|
Next: Deskjet 4180 & Win Vista 6.0 SP2
|
| Author |
Message |
External

Since: Oct 30, 2009 Posts: 1
|
(Msg. 1) Posted: Fri Oct 30, 2009 9:22 pm
Post subject: What did this do to my PC? Archived from groups: microsoft>public>windowsxp>security_admin (more info?)
|
|
|
|
| I installed malwarebytes and found this little gift on my system:
(Trojan.DNSChanger)
It seem to have messed around with the security center, but im not sure what
it did to it. Does anyone know exactly what it did to my security center?
|
|
|
| Back to top |
|
 |  |
External

Since: Jan 16, 2006 Posts: 106
|
(Msg. 2) Posted: Fri Oct 30, 2009 9:58 pm
Post subject: Re: What did this do to my PC? [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
=?Utf-8?B?R2FtZXIxMDE=?= <Gamer101.RemoveThis@discussions.microsoft.com> wrote
in news:3EEA84DD-A907-412D-ADF8-705318FFDA73@microsoft.com:
> I installed malwarebytes and found this little gift on my system:
>
> (Trojan.DNSChanger)
>
> It seem to have messed around with the security center, but im not
> sure what it did to it. Does anyone know exactly what it did to my
> security center?
>
Here's the write-up on it from Symantec:
<http://www.symantec.com/business/security_response/writeup.jsp?docid=2007-011811-1222-99>
HTH,
John |
|
| Back to top |
|
 |  |
External

Since: Feb 12, 2009 Posts: 4
|
(Msg. 3) Posted: Mon Nov 02, 2009 2:13 pm
Post subject: Re: What did this do to my PC? [Login to view extended thread Info.] Archived from groups: microsoft>public>security>virus, others (more info?)
|
|
|
"Gamer101" <Gamer101 RemoveThis @discussions.microsoft.com> wrote in message
news:3EEA84DD-A907-412D-ADF8-705318FFDA73@microsoft.com...
>I installed malwarebytes and found this little gift on my system:
>
> (Trojan.DNSChanger)
>
> It seem to have messed around with the security center, but im not
> sure what
> it did to it. Does anyone know exactly what it did to my security
> center?
Gamer101,
Sounds like you installed some rogue knockoff instead of the real thing.
Where did you download this version of "malwarebytes" from? I'm willing
to bet it wasn't from http://malwarebytes.org/
xposted to microsoft.public.security.virus for added input.
Regards,
Len Agoado
agoado RemoveThis @msn.com |
|
| Back to top |
|
 |  |
External

Since: Aug 09, 2007 Posts: 156
|
(Msg. 4) Posted: Mon Nov 02, 2009 3:20 pm
Post subject: Re: What did this do to my PC? [Login to view extended thread Info.] Archived from groups: microsoft>public>windowsxp>security_admin (more info?)
|
|
|
If that's all it found consider yourself lucky.
--
--
"Gamer101" <Gamer101 DeleteThis @discussions.microsoft.com> wrote in message
news:3EEA84DD-A907-412D-ADF8-705318FFDA73@microsoft.com...
>I installed malwarebytes and found this little gift on my system:
>
> (Trojan.DNSChanger)
>
> It seem to have messed around with the security center, but im not sure
> what
> it did to it. Does anyone know exactly what it did to my security center? |
|
| Back to top |
|
 |  |
External

Since: May 22, 2009 Posts: 10
|
(Msg. 5) Posted: Mon Nov 02, 2009 5:20 pm
Post subject: Re: What did this do to my PC? [Login to view extended thread Info.] Archived from groups: microsoft>public>security>virus, others (more info?)
|
|
|
Sounds to me like Gamer101 is saying MBAM *found* the trojan, and he or
she wants to know the consequences of having had that malware.
Asking a good question would would help here (or maybe using Google).
IIRC this one can affect your router if not locked down.
"Leonard Agoado" <len RemoveThis @mwswire.com> wrote in message
news:%23WE1WnAXKHA.4816@TK2MSFTNGP06.phx.gbl...
> "Gamer101" <Gamer101 RemoveThis @discussions.microsoft.com> wrote in message
> news:3EEA84DD-A907-412D-ADF8-705318FFDA73@microsoft.com...
>
>
>>I installed malwarebytes and found this little gift on my system:
>>
>> (Trojan.DNSChanger)
>>
>> It seem to have messed around with the security center, but im not
>> sure what
>> it did to it. Does anyone know exactly what it did to my security
>> center?
>
>
> Gamer101,
>
> Sounds like you installed some rogue knockoff instead of the real
> thing.
>
> Where did you download this version of "malwarebytes" from? I'm
> willing to bet it wasn't from http://malwarebytes.org/
>
> xposted to microsoft.public.security.virus for added input.
>
>
> Regards,
>
> Len Agoado
> agoado RemoveThis @msn.com
> |
|
| Back to top |
|
 |  |
External

Since: Sep 18, 2004 Posts: 113
|
(Msg. 6) Posted: Mon Nov 02, 2009 7:20 pm
Post subject: Re: What did this do to my PC? [Login to view extended thread Info.] Archived from groups: microsoft>public>windowsxp>security_admin (more info?)
|
|
|
From: "Gamer101" <Gamer101.DeleteThis@discussions.microsoft.com>
| I installed malwarebytes and found this little gift on my system:
| (Trojan.DNSChanger)
| It seem to have messed around with the security center, but im not sure what
| it did to it. Does anyone know exactly what it did to my security center?
NOTE: The DNSChanger trojan may also have an peer RootKit.,
The pupose of the trojan is to modify the Domain Name System (DNS) resolution that your PC
performs. Instead of using choice or ISP DNS servers, it places malicious servers in the
DNS server list instead. Thus redirecting you from legitimate web sites to malicious web
sites.
Additionally this infector tragets both MAC and PC as well as can modify the DNS table of
SOHO Routers if they are not secured properly.
To make sure you do NOT have the RootKit, scan your PC with Gmer.
http://www.gmer.net/#files
--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp |
|
| Back to top |
|
 |  |
External

Since: Nov 02, 2009 Posts: 1
|
(Msg. 7) Posted: Mon Nov 02, 2009 10:46 pm
Post subject: Re: What did this do to my PC? [Login to view extended thread Info.] Archived from groups: microsoft>public>security>virus, others (more info?)
|
|
|
Removal instructions for Trojan.DNSChanger:
http://www.malwarebytes.org/forums/index.php?showtopic=5398
Analysis of Trojan.DNSChanger is at:
http://www.symantec.com/business/security_response/writeup.jsp?docid=2...-011811
The analysis does not mention any changes to the Security Center.
"Leonard Agoado" <len.RemoveThis@mwswire.com> wrote in message
news:%23WE1WnAXKHA.4816@TK2MSFTNGP06.phx.gbl...
> "Gamer101" <Gamer101.RemoveThis@discussions.microsoft.com> wrote in message
> news:3EEA84DD-A907-412D-ADF8-705318FFDA73@microsoft.com...
>
>
>>I installed malwarebytes and found this little gift on my system:
>>
>> (Trojan.DNSChanger)
>>
>> It seem to have messed around with the security center, but im not sure
>> what
>> it did to it. Does anyone know exactly what it did to my security center?
>
>
> Gamer101,
>
> Sounds like you installed some rogue knockoff instead of the real thing.
>
> Where did you download this version of "malwarebytes" from? I'm willing
> to bet it wasn't from http://malwarebytes.org/
>
> xposted to microsoft.public.security.virus for added input.
>
>
> Regards,
>
> Len Agoado
> agoado.RemoveThis@msn.com |
|
| Back to top |
|
 |  |
External

Since: Nov 03, 2009 Posts: 1
|
(Msg. 8) Posted: Tue Nov 03, 2009 4:56 am
Post subject: Re: What did this do to my PC? [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
"Leonard Agoado" <len.DeleteThis@mwswire.com> wrote in message news:#WE1WnAXKHA.4816@TK2MSFTNGP06.phx.gbl...
> "Gamer101" <Gamer101.DeleteThis@discussions.microsoft.com> wrote in message
> news:3EEA84DD-A907-412D-ADF8-705318FFDA73@microsoft.com...
>
>
>>I installed malwarebytes and found this little gift on my system:
>>
>> (Trojan.DNSChanger)
>>
>> It seem to have messed around with the security center, but im not
>> sure what
>> it did to it. Does anyone know exactly what it did to my security
>> center?
>
>
> Gamer101,
>
> Sounds like you installed some rogue knockoff instead of the real thing.
>
> Where did you download this version of "malwarebytes" from? I'm willing
> to bet it wasn't from http://malwarebytes.org/
>
> xposted to microsoft.public.security.virus for added input.
>
>
> Regards,
>
> Len Agoado
> agoado.DeleteThis@msn.com
>
>
>
Post the report from the MBAM so we can see exactly what it found and where
sometimes this is a false positive IF you are on a network or change DNS settings yourself |
|
| Back to top |
|
 |  |
External

Since: Feb 12, 2009 Posts: 4
|
(Msg. 9) Posted: Tue Nov 03, 2009 11:49 am
Post subject: Re: What did this do to my PC? [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
"FromTheRafters" <erratic @nomail.afraid.org> wrote in message
news:evHvZ2AXKHA.844@TK2MSFTNGP05.phx.gbl...
> Sounds to me like Gamer101 is saying MBAM *found* the trojan, and he
> or she wants to know the consequences of having had that malware.
FTR,
Upon rereading the OP, I think you're right.
Also, David Lipman later responded to the original post in
m.p.w.security_admin by suggesting a scan with Gmer.
Regards,
Len Agoado
agoado.TakeThisOut@msn.com |
|
| Back to top |
|
 |  |
External

Since: May 22, 2009 Posts: 10
|
(Msg. 10) Posted: Tue Nov 03, 2009 8:53 pm
Post subject: Re: What did this do to my PC? [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
"Leonard Agoado" <len.RemoveThis@mwswire.com> wrote in message
news:uplQ86LXKHA.3428@TK2MSFTNGP06.phx.gbl...
>
> "FromTheRafters" <erratic @nomail.afraid.org> wrote in message
> news:evHvZ2AXKHA.844@TK2MSFTNGP05.phx.gbl...
>
>> Sounds to me like Gamer101 is saying MBAM *found* the trojan, and he
>> or she wants to know the consequences of having had that malware.
>
>
> FTR,
>
> Upon rereading the OP, I think you're right.
>
> Also, David Lipman later responded to the original post in
> m.p.w.security_admin by suggesting a scan with Gmer.
That is quickly becoming a standard practice - "rootkits" must be
addressed before anything else in your toolbox can be trusted to work as
designed. The term "rootkit" is in the popular lexicon just as "virus"
was - its meaning is being shifted and soon we'll be hearing about the
"trojan rootkit virus" that caused my brother's laptop to spew black
smoke.  ) |
|
| Back to top |
|
 |  |
External

Since: Sep 18, 2004 Posts: 113
|
(Msg. 11) Posted: Tue Nov 03, 2009 9:05 pm
Post subject: Re: What did this do to my PC? [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
From: "FromTheRafters" <erratic @nomail.afraid.org>
| "Leonard Agoado" <len.TakeThisOut@mwswire.com> wrote in message
| news:uplQ86LXKHA.3428@TK2MSFTNGP06.phx.gbl...
>> "FromTheRafters" <erratic @nomail.afraid.org> wrote in message
>> news:evHvZ2AXKHA.844@TK2MSFTNGP05.phx.gbl...
>>> Sounds to me like Gamer101 is saying MBAM *found* the trojan, and he
>>> or she wants to know the consequences of having had that malware.
>> FTR,
>> Upon rereading the OP, I think you're right.
>> Also, David Lipman later responded to the original post in
>> m.p.w.security_admin by suggesting a scan with Gmer.
| That is quickly becoming a standard practice - "rootkits" must be
| addressed before anything else in your toolbox can be trusted to work as
| designed. The term "rootkit" is in the popular lexicon just as "virus"
| was - its meaning is being shifted and soon we'll be hearing about the
| "trojan rootkit virus" that caused my brother's laptop to spew black
| smoke. )
LOL "trojan rootkit virus" LOL
--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp |
|
| Back to top |
|
 |  |