My Anti Spyware
News, Free Programs, Online Scanners, Tutorials
Post your problems with Spyware, Hijackers, Trojans...
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister     ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

DNSChanger Trojan Found!

 
Post new topic   Reply to topic    My Anti Spyware Forum Index -> Spyware Removal
View previous topic :: View next topic  
Author Message
amit



Joined: 27 Oct 2008
Posts: 5
Location: India

PostPosted: Mon Oct 27, 2008 4:06 pm    Post subject: DNSChanger Trojan Found! Reply with quote

Hi,

On checking the log it stated that the system is infected with DNSChanger Trojan.

Resulting in the system with DNS Servers as 85.255.112.118 & 85.255.112.218

I have attached the report which was generated after executing the SDfix file.

Anyhelp would be good.

Amit



Report.txt
 Description:
SDfix report

Download
 Filename:  Report.txt
 Filesize:  6.03 KB
 Downloaded:  46 Time(s)

Back to top
View user's profile Send private message
patrik
Site Admin


Joined: 08 Jan 2006
Posts: 1865

PostPosted: Tue Oct 28, 2008 2:38 am    Post subject: Reply with quote

Hello amit, welcome to the Myantispyware forum!

Download FixWareout and save it to your desktop.
Run Fixwareout.
Click Next, then Install, then make sure “Run fixit” is checked and click Finish.
The fix will begin, follow the prompts.
You will be asked to reboot your computer, please do so. Your system may take longer than usual to load; this is normal.
At the end of the fix, you may need to restart your computer again.
When the Desktop loads, a text opens (report.txt).

If you are having problems with your Internet connection after running of fixwareout, then:
* Go to Start -> Control Panel ->Network Connections.
* Right click your default connection, usually Local Area Connection or Dial-up Connection, if you are using Dial-up, and left click on Properties.
* Double-click on the Internet Protocol (TCP/IP) item and select the radio button that says Obtain DNS servers automatically. Click OK twice.
* Go to Start -> Run, enter CMD and click OK.
* At the Dos Prompt Screen, type in cd\ and then press ENTER.
* Now type in ipconfig /flushdns and then press ENTER. (notice the space after ipconfig)
* Close the command prompt window.

Download HijackThis (HijackThis Installer - HJTinstall.exe) save it to your Desktop.
Doubleclick on the HJTinstall.exe icon on your desktop for install. Click on Install, It will create a HijackThis icon on the desktop.

Once installed, it will launch Hijackthis. Click on the Do a system scan and save a logfile button. It will scan and the log should open in Notepad.

Post back with following:
- Fixwareout log.
- HijackThis log.

_________________
Free Antispyware: HijackThis, SmitfraudFix, ComboFix, Super Antispyware, Malwarebytes Anti-malware
Instructions: Show hidden files, Reboot in Safe Mode
Back to top
View user's profile Send private message Send e-mail
amit



Joined: 27 Oct 2008
Posts: 5
Location: India

PostPosted: Tue Oct 28, 2008 12:45 pm    Post subject: Reply with quote

Deleted the registery entries which were stating the IP's.

The IPconfig/all output didnt show the 85*. IPs

I'll reboot and check. How do i confirm that Torgan is no more present in the system.

Thanks for all the help.

Regards,
-Amit



hijackthis_log.txt
 Description:
hijackthis

Download
 Filename:  hijackthis_log.txt
 Filesize:  10.99 KB
 Downloaded:  36 Time(s)

Back to top
View user's profile Send private message
patrik
Site Admin


Joined: 08 Jan 2006
Posts: 1865

PostPosted: Tue Oct 28, 2008 2:45 pm    Post subject: Reply with quote

Run HijackThis and scan, put a checkmark next to the following items (if exists):
Code:
O2 - BHO: (no name) - {1C3C4699-B285-475F-BE47-0B26088CE876} - (no file)
O17 - HKLM\System\CCS\Services\Tcpip\..\{095DBF0D-1C44-4984-AC06-C96A34342964}: NameServer = 85.255.112.118;85.255.112.218
O17 - HKLM\System\CCS\Services\Tcpip\..\{FC78A2DC-41FC-481D-8BD2-FA020E5B99BE}: NameServer = 85.255.112.118;85.255.112.218
O22 - SharedTaskScheduler: beers - {b8ea5f37-7327-4923-9808-8fd3b6f0d529} - (no file)

Now close all browser and other windows except for HijackThis, and click “Fix Checked” to have HijackThis fix the entries you checked.

Run Fixwareout.
Click Next, then Install, then make sure “Run fixit” is checked and click Finish.
The fix will begin, follow the prompts.
You will be asked to reboot your computer, please do so. Your system may take longer than usual to load; this is normal.
At the end of the fix, you may need to restart your computer again.
When the Desktop loads, a text opens (report.txt).

Post back wit following:
1. Fixwareout report
2. HijackThis log

_________________
Free Antispyware: HijackThis, SmitfraudFix, ComboFix, Super Antispyware, Malwarebytes Anti-malware
Instructions: Show hidden files, Reboot in Safe Mode
Back to top
View user's profile Send private message Send e-mail
amit



Joined: 27 Oct 2008
Posts: 5
Location: India

PostPosted: Fri Oct 31, 2008 9:30 am    Post subject: Reply with quote

I deleted the entries prior to that some more.
I can not join my laptop to the domain with the current local id and the GAL is no more availbe on my MS Outlook.

Thanks,
Amit



Malware Detective Report.zip
 Description:
This report was generated using spy-ware doctor version 6.0.0.386 using the Malware detective tool.

Download
 Filename:  Malware Detective Report.zip
 Filesize:  68.21 KB
 Downloaded:  23 Time(s)


hijackthis_oct_31_08_second_run.txt
 Description:
hijackthis_oct_31_08 - second log file --> i deleted the domain name entry which I had manually changed way back when the system was infected.

Download
 Filename:  hijackthis_oct_31_08_second_run.txt
 Filesize:  11.08 KB
 Downloaded:  26 Time(s)


hijackthis_oct_31_08.txt
 Description:
hijackthis_oct_31_08 - current log file

Download
 Filename:  hijackthis_oct_31_08.txt
 Filesize:  10.41 KB
 Downloaded:  27 Time(s)

Back to top
View user's profile Send private message
patrik
Site Admin


Joined: 08 Jan 2006
Posts: 1865

PostPosted: Fri Oct 31, 2008 3:47 pm    Post subject: Reply with quote

HijackThis log looks ok.

Quote:
I can not join my laptop to the domain with the current local id

You have a problem with Internet access ?

Quote:
the GAL is no more availbe on my MS Outlook.

Whats GAL ? Give me more details.

_________________
Free Antispyware: HijackThis, SmitfraudFix, ComboFix, Super Antispyware, Malwarebytes Anti-malware
Instructions: Show hidden files, Reboot in Safe Mode
Back to top
View user's profile Send private message Send e-mail
amit



Joined: 27 Oct 2008
Posts: 5
Location: India

PostPosted: Fri Oct 31, 2008 3:52 pm    Post subject: Reply with quote

I can access internet from my machine. Internet access is not a problem.

GAL - Global Access List from Exchange on Ms Outlook.

The machine was not in the domain and when I try adding the machine to the domain it did not join the domain. I made a new user on my laptop and then tried joining the machine in the domain it did.

Just thinking what could be the problem.

_________________
-Regards,
Amit
Back to top
View user's profile Send private message
patrik
Site Admin


Joined: 08 Jan 2006
Posts: 1865

PostPosted: Fri Oct 31, 2008 4:08 pm    Post subject: Reply with quote

One tcpip parameter has been removed from registry.
Code:
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = hyperquality.com

hyperquality.com is your domain?

_________________
Free Antispyware: HijackThis, SmitfraudFix, ComboFix, Super Antispyware, Malwarebytes Anti-malware
Instructions: Show hidden files, Reboot in Safe Mode
Back to top
View user's profile Send private message Send e-mail
amit



Joined: 27 Oct 2008
Posts: 5
Location: India

PostPosted: Fri Oct 31, 2008 4:10 pm    Post subject: Reply with quote

Yes that be the domain. I have restored the entry now and will update after restarting the sytem.
_________________
-Regards,
Amit
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    My Anti Spyware Forum Index -> Spyware Removal All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group
phpBB SEO