What the Tech logo
Welcome Guest to What the Tech! ( Log In | Register ) • We clean malware from computers for free, and answer tech questions for fun.
• It's fast, friendly and 100% free! • Register Now • Spyware, Virus, Trojan, Rootkit? Read this before posting • Learn how it works
 
Closed TopicStart new topic
> [Resolved] Hijack This Logs - Unable to change DNS servers, Hijack This Logs - Unable to change DNS servers
niroowns
post Dec 9 2008, 01:06 PM
Post #1


New Member
*

Group: New Member
Posts: 2
Joined: 9-December 08
Member No.: 82,830
Operating System: Windoes XP



Hi,

I was recently infected with a virus on my computer (win32/heur). I used AVG and HijackThis to safely (from what I can tell anyhow) clean out most instances of the virus. However, it seems to have also added information to my tcp/ip settings to use a DNS server. I have tried numerous things, but still can not change the 2 IP's that are hard coded there. Can someone pls help? Below are the HijackThis logs (I have bolded what I see to be problematic). Here are the steps I took to try and correct the issue without any luck:

1) Selected all occurences of O17 below and "fix checked"
2) Went to the tcp/ip settings of my Local Area Connection and check off "Obtain DNS server automatically".
3) Re-started my computer
4) Once rebooted, ran "ipconfig /flushdns"
5) Re-started computer again
6) Did another scan with HijackThis, but had exact re-occurrences of O17 below...

Any help is appreciated! Thanks in advance.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:03:08 PM, on 12/9/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp /HIDEBL
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2A9146F3-E5DE-48D8-8B53-E1214450B778} (Generator Class) - http://users.rcn.com/hornms/MachineID.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1219755032718
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://attwm.webex.com/client/T25L10NSP41E...bex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A78999CA-CB43-42CE-B406-28895F808FD6}: NameServer = 85.255.116.150;85.255.112.24
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.150;85.255.112.24
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.116.150;85.255.112.24
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.150;85.255.112.24

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe

--
End of file - 5650 bytes
Go to the top of the page
 
+Quote Post
IndiGenus
post Dec 9 2008, 04:29 PM
Post #2


Anti-Malware Buddha
Group Icon

Group: Malware Expert
Posts: 5,249
Joined: 22-July 04
From: New England, USA
Member No.: 10,811
Operating System: Windows XP Pro SP3 ~ Vista Ultimate SP2 ~ Windows 7 Ultimate



Hello niroowns and welcome to the forums here at WTT!

welcome.gif

There is a new variant of this Wareout infection that is changing the settings in routers, if present. Do you have a router? If so proceed with the following instructions. If not let me know.

Please download Malwarebytes' Anti-Malware from Here or Here

Next disconnect your system from the internet, and your router, then…

Double Click mbam-setup.exe to install the application.
  • Launch Malwarebytes' Anti-Malware, then click Finish.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
===============================================

Next you must reset the router to its default configuration. This can be done by inserting something tiny like a paper clip end or pencil tip into a small hole labeled "reset" located on the back of the router. Press and hold down the small button inside until the lights on the front of the router blink off and then on again (usually about 10 seconds). If you don’t know the router's default password, you can look it up HERE

However, if there are other Zlob-infected machines using the same router, they will need to be cleared with the above steps before resetting the router. Otherwise, the malware will simply go back and change the router's DNS settings. You also need to reconfigure any security settings you had in place prior to the reset. Check out this site here for video tutorials on how to properly configure your router's encryption and security settings. You may also need to consult with your Internet service provider to find out which DNS servers your network should be using.

Once you have ran Malwarebytes' Anti-Malware on the infected system, and reset the router to its default configuration you can reconnect to the internet, and router. Then return to this site to post your logs.

===============================================

Please post the Malwarebytes log and a new HijackThis log, and also let me know how things are running now.

Go to the top of the page
 
+Quote Post
IndiGenus
post Dec 14 2008, 08:23 AM
Post #3


Anti-Malware Buddha
Group Icon

Group: Malware Expert
Posts: 5,249
Joined: 22-July 04
From: New England, USA
Member No.: 10,811
Operating System: Windows XP Pro SP3 ~ Vista Ultimate SP2 ~ Windows 7 Ultimate



Any update here?
Go to the top of the page
 
+Quote Post
niroowns
post Dec 14 2008, 10:34 AM
Post #4


New Member
*

Group: New Member
Posts: 2
Joined: 9-December 08
Member No.: 82,830
Operating System: Windoes XP



QUOTE (IndiGenus @ Dec 14 2008, 09:23 AM) *
Any update here?


Sorry for the delay - the fix worked great! Thanks for the help and guidance!
Go to the top of the page
 
+Quote Post
IndiGenus
post Dec 14 2008, 02:05 PM
Post #5


Anti-Malware Buddha
Group Icon

Group: Malware Expert
Posts: 5,249
Joined: 22-July 04
From: New England, USA
Member No.: 10,811
Operating System: Windows XP Pro SP3 ~ Vista Ultimate SP2 ~ Windows 7 Ultimate



Glad it worked out. You should post the logs and we may want to run another scan or 2 to make sure you are all clean. Absence of symptoms does not always mean a clean PC. Up to you...
Go to the top of the page
 
+Quote Post
IndiGenus
post Dec 19 2008, 02:00 PM
Post #6


Anti-Malware Buddha
Group Icon

Group: Malware Expert
Posts: 5,249
Joined: 22-July 04
From: New England, USA
Member No.: 10,811
Operating System: Windows XP Pro SP3 ~ Vista Ultimate SP2 ~ Windows 7 Ultimate



Since this issue appears to be resolved ... this Topic has been closed. Glad we could be of assistance.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

Go to the top of the page
 
+Quote Post

Closed TopicStart new topic

Collapse

> Similar Topics

    Topic Title Replies Topic Starter Views Last Action
No New Posts   8 Kendo 2,932 27th June 2003 - 11:54 PM
Last post by: Galadriel
No New Posts   3 exposedone 1,663 24th May 2005 - 07:19 PM
Last post by: pskelley
No New Posts   5 -golfer59- 1,368 14th November 2003 - 11:04 AM
Last post by: cnm
No New Posts   4 burnt horns 1,018 15th March 2005 - 07:46 AM
Last post by: pskelley
No New Posts   7 chrose 1,199 13th October 2006 - 02:11 PM
Last post by: Micah_6:8


 

RSS Time is now: 17th May 2012 - 03:33 AM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy