DNS changer

Discussion in 'Malware Help (A Specialist Will Reply)' started by wacko, Aug 3, 2009.

  1. wacko

    wacko Private E-2

    My gf is having issues with her internet. When you click on a link say from google, 50% of the time, you go to some random website. I believe this to be the work of a DNS changer. I checked that TDSSserv.sys did not exist and it does not. However, when following your "READ & RUN ME FIRST. Malware Removal Guide" i came across several issues.

    1) Superantispyware will not install. Before stumbling across this forum, i managed to get it to instal by changing the name of the install file and the exe file. Towards the end of the scan, the computer would lock up. To follow the guide, i unistalled it and then tried again and it would not instal still. I decided to leave it that way as the guide instructed.

    2) Malware bytes will install but does nothing when you try to run it. Nothing pops up saying it is running and nothing comes up in the task manager. Again, by changing the name of the exe will allow it to run however it does run all the way through. Nothing comes up on that scan. Again, i unistalled it before following the guide.

    3)running rootrepeal i got an error "could not read the boot sector. Try adjusting the disk access level in the options dialog". after closing this box several times (20-30) the scanner was startable. However, it crashed and gave a bunch of crash logs. I have attached those.

    MSG tools was the only program to run without errors.

    I appreciate any help in resolving this bug.
     

    Attached Files:

    Last edited: Aug 3, 2009
  2. wacko

    wacko Private E-2

    and the file that was spat out after mgtools ran
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Did you disable UAC and reboot before trying to run scans? If not, please do so.

    Did you shut down Avast and Windows Defender before trying to run any of our scans? If not, please do so.

    You made no mention of running ComboFix. Did you try it? Did you try it in safe boot mode if it would not run in normal boot mode?


    Did you try running Malwarebytes in safe boot mode?


    You need to attach the log from MGtools that was requested. The procedure told you that the log was the MGlogs.zip file in your root folder.
     
  4. wacko

    wacko Private E-2

    UAC was disabled and then the system rebooted.

    Avast and Windows Defender was shut down.

    Combofix installed but it gets an error message saying "ComboFix.exe has stopped working..." and will not run. It does nothing in Safe mode.

    I tried running malware bytes and installing superantispyware in safe mode, but i encountered the same issues as before.

    Here is the mglogs.zip file that you wanted. Thats my fault for assuming the text log that was spat out was what you were looking for. I should have read a bit more.

    Hope this helps...
     

    Attached Files:

    Last edited: Aug 6, 2009
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm sorry but it did not run properly and is not really going to help us. Please try the below and make sure that UAC is still disabled, that you run as administrator and that you allow it to finish running. Do not close the command prompt window until it tells you it is finished.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the new C:\MGlogs.zip file
     
  6. wacko

    wacko Private E-2

    Here is another scan. It had completed last time also. So hopefully this time it gives you what you need. This time i made sure to run it as admin. I dont remember if i did or not last time.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The logs you have attached do not show any malware problems. If you had something tell you that you had a DNS changer type infection there are two things you should try:

    Click Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /flushdns
    • Hit Enter
    • Exit the command window

    The infection you mentioned is known to infect router hardware. If you have a router hooked up then you need to follow the instructions for your hardware and reset it to factory default settings. Normally there is a recessed push button type switch that needs to be held down for some number of seconds to do this. After resetting to factory defaults on your router, you will need to reconfigure the router for your network if you have made any changes to the default network setup.
     
  8. wacko

    wacko Private E-2

    I tried flushing the DNS and it said it was successful however the problem persisted. The laptop is not connected to any router and has been moved to several different jacks, in different buildings and different parts of the city yet the problem still exists. Tried plugging my computer into the same jack but i did experience any of the symptoms.

    Any suggestions on where to turn next?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run Radix per the below and attach the log

    Using Radix To Detect Rootkits



    Also run the below online scan from Eset and attach the log:

    Using ESET's Online Scanner


    Also please uninstall both SUPERAntiSpyware and Malwarebytes and then reboot your PC. DO NOT SKIP the reboot.



    Now redownload the below:
    Now reinstall both of the above programs and try to run scans with them again. Attach logs if they run.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Two more questions!
    1. Does the problem occur in both Internet Explorer and FireFox browsers?
    2. Does it also happen if you boot in safe mode?
     
  11. wacko

    wacko Private E-2

    The problem does occur in both Internet explorer and firefox.

    Looked in safe mode and i cant connect to the internet at all. I cant even get into the network and sharing center. If i double click the icon it registers that i selected it but does not come up.

    Runnin Radix did not work as it is a vista machine and apparently Radix doesnt work on Vista. It gives a little box saying "Your windows version is currently not supported..." and then asks for a donation via paypal.

    I am running the eset scan now but it seems to be stuck at 31%. the time ticker is still going. Not sure how long this scan is supposed to take. I disabled the antivirus and everything to do with it. Left the firewall up. Ill update when its done or in a couple hours if the scan hasnt gone anywhere
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about the Radix/Vista problem. I forgot you had Vista. I may give you a different scan to run in another message later.


    Earlier you said the below.
    I assume you meant "did not experience".;) But here is another question. The computer with the problem has the default web page and also default search set to www.lge.com which I assume you did not have on your PC. Is this the desired home page and desired default search page?

    What browser addons are setup for FireFox and Internet Explorer? Have you tried disabling them?

    Also please give an example of a Google search and the link clicked on and where exactly you are taken to.


    Also regardless of whether the Eset scan is able to finish or not, please retry what I requested with SUPERAntiSpyware (SAS) and Malwarebytes (MBAM). If SAS installs, try running by clicking Start > All Programs > SUPERAntiSpyware > SUPERAntiSpyware Alternate Start.

    If MBAM reinstalls but does not run properly, make sure there is no process for it showing in Task Manager. If there is, shut it down. Then go to C:\MGtools and double click on the RunMB.bat file to see if it can run MBAM. It tries to rename the program and then run it.


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.



    Now one additional request (remember UAC still needs to be disabled)
    • open up 1 FireFox window
    • open up 1 Internet Explorer window
    • now with the above to windows open, now run the C:\MGtools.exe file by right clicking on it and selecting Run As Administrator).
    Then attach the new C:\MGlogs.zip log
     
    Last edited: Aug 11, 2009
  13. wacko

    wacko Private E-2

    you are correct. should proof read my stuff to make sure it actually makes sense. The default webpage and search was www.lge.com. It came preloaded this way. It is the LG site. (www.lge.com/gateway/index.html is what comes up as her home page) The Laptop is an LG model so i figured it was just factory default.

    Firefox addons:

    EXTENSIONS
    Microsoft .Net Franwork Assistant 1.0
    Skype extension for firfox 3.3.0.3290

    THEMES
    Default 3.5.2

    PLUGINS
    Adobe Acrobat 9.0.163
    BitTorrent 1.0.0.1
    DNA Plug-in 1.0.0.1
    iTunes Application Detector 1.0.1.1
    Java Deployment Toolkit 6.0.140.8 6.0.140.8
    Java(TM) Platform SE 6 U14 6.0.140.8
    Mozilla Default Plug-in 1.0.0.15
    QuickTime Plig-in 7.6.2 7.6.2.0
    Showave Flash 10.0.22.87
    Windows Presentation Foundation 3.5.30729.1

    Internet Explorer addons

    TOOLBARS AND EXTENSIONS
    Adobe PDF Link Helper 9.1.0.163
    Windows Live Sign-in Helper 5.0.818.5
    Research 12.0.6423.0 -->publisher is Microsoft
    Corporation
    Research --> publisher is "not availible"
    Discuss v6.0.6001.18 --> publisher is "not availible"
    Java(TM) Plug-in 2 SSV Helper 6.0.140.8

    SEARCH PROVIDERS
    Google
    Live Search

    ACCELERATORS
    Blog with Windows Live
    Email with Windows Live
    Map with Live Search
    Translate with Live Search

    InPrivate Filtering
    no add ons in this category

    Have not tried disabling any of the addons. Never though to look there to be honest.

    If i insert "Superanti spyware" as the search in google, here are a couple sites that pop up instead of the super antispyware site when clicking on the link to the site:
    www.tazinga.com
    http://125skooble.com (which loads http://smartbizsearch.com)
    and a bunch of other ones.

    The Eset scan eventually locked up the computer after 5hours 13 mins.

    Restarted the computer after uninstalling malwarebytes. Superantispyware was not installed. However, upon trying to reinstal them, i got the same results. Malware bytes installed but would not run and superantispyware would not instal.

    Ran the MGTools with the two windows open and here is the log.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Still not seeing anything in your logs. That does not mean there is no infection. There is a new wave of a very nasty infection going around that hides itself extremely well and also blocks many tools from running. You could have a form of this infection but tend to doubt it since HijackThis ( embedded in MGtools ) is running and this new infection that I'm referring to, blocks HijackThis.

    Please see if you can run the below procedures. If any work, attach the logs.

    Running GMER to detect rootkits

    Using Dr.Web CureIt

    Using SDFix
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds