hidden hit counter
Welcome to Soft32 Forums!
FAQFAQ    SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

What did this do to my PC?

 
   Soft32 Home -> Windows -> Security Admin RSS
Next:  Deskjet 4180 & Win Vista 6.0 SP2  
Author Message
Gamer101

External


Since: Oct 30, 2009
Posts: 1



(Msg. 1) Posted: Fri Oct 30, 2009 9:22 pm
Post subject: What did this do to my PC?
Archived from groups: microsoft>public>windowsxp>security_admin (more info?)

I installed malwarebytes and found this little gift on my system:

(Trojan.DNSChanger)

It seem to have messed around with the security center, but im not sure what
it did to it. Does anyone know exactly what it did to my security center?
Back to top
Login to vote
John Wunderlich

External


Since: Jan 16, 2006
Posts: 106



(Msg. 2) Posted: Fri Oct 30, 2009 9:58 pm
Post subject: Re: What did this do to my PC? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

=?Utf-8?B?R2FtZXIxMDE=?= <Gamer101.RemoveThis@discussions.microsoft.com> wrote
in news:3EEA84DD-A907-412D-ADF8-705318FFDA73@microsoft.com:

> I installed malwarebytes and found this little gift on my system:
>
> (Trojan.DNSChanger)
>
> It seem to have messed around with the security center, but im not
> sure what it did to it. Does anyone know exactly what it did to my
> security center?
>

Here's the write-up on it from Symantec:
<http://www.symantec.com/business/security_response/writeup.jsp?docid=2007-011811-1222-99>

HTH,
John
Back to top
Login to vote
Leonard Agoado

External


Since: Feb 12, 2009
Posts: 4



(Msg. 3) Posted: Mon Nov 02, 2009 2:13 pm
Post subject: Re: What did this do to my PC? [Login to view extended thread Info.]
Archived from groups: microsoft>public>security>virus, others (more info?)

"Gamer101" <Gamer101 RemoveThis @discussions.microsoft.com> wrote in message
news:3EEA84DD-A907-412D-ADF8-705318FFDA73@microsoft.com...


>I installed malwarebytes and found this little gift on my system:
>
> (Trojan.DNSChanger)
>
> It seem to have messed around with the security center, but im not
> sure what
> it did to it. Does anyone know exactly what it did to my security
> center?


Gamer101,

Sounds like you installed some rogue knockoff instead of the real thing.

Where did you download this version of "malwarebytes" from? I'm willing
to bet it wasn't from http://malwarebytes.org/

xposted to microsoft.public.security.virus for added input.


Regards,

Len Agoado
agoado RemoveThis @msn.com
Back to top
Login to vote
David B.

External


Since: Aug 09, 2007
Posts: 156



(Msg. 4) Posted: Mon Nov 02, 2009 3:20 pm
Post subject: Re: What did this do to my PC? [Login to view extended thread Info.]
Archived from groups: microsoft>public>windowsxp>security_admin (more info?)

If that's all it found consider yourself lucky.

--


--
"Gamer101" <Gamer101 DeleteThis @discussions.microsoft.com> wrote in message
news:3EEA84DD-A907-412D-ADF8-705318FFDA73@microsoft.com...
>I installed malwarebytes and found this little gift on my system:
>
> (Trojan.DNSChanger)
>
> It seem to have messed around with the security center, but im not sure
> what
> it did to it. Does anyone know exactly what it did to my security center?
Back to top
Login to vote
FromTheRafters

External


Since: May 22, 2009
Posts: 10



(Msg. 5) Posted: Mon Nov 02, 2009 5:20 pm
Post subject: Re: What did this do to my PC? [Login to view extended thread Info.]
Archived from groups: microsoft>public>security>virus, others (more info?)

Sounds to me like Gamer101 is saying MBAM *found* the trojan, and he or
she wants to know the consequences of having had that malware.

Asking a good question would would help here (or maybe using Google).

IIRC this one can affect your router if not locked down.

"Leonard Agoado" <len RemoveThis @mwswire.com> wrote in message
news:%23WE1WnAXKHA.4816@TK2MSFTNGP06.phx.gbl...
> "Gamer101" <Gamer101 RemoveThis @discussions.microsoft.com> wrote in message
> news:3EEA84DD-A907-412D-ADF8-705318FFDA73@microsoft.com...
>
>
>>I installed malwarebytes and found this little gift on my system:
>>
>> (Trojan.DNSChanger)
>>
>> It seem to have messed around with the security center, but im not
>> sure what
>> it did to it. Does anyone know exactly what it did to my security
>> center?
>
>
> Gamer101,
>
> Sounds like you installed some rogue knockoff instead of the real
> thing.
>
> Where did you download this version of "malwarebytes" from? I'm
> willing to bet it wasn't from http://malwarebytes.org/
>
> xposted to microsoft.public.security.virus for added input.
>
>
> Regards,
>
> Len Agoado
> agoado RemoveThis @msn.com
>
Back to top
Login to vote
David H. Lipman

External


Since: Sep 18, 2004
Posts: 113



(Msg. 6) Posted: Mon Nov 02, 2009 7:20 pm
Post subject: Re: What did this do to my PC? [Login to view extended thread Info.]
Archived from groups: microsoft>public>windowsxp>security_admin (more info?)

From: "Gamer101" <Gamer101.DeleteThis@discussions.microsoft.com>

| I installed malwarebytes and found this little gift on my system:

| (Trojan.DNSChanger)

| It seem to have messed around with the security center, but im not sure what
| it did to it. Does anyone know exactly what it did to my security center?

NOTE: The DNSChanger trojan may also have an peer RootKit.,

The pupose of the trojan is to modify the Domain Name System (DNS) resolution that your PC
performs. Instead of using choice or ISP DNS servers, it places malicious servers in the
DNS server list instead. Thus redirecting you from legitimate web sites to malicious web
sites.

Additionally this infector tragets both MAC and PC as well as can modify the DNS table of
SOHO Routers if they are not secured properly.

To make sure you do NOT have the RootKit, scan your PC with Gmer.
http://www.gmer.net/#files

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
Back to top
Login to vote
Andy Medina

External


Since: Nov 02, 2009
Posts: 1



(Msg. 7) Posted: Mon Nov 02, 2009 10:46 pm
Post subject: Re: What did this do to my PC? [Login to view extended thread Info.]
Archived from groups: microsoft>public>security>virus, others (more info?)

Removal instructions for Trojan.DNSChanger:

http://www.malwarebytes.org/forums/index.php?showtopic=5398

Analysis of Trojan.DNSChanger is at:

http://www.symantec.com/business/security_response/writeup.jsp?docid=2...-011811

The analysis does not mention any changes to the Security Center.

"Leonard Agoado" <len.RemoveThis@mwswire.com> wrote in message
news:%23WE1WnAXKHA.4816@TK2MSFTNGP06.phx.gbl...
> "Gamer101" <Gamer101.RemoveThis@discussions.microsoft.com> wrote in message
> news:3EEA84DD-A907-412D-ADF8-705318FFDA73@microsoft.com...
>
>
>>I installed malwarebytes and found this little gift on my system:
>>
>> (Trojan.DNSChanger)
>>
>> It seem to have messed around with the security center, but im not sure
>> what
>> it did to it. Does anyone know exactly what it did to my security center?
>
>
> Gamer101,
>
> Sounds like you installed some rogue knockoff instead of the real thing.
>
> Where did you download this version of "malwarebytes" from? I'm willing
> to bet it wasn't from http://malwarebytes.org/
>
> xposted to microsoft.public.security.virus for added input.
>
>
> Regards,
>
> Len Agoado
> agoado.RemoveThis@msn.com
Back to top
Login to vote
Derek Knight

External


Since: Nov 03, 2009
Posts: 1



(Msg. 8) Posted: Tue Nov 03, 2009 4:56 am
Post subject: Re: What did this do to my PC? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Leonard Agoado" <len.DeleteThis@mwswire.com> wrote in message news:#WE1WnAXKHA.4816@TK2MSFTNGP06.phx.gbl...
> "Gamer101" <Gamer101.DeleteThis@discussions.microsoft.com> wrote in message
> news:3EEA84DD-A907-412D-ADF8-705318FFDA73@microsoft.com...
>
>
>>I installed malwarebytes and found this little gift on my system:
>>
>> (Trojan.DNSChanger)
>>
>> It seem to have messed around with the security center, but im not
>> sure what
>> it did to it. Does anyone know exactly what it did to my security
>> center?
>
>
> Gamer101,
>
> Sounds like you installed some rogue knockoff instead of the real thing.
>
> Where did you download this version of "malwarebytes" from? I'm willing
> to bet it wasn't from http://malwarebytes.org/
>
> xposted to microsoft.public.security.virus for added input.
>
>
> Regards,
>
> Len Agoado
> agoado.DeleteThis@msn.com
>
>
>

Post the report from the MBAM so we can see exactly what it found and where

sometimes this is a false positive IF you are on a network or change DNS settings yourself
Back to top
Login to vote
Leonard Agoado

External


Since: Feb 12, 2009
Posts: 4



(Msg. 9) Posted: Tue Nov 03, 2009 11:49 am
Post subject: Re: What did this do to my PC? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"FromTheRafters" <erratic @nomail.afraid.org> wrote in message
news:evHvZ2AXKHA.844@TK2MSFTNGP05.phx.gbl...

> Sounds to me like Gamer101 is saying MBAM *found* the trojan, and he
> or she wants to know the consequences of having had that malware.


FTR,

Upon rereading the OP, I think you're right.

Also, David Lipman later responded to the original post in
m.p.w.security_admin by suggesting a scan with Gmer.

Regards,

Len Agoado
agoado.TakeThisOut@msn.com
Back to top
Login to vote
FromTheRafters

External


Since: May 22, 2009
Posts: 10



(Msg. 10) Posted: Tue Nov 03, 2009 8:53 pm
Post subject: Re: What did this do to my PC? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Leonard Agoado" <len.RemoveThis@mwswire.com> wrote in message
news:uplQ86LXKHA.3428@TK2MSFTNGP06.phx.gbl...
>
> "FromTheRafters" <erratic @nomail.afraid.org> wrote in message
> news:evHvZ2AXKHA.844@TK2MSFTNGP05.phx.gbl...
>
>> Sounds to me like Gamer101 is saying MBAM *found* the trojan, and he
>> or she wants to know the consequences of having had that malware.
>
>
> FTR,
>
> Upon rereading the OP, I think you're right.
>
> Also, David Lipman later responded to the original post in
> m.p.w.security_admin by suggesting a scan with Gmer.

That is quickly becoming a standard practice - "rootkits" must be
addressed before anything else in your toolbox can be trusted to work as
designed. The term "rootkit" is in the popular lexicon just as "virus"
was - its meaning is being shifted and soon we'll be hearing about the
"trojan rootkit virus" that caused my brother's laptop to spew black
smoke. Surprised)
Back to top
Login to vote
David H. Lipman

External


Since: Sep 18, 2004
Posts: 113



(Msg. 11) Posted: Tue Nov 03, 2009 9:05 pm
Post subject: Re: What did this do to my PC? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

From: "FromTheRafters" <erratic @nomail.afraid.org>


| "Leonard Agoado" <len.TakeThisOut@mwswire.com> wrote in message
| news:uplQ86LXKHA.3428@TK2MSFTNGP06.phx.gbl...

>> "FromTheRafters" <erratic @nomail.afraid.org> wrote in message
>> news:evHvZ2AXKHA.844@TK2MSFTNGP05.phx.gbl...

>>> Sounds to me like Gamer101 is saying MBAM *found* the trojan, and he
>>> or she wants to know the consequences of having had that malware.


>> FTR,

>> Upon rereading the OP, I think you're right.

>> Also, David Lipman later responded to the original post in
>> m.p.w.security_admin by suggesting a scan with Gmer.

| That is quickly becoming a standard practice - "rootkits" must be
| addressed before anything else in your toolbox can be trusted to work as
| designed. The term "rootkit" is in the popular lexicon just as "virus"
| was - its meaning is being shifted and soon we'll be hearing about the
| "trojan rootkit virus" that caused my brother's laptop to spew black
| smoke. Surprised)

LOL "trojan rootkit virus" LOL



--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Group Policy in XP - I log on as local admin, open gpedit.msc and goto Local Computer Policy, User Configuration, Administrative Templates,...

KB928366 cannot be installed. - Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB928366) The message I get when my compute...

Group properies help.. - How can you define a group access rights. I created a new group for my developer and I want to custom define thier..

PrintFilterPipelineSvc.exe wants access to the Internet - .. - Windows defender has just blocked 'PrintFilterPipelineSvc.exe' from accessing the internet. What is it and why does it...

Is there a registry - Is there a registry setting in XP to extend the timeout default value for a client to reach the domain controller when...

Security Issue Has Locked Out One of My Drives - Hello there, I was trying to protect the information in my drives from whomever is using our guest account at the..
       Soft32 Home -> Windows -> Security Admin All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You can edit your posts in this forum
You can delete your posts in this forum
You can vote in polls in this forum

Categories:
  Windows
 Linux
 Mac
 PDA


[ Contact us | Terms of Service/Privacy Policy ]