielow

    fgielow Notebook Enthusiast

    Reputations:
    0
    Messages:
    44
    Likes Received:
    0
    Trophy Points:
    15
    People use this kind of scam for two things, generally.
    1) try to sell you an anti-virus
    2) try to infect you

    But I think it cannot do harm to Mac OS X, since it is obviously intended to affect Windows :p
     
  19. PopRoxMimo3

    PopRoxMimo3 Notebook Deity

    Reputations:
    82
    Messages:
    1,090
    Likes Received:
    1
    Trophy Points:
    56
    what i wonder how it got there. I clicked on my NBR bookmark and it popped up.
     
  20. Kaelang

    Kaelang Requires more Witcher.

    Reputations:
    717
    Messages:
    1,210
    Likes Received:
    0
    Trophy Points:
    55
    It sounds like a redirect spyware or virus.
    I don't know if there are free scanners for Macs but you might want to err on the side of safety. Never get too comfortable.
     
  21. fgielow

    fgielow Notebook Enthusiast

    Reputations:
    0
    Messages:
    44
    Likes Received:
    0
    Trophy Points:
    15
    Actually, it doesnt seem a reason for much concearn to me..

    This website was intended to attack windows, the only weird thing is how it popped up on your screen :p This kind of websites has appeared several times to me, but I am currently running Linux, so, whatever.

    I don't think that whoever hosts this website would do a DNS attack so that they get other names to point to their IP address. Also, I don't know how feasable it is for anyone to change the hosts file in the Mac OS X.

    Normally (I THINK, not entirely sure, but I am pretty convinced lol), SOs have a file in which you can store a name and its corresponding IP, so that that this configuration is checked before consulting the DNS - if someone can mess with that file, it would be easier and as effective as a DNS attack. If I am talking bull, someone please correct me.


    And sorry if I was unclear, my english was getting rusty. lol xD




    Fernando
     
  22. Kaelang

    Kaelang Requires more Witcher.

    Reputations:
    717
    Messages:
    1,210
    Likes Received:
    0
    Trophy Points:
    55
    If his bookmark has the correct URL (forum.notebookreview.com), then something redirected him to that page. Sounds like something on his end, since no-one else is reporting this.
     
  23. Seshan

    Seshan Rawrrr!

    Reputations:
    540
    Messages:
    1,989
    Likes Received:
    0
    Trophy Points:
    55
    Are you on wifi? Is it secure? It could of been a posible MiTM attack.
     
  24. PopRoxMimo3

    PopRoxMimo3 Notebook Deity

    Reputations:
    82
    Messages:
    1,090
    Likes Received:
    1
    Trophy Points:
    56
    it popped up when i was plugged into the router, but never popped up when i was using the wifi.
     
  25. doh123

    doh123 Without ME its just AWESO

    Reputations:
    996
    Messages:
    3,727
    Likes Received:
    1
    Trophy Points:
    106
    you really should check if your router or computer has compromised DNS servers set, and not your ISPs default.
     
  26. PopRoxMimo3

    PopRoxMimo3 Notebook Deity

    Reputations:
    82
    Messages:
    1,090
    Likes Received:
    1
    Trophy Points:
    56
    no idea on how to do that
     
  27. PopRoxMimo3

    PopRoxMimo3 Notebook Deity

    Reputations:
    82
    Messages:
    1,090
    Likes Received:
    1
    Trophy Points:
    56
    Just happened again... right after I hooked up to the router.

    [​IMG]
     
  28. fgielow

    fgielow Notebook Enthusiast

    Reputations:
    0
    Messages:
    44
    Likes Received:
    0
    Trophy Points:
    15
    It popped up from nothing, or did you try entering a website, then it appeared?
     
  29. Kaelang

    Kaelang Requires more Witcher.

    Reputations:
    717
    Messages:
    1,210
    Likes Received:
    0
    Trophy Points:
    55
    Does this happen on wireless networks?
    If it happens regardless of the network, it appears you have a deeper problem.

    I blame Facebook.
     
  30. PopRoxMimo3

    PopRoxMimo3 Notebook Deity

    Reputations:
    82
    Messages:
    1,090
    Likes Received:
    1
    Trophy Points:
    56
    I clicked the facebook bookmark and it happened.

    I just shut off the wireless router and hooked up my mac to the CLEAR modem directly.
     
  31. PopRoxMimo3

    PopRoxMimo3 Notebook Deity

    Reputations:
    82
    Messages:
    1,090
    Likes Received:
    1
    Trophy Points:
    56
    I was at my college, used the Wifi, no pop up.
    This pop up happens, i believe, only when i use the router.
     
  32. Kaelang

    Kaelang Requires more Witcher.

    Reputations:
    717
    Messages:
    1,210
    Likes Received:
    0
    Trophy Points:
    55
    If you can, try a different network, like a McDonalds if there's one near you.
    Unless there's a better way to determine what's going on here, which I'm sure there is.
     
  33. fgielow

    fgielow Notebook Enthusiast

    Reputations:
    0
    Messages:
    44
    Likes Received:
    0
    Trophy Points:
    15
    You know how to enter your router configuration and change its DNS?
    Try using OpenDNS.

    Use 208.67.222.222 as primary mirror
    and 208.67.220.220 as secondary

    (source: OpenDNS | Internet Navigation And Security)

    Just remember to take note of the IPs you were using as DNS before, in case you want to switch back.

    If it is your ISP that provides your DNS and you can't change it, then it is either their DNS fault, or, it is nothing related to DNS (I say this because before this website appeared as NBR, and now it appeared as facebook, ?).



    Ah, another think.
    are you able to access facebook if you try again, or you end up accessing this website EVERYTIME you try to access facebook?
     
  34. Nick

    Nick Professor Carnista

    Reputations:
    3,870
    Messages:
    4,089
    Likes Received:
    649
    Trophy Points:
    181
    Why are you worried, the pop up is for a PC and you have a Mac :)
     
  35. fgielow

    fgielow Notebook Enthusiast

    Reputations:
    0
    Messages:
    44
    Likes Received:
    0
    Trophy Points:
    15
    I think that this thing will do no harm, either. Buuut. It is annoying xD If it happened to me I would try to get rid of it too hahahaha
     
  36. Kaelang

    Kaelang Requires more Witcher.

    Reputations:
    717
    Messages:
    1,210
    Likes Received:
    0
    Trophy Points:
    55
    If it's not his network that's causing the issue, obviously it's something on his computer.
    Regardless of what it looks like, it can still be harmful.

    Nothing has been ruled out by the OP, far as I can tell.

    I googled that message from the screenshot:
    http://forums.cnet.com/5208-6122_102-0.html?threadID=341855
    https://www.microsoft.com/security/...edia/Entry.aspx?Name=Worm:Win32/Prolaco.gen!B

    Seems like you have the symptoms of a scam thing. I'm slightly confused.
    http://answers.yahoo.com/question/index?qid=20090131191758AAjsqmG

    I guess it won't hurt you, but I still wouldn't be comfortable leaving it alone. Eradicate it!
     
  37. unnamed01

    unnamed01 Notebook Deity

    Reputations:
    194
    Messages:
    982
    Likes Received:
    0
    Trophy Points:
    30
    Just play more Starcraft 2. Looks like one of those "YOU 34789 VIRUS' CLICK HERE TO REMOVE!" things.
     
  38. Sladerade

    Sladerade Notebook Consultant

    Reputations:
    168
    Messages:
    229
    Likes Received:
    6
    Trophy Points:
    31
    Let me get this straight, when you go straight into the Clear modem you have no pop up ad? But when you hook up to YOUR wireless router you get the pop up ads?

    If that's the case someone managed to get into your wireless router and change the routing of the DNS server that is provided by Clear.

    layman terms your router was hacked into and they changed the DNS server ip address. So no matter what site you go to it provides there crap that they have linked to. (this is only if its with YOUR wireless router)

    If that is the problem do a hard reset on your wireless router. push the reset button for 30 seconds keep holding and unplug the power and keep holding it for another 30 sec, then plug in the power and still keep holding it for another 30 seconds. total of 90 seconds holding down the reset button to do a Hard reset

    If it does this on other wireless networks ex. starbucks (now free) friends house, school campus's and any other place you can get internet then you have a problem internally. Either its a trojan or a program that you installed that can change you DNS setting in your system preferences.
     
  39. Kaelang

    Kaelang Requires more Witcher.

    Reputations:
    717
    Messages:
    1,210
    Likes Received:
    0
    Trophy Points:
    55
    That's kinda where I was going, but no-one seems to think it's a big deal. I figured if it's something on his computer that's changing settings or something, it doesn't matter if you have OS X or not, you have a problem, the problem is evident. Something has already gone wrong.

    Of course, if it's just the router, you're fine. Do the reset if you can and see if it goes away, or try a different network.
     
  40. DJRiful

    DJRiful Notebook Consultant

    Reputations:
    23
    Messages:
    289
    Likes Received:
    0
    Trophy Points:
    30
    Why So Serious?
     
  41. doh123

    doh123 Without ME its just AWESO

    Reputations:
    996
    Messages:
    3,727
    Likes Received:
    1
    Trophy Points:
    106
    compromised DNS server on your set up is always a big deal.

    a DNS server is where address look up happens. When you type something in like "http://www.notebookreview.com" it has no idea what that means or how to get there... it checks with your DNS server, and the DNS server says... oh heres the actual real address to there... so you can get there. If your DNS server is compromised, your life can get a mess. They can redirect to phishing sites and steal all types of info from you. Say you go to your bank website, or paypal or anything directly by typing in the right URL... it can be a totally fake website that looks real... as soon as you type in a user name and password... its stolen. Now some criminals have your log ins and do whatever they want with them.
     
  42. fgielow

    fgielow Notebook Enthusiast

    Reputations:
    0
    Messages:
    44
    Likes Received:
    0
    Trophy Points:
    15
    and that's why it is always necessary to check if a website's identity is verified. Websites with https encryptions must have their identities checked by third ones, such as verisign. So, if your browser says that something is wrong with the HTTPS encryption, go away! specially in case of bank accounts or whatever. There are cases in which websites use https but aren't really verified by any entity, but I can assure you that this is not the case of paypal, email accounts, or any bank websites :p
     
  43. PopRoxMimo3

    PopRoxMimo3 Notebook Deity

    Reputations:
    82
    Messages:
    1,090
    Likes Received:
    1
    Trophy Points:
    56
    I reset the router. What should I do next to set it up properly that way it does not happen again? Any way I can only allow certain laptops, wii, ps3, ipod touch, or phones to hook up to my router. An old friend of mine, who i have lost contact with, was able to write down my laptops adress, go into his router, add my laptops address, and only then would i be able to access the web.
    my router is a wrt54g
     
  44. doh123

    doh123 Without ME its just AWESO

    Reputations:
    996
    Messages:
    3,727
    Likes Received:
    1
    Trophy Points:
    106
    sure.. most routers have options to limit by MAC address...
    That slows down a hacker a couple of minutes or more as they have to figure out a valid MAC and spoof it.... which isn't too hard to do, but you may have to monitor the network for awhile for a machine with a valid MAC to connect.

    make sure its all locked down WPA2 encryption as well.

    Not really a whole lot you can do if someone really really wants in... but people driving around hacking WIFI routers for DNS attacks isn't exactly common... just make sure you have your firmware updated on the router in case there is any remote exploits that have been fixed.... and use your ISPs issued DNS server, or OpenDNS is decent.
     
  45. pbcustom98

    pbcustom98 Goldmember

    Reputations:
    405
    Messages:
    1,654
    Likes Received:
    0
    Trophy Points:
    55
    also, check your bookmarks to see where they are pointing to.

    i see you are using safari, so follow these instructions

    1) open safari.
    2) on the menu bar, go to bookmarks -> bookmark manager
    3) once that opens, go to the folder you put your bookmarks in, and look at the bookmarks in question. to the right shows the address they are going to. you can right click on them, and edit the address.

    if it still doesnt work, you there is a bigger problem...
     
  46. PopRoxMimo3

    PopRoxMimo3 Notebook Deity

    Reputations:
    82
    Messages:
    1,090
    Likes Received:
    1
    Trophy Points:
    56
    i did the router reset. havent had the problem since.
     
  47. gms238

    gms238 Notebook Consultant

    Reputations:
    8
    Messages:
    133
    Likes Received:
    0
    Trophy Points:
    30
    Another lesson to learn: never, NEVER click on a pop-up. Ever!
     
  48. Sladerade

    Sladerade Notebook Consultant

    Reputations:
    168
    Messages:
    229
    Likes Received:
    6
    Trophy Points:
    31
    I am glad to here that!
     
  49. tenderidol

    tenderidol Notebook Evangelist

    Reputations:
    44
    Messages:
    390
    Likes Received:
    0
    Trophy Points:
    30
    Glad to see that the problem went away, which appears that your router was hacked. The problem is that this is a wireless router in a "static" location. Is it safe to assume that whoever hacked it is most likely "local"?
     
  50. Kaelang

    Kaelang Requires more Witcher.

    Reputations:
    717
    Messages:
    1,210
    Likes Received:
    0
    Trophy Points:
    55
    He did say it was at college, right?
    Not surprising, honestly. :p
     
 Next page →