Trojan DNSChanger

Discussion in 'Malware Help (A Specialist Will Reply)' started by vedder45, Sep 25, 2010.

  1. vedder45

    vedder45 Private E-2

    Hello -

    In the past 2 or 3 days, I have noticed that my web activity is being redirected to advertising/shopping sites. It doesn't happen with every click - I haven't quite figured out any patterns but today it became VERY frequent. I also noticed over the past 2 days that my AVG scheduled scans (they start at 3:00am) have hung up without finishing.

    I tried running Malwarebytes and SuperAntiSpyware but they wouldn't open - something obviously was blocking them. I did manage to get them running in Safe Mode and Malwarebytes found the Trojan DNSChanger.

    I have since done the steps required previous to starting a thread and files are attached for review.

    If there is anything else I need to provide, please let me know.

    Thank you in advance for your expert assistance!
     

    Attached Files:

  2. vedder45

    vedder45 Private E-2

    MGLogs file attached.

    Thanks again.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Next time you have a problem, please attach the first scan logs as requested in the READ & RUN ME. You should have attached the below which would have showed us what was found and removed.
    Code:
    "C:\Documents and Settings\Brad\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\"
    Sep 25 2010 5822 "SUPERAntiSpyware Scan Log - 09-25-2010 - 11-27-28.log"
     
    "C:\Documents and Settings\Brad\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\"
    Sep 25 2010 1284 "mbam-log-2010-09-25 (11-24-34).txt"

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - (no file)
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
    O18 - Protocol: schmap-help - (no CLSID) - (no file)

    After clicking Fix, exit HJT.



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    The infection you have is known to infect router hardware. If you have a router hooked up then you need to follow the instructions for your hardware and reset it to factory default settings. Normally there is a recessed push button type switch that needs to be held down for some number of seconds to do this. After resetting to factory defaults on your router, you will need to reconfigure the router for your network if you have made any changes to the default network setup.



    Now download Registry Search (see the link titled RegSearch Download Link )
    • Extract the files from Regsearch.zip into a folder.
    • Doubleclick regsearch.exe to start the program.
    • See the top 3 boxes under the Enter search strings (case independen) and click Ok... option, enter the below string (use copy and paste)
      • DhcpNameServer
    • Then click "OK".
    • Notepad will be opened with text in it (the file named RegSearch.txt will be saved in the program's folder as well).
    • Attach this RegSearch.txt file.
    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • RegSearch.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. vedder45

    vedder45 Private E-2

    Completed the Analyse and ComboFix steps as directed. I got a blue screen on the first ComboFix attempt so, upon reboot, I started from the beginning. It worked fine the second time.

    Reset my router to default and reconfigured network.

    Ran RegistrySearch, CCleaner and GetLogs.

    I've also attached the first MB log from the scan I did early yesterday so you can see the Trojan DNSChanger results.

    Things seem to be working smoothly now - no website redirects.

    Thanks again!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I suspect that the problem will come back. MBAM only found part of the DNS infection. It is not seeing the 213.109.x.x addresses which still show in your logs. The fix I gave you with ComboFix tried to remove these but some of them did not get removed. This means your problem will likely return. Did you start getting redirect again???
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If still having problems as I suspect you will then do the below.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. vedder45

    vedder45 Private E-2

    So far no more redirects. You listed another fix based up on a recurrence of issues but I wonder if you would recommend going ahead with it even though the redirects have not started back? Can/Should I run your latest suggestion anyway for good measure?

    Thanks again!
     
  8. vedder45

    vedder45 Private E-2

    An update:

    Firefox seems to be running abnormally high and, not sure if it's just a coincidence, but I failed to mention previously that, around the time of my fixes, I lost the recognition of my external hard drive and some of my keyboard controls no longer work (e.g. sound controls). Could any of these be related to my original issue or fixes?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I suggest running that and attaching the new requested logs.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not based on anything seen in your logs nor on anything that was fixed.
     
  11. vedder45

    vedder45 Private E-2

    Steps completed.

    Still no redirects since the first round of fixes.

    Thanks!
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Excellent!


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  13. vedder45

    vedder45 Private E-2

    Done.

    Thank you very much!!
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds