Need help - hijacked connection.

Discussion in 'Malware Help (A Specialist Will Reply)' started by ClockworkOrange, Dec 5, 2008.

  1. ClockworkOrange

    ClockworkOrange Private E-2

    My connection is hijacked and the DNS keeps being reset as with the Zlob DNSchanger trojan. I've run the malware removal tools as suggested, and attached are my logs - but the darn thing keeps coming back into registry and my network connection. I've reset my broadband modem and my router, deleted every 'resycle' folder - I'm at a loss. Please help, I'm tearing my hair out.

    TIA -

    Ted
     

    Attached Files:

  2. ClockworkOrange

    ClockworkOrange Private E-2

    Here is the remaining log. TIA -

    Ted
     

    Attached Files:

  3. ClockworkOrange

    ClockworkOrange Private E-2

    I should add that I have done every step in the Win XP procedure, and read all the Zlob/DNSchanger.trojan threads - and the darn thing keeps coming back. I've deleted the registry keys that specify the DNS, and they keep rewriting themselves. I'm beginning to consider a wipe, reformat, and restart - but the loss of data would be devastating. It's extremely frustrating.

    Thanks again for all your help!

    Ted
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try this:

    Download SDFix and save it to your Desktop.

    * Run the SDFix.exe by double clicking on it.
    * Allow it to install into the default location which is normally c:\SDFix
    * Now please reboot your computer into Safe Mode (see this if you don't know how: Starting your computer in Safe mode. )
    * When you have booted into safe mode, open the C:\SDFix folder and double click RunThis.bat to start the script.
    * Type Y to begin the cleanup process.
    * It will remove any Trojan Services or Registry entries found and then prompt you to press any key to Reboot.
    * Press any Key and it will restart the PC.
    * When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
    * Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
    * Attach the Report.txt file to your next message.
     
  5. ClockworkOrange

    ClockworkOrange Private E-2

    Thanks TimW!.

    I have to let you know that I found two .dll files in my c:\Windows\System32 folder that were created at the same date/time as the infection and had odd names something like mpqrlldxx.dll - which were flagged by Avenger (finally).

    After that, I reran the cleaning procedure and the Smitfraud fix, and reset the DNS configuration.

    Now I've run SDfix as specified, and attached is the log - it seems as though I'm finally clean of this thing, but I want to be sure. It's a persistent little b@$t@rd.

    Thanks again for your help - I certainly appreciate what you do!

    Ted
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file so I can be sure you are clean. :)
     
  7. ClockworkOrange

    ClockworkOrange Private E-2

    Here you go - (fingers crossed)!

    TYVM,

    Ted
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good...just one thing to do:

    Please disable all anti-virus and anti-spyware programs while we do the following ( be sure to re-enable when we are finished):


    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Again, Run C:\MGtools\analyse.exe by double clicking on it. Look for those lines. If they are not there:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds