| | |
Problems with a DNS Changer Trojan
Thread Solved |
•
•
•
•
I have 'Tuneup Utilities 2008' installed and just assumed it was connected with that in some way.
Now I am somewhat confused here....Exactly WHICH computer is the infected computer we are working on at this moment? Have any of the others been infected? Don't tell me anything about the ones that are not. Is the infected one the one on the router or the one directly connected to the internet?
Last edited by jholland1964; Nov 21st, 2008 at 6:20 pm.
•
•
Join Date: Nov 2008
Posts: 13
Reputation:
Solved Threads: 0
Sorry for the confusion. Just trying to give u all the info.
The laptop is not infected. The sever pc is not infected. My personal one is infected. My personal pc and server pc are connected to the wireless router via ethernet cables.
I put "TuneUpDefragService.exe" into google and its malware sites galore that come up.
The laptop is not infected. The sever pc is not infected. My personal one is infected. My personal pc and server pc are connected to the wireless router via ethernet cables.
I put "TuneUpDefragService.exe" into google and its malware sites galore that come up.
•
•
•
•
I put "TuneUpDefragService.exe" into google and its malware sites galore that come up
Also, have to say here I am not familiar with using a router, wireless or otherwise but have found multiple listings while searching that this particular infection does some changes with DNS settings on the router.
Concerning being connected to a wireless router and this particular infection take a look at this;
http://voices.washingtonpost.com/sec..._wirele_1.html
and this one; http://forums.spybot.info/showthread.php?t=35568&page=2
and also this one;
http://extremesecurity.blogspot.com/...-hijacked.html
Last edited by jholland1964; Nov 21st, 2008 at 6:51 pm.
•
•
Join Date: Nov 2008
Posts: 13
Reputation:
Solved Threads: 0
So is it possible that me having Tuneup utilities 2008 is just a coincidence? Or would MBA-M have picked this up if it was actually malware?
Edit- Hmm maybe not. Just done some more searching and it looks legit with having tuneup utilities installed.
Edit- Hmm maybe not. Just done some more searching and it looks legit with having tuneup utilities installed.
Last edited by redrevis; Nov 21st, 2008 at 6:53 pm.
•
•
Join Date: Nov 2008
Posts: 13
Reputation:
Solved Threads: 0
I had a look at those websites and it is interesting how the trojan can actually get into the router and change DNS settings. I don't think this has happened on mine as i didn't see any changes BUT i did realise that i was using some DNS IP's that were recommended on my ISP forum. Just incase these have stopped working i changed them to openDNS.
The "TuneUpDefragService.exe" in services say's is actually not running. It is already stopped, which is strange. So i changed it to disabled for now. See if that helps. Going to do a restart and ill report back.
Edit - OMG i restarted and everything just started to update automatically, was like all my programs were coming alive. Looks like it was my router DNS settings that were the culprit after all. Im changing the username and password on my router right now. Thanks so much for your help. I'm pretty sure evrything is working properly now, but i'll report back if not :-)
The "TuneUpDefragService.exe" in services say's is actually not running. It is already stopped, which is strange. So i changed it to disabled for now. See if that helps. Going to do a restart and ill report back.
Edit - OMG i restarted and everything just started to update automatically, was like all my programs were coming alive. Looks like it was my router DNS settings that were the culprit after all. Im changing the username and password on my router right now. Thanks so much for your help. I'm pretty sure evrything is working properly now, but i'll report back if not :-)
Last edited by redrevis; Nov 21st, 2008 at 7:37 pm.
Have done some more checking and from what I have found, even though other computers connected to this router have not displayed any signs of this infection all I have found states that ALL should be put through the same clean up procedures, the MBA-M scan should be done on each also just to be sure the infection is not lurking on them to infect the others again. Afterwards you may have to reset the router again.
![]() |
Other Threads in the Viruses, Spyware and other Nasties Forum
- Previous Thread: can't delete download
- Next Thread: Google redirecting adware or something
| Thread Tools | Search this Thread |
adware anti-malware anti-virussitesaccessissue antivirus attack audio avg backtoschoolspeech bar blackhat botnet botnets censorship china commercial commercials conficker connect control crosssitescripting cyber cybercrime cyberwarfare ddos domains e-mafia education email europe exam exploit facebook fake fancheckvirus gaming gumblar halloween herss.exe hijack hosting internet iphone kaspersky legal logfiles mail malware mcafee mega-d messagelabs microsoft mobile nazi news obama onlinethreats paedophile panel parents patch phishing police policeprovirusmba-mblockedinternetaccess president privacy pro problem redirect redirecting reliability report research risk rogueantivirus samhain sans scareware school search security seopoisoning software spam spyware spywareexternalwindows7adminstratortrojans sqlinjection symantec trojan unwanted update usa virus viruses vista war warning windows worm yahoo zeroday






