| View previous topic :: View next topic |
| Author |
Message |
amit
Joined: 27 Oct 2008 Posts: 5 Location: India
|
Posted: Mon Oct 27, 2008 4:06 pm Post subject: DNSChanger Trojan Found! |
|
|
Hi,
On checking the log it stated that the system is infected with DNSChanger Trojan.
Resulting in the system with DNS Servers as 85.255.112.118 & 85.255.112.218
I have attached the report which was generated after executing the SDfix file.
Anyhelp would be good.
Amit
| Description: |
|
 Download |
| Filename: |
Report.txt |
| Filesize: |
6.03 KB |
| Downloaded: |
46 Time(s) |
|
|
| Back to top |
|
 |
|
|
patrik Site Admin
Joined: 08 Jan 2006 Posts: 1865
|
Posted: Tue Oct 28, 2008 2:38 am Post subject: |
|
|
Hello amit, welcome to the Myantispyware forum!
Download FixWareout and save it to your desktop.
Run Fixwareout.
Click Next, then Install, then make sure “Run fixit” is checked and click Finish.
The fix will begin, follow the prompts.
You will be asked to reboot your computer, please do so. Your system may take longer than usual to load; this is normal.
At the end of the fix, you may need to restart your computer again.
When the Desktop loads, a text opens (report.txt).
If you are having problems with your Internet connection after running of fixwareout, then:
* Go to Start -> Control Panel ->Network Connections.
* Right click your default connection, usually Local Area Connection or Dial-up Connection, if you are using Dial-up, and left click on Properties.
* Double-click on the Internet Protocol (TCP/IP) item and select the radio button that says Obtain DNS servers automatically. Click OK twice.
* Go to Start -> Run, enter CMD and click OK.
* At the Dos Prompt Screen, type in cd\ and then press ENTER.
* Now type in ipconfig /flushdns and then press ENTER. (notice the space after ipconfig)
* Close the command prompt window.
Download HijackThis (HijackThis Installer - HJTinstall.exe) save it to your Desktop.
Doubleclick on the HJTinstall.exe icon on your desktop for install. Click on Install, It will create a HijackThis icon on the desktop.
Once installed, it will launch Hijackthis. Click on the Do a system scan and save a logfile button. It will scan and the log should open in Notepad.
Post back with following:
- Fixwareout log.
- HijackThis log.
_________________ Free Antispyware: HijackThis, SmitfraudFix, ComboFix, Super Antispyware, Malwarebytes Anti-malware
Instructions: Show hidden files, Reboot in Safe Mode |
|
| Back to top |
|
 |
amit
Joined: 27 Oct 2008 Posts: 5 Location: India
|
Posted: Tue Oct 28, 2008 12:45 pm Post subject: |
|
|
Deleted the registery entries which were stating the IP's.
The IPconfig/all output didnt show the 85*. IPs
I'll reboot and check. How do i confirm that Torgan is no more present in the system.
Thanks for all the help.
Regards,
-Amit
| Description: |
|
 Download |
| Filename: |
hijackthis_log.txt |
| Filesize: |
10.99 KB |
| Downloaded: |
36 Time(s) |
|
|
| Back to top |
|
 |
|
|
patrik Site Admin
Joined: 08 Jan 2006 Posts: 1865
|
Posted: Tue Oct 28, 2008 2:45 pm Post subject: |
|
|
Run HijackThis and scan, put a checkmark next to the following items (if exists):
| Code: | O2 - BHO: (no name) - {1C3C4699-B285-475F-BE47-0B26088CE876} - (no file)
O17 - HKLM\System\CCS\Services\Tcpip\..\{095DBF0D-1C44-4984-AC06-C96A34342964}: NameServer = 85.255.112.118;85.255.112.218
O17 - HKLM\System\CCS\Services\Tcpip\..\{FC78A2DC-41FC-481D-8BD2-FA020E5B99BE}: NameServer = 85.255.112.118;85.255.112.218
O22 - SharedTaskScheduler: beers - {b8ea5f37-7327-4923-9808-8fd3b6f0d529} - (no file) |
Now close all browser and other windows except for HijackThis, and click “Fix Checked” to have HijackThis fix the entries you checked.
Run Fixwareout.
Click Next, then Install, then make sure “Run fixit” is checked and click Finish.
The fix will begin, follow the prompts.
You will be asked to reboot your computer, please do so. Your system may take longer than usual to load; this is normal.
At the end of the fix, you may need to restart your computer again.
When the Desktop loads, a text opens (report.txt).
Post back wit following:
1. Fixwareout report
2. HijackThis log
_________________ Free Antispyware: HijackThis, SmitfraudFix, ComboFix, Super Antispyware, Malwarebytes Anti-malware
Instructions: Show hidden files, Reboot in Safe Mode |
|
| Back to top |
|
 |
amit
Joined: 27 Oct 2008 Posts: 5 Location: India
|
Posted: Fri Oct 31, 2008 9:30 am Post subject: |
|
|
I deleted the entries prior to that some more.
I can not join my laptop to the domain with the current local id and the GAL is no more availbe on my MS Outlook.
Thanks,
Amit
| Description: |
| This report was generated using spy-ware doctor version 6.0.0.386 using the Malware detective tool. |
|
 Download |
| Filename: |
Malware Detective Report.zip |
| Filesize: |
68.21 KB |
| Downloaded: |
23 Time(s) |
| Description: |
| hijackthis_oct_31_08 - second log file --> i deleted the domain name entry which I had manually changed way back when the system was infected. |
|
 Download |
| Filename: |
hijackthis_oct_31_08_second_run.txt |
| Filesize: |
11.08 KB |
| Downloaded: |
26 Time(s) |
| Description: |
| hijackthis_oct_31_08 - current log file |
|
 Download |
| Filename: |
hijackthis_oct_31_08.txt |
| Filesize: |
10.41 KB |
| Downloaded: |
27 Time(s) |
|
|
| Back to top |
|
 |
patrik Site Admin
Joined: 08 Jan 2006 Posts: 1865
|
|
| Back to top |
|
 |
|
|
amit
Joined: 27 Oct 2008 Posts: 5 Location: India
|
Posted: Fri Oct 31, 2008 3:52 pm Post subject: |
|
|
I can access internet from my machine. Internet access is not a problem.
GAL - Global Access List from Exchange on Ms Outlook.
The machine was not in the domain and when I try adding the machine to the domain it did not join the domain. I made a new user on my laptop and then tried joining the machine in the domain it did.
Just thinking what could be the problem.
_________________ -Regards,
Amit |
|
| Back to top |
|
 |
patrik Site Admin
Joined: 08 Jan 2006 Posts: 1865
|
|
| Back to top |
|
 |
amit
Joined: 27 Oct 2008 Posts: 5 Location: India
|
Posted: Fri Oct 31, 2008 4:10 pm Post subject: |
|
|
Yes that be the domain. I have restored the entry now and will update after restarting the sytem.
_________________ -Regards,
Amit |
|
| Back to top |
|
 |
|
|
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You can attach files in this forum You can download files in this forum
|
|