943,675 Members | Top Members by Rank

Ad:
You are currently viewing page 2 of this multi-page discussion thread; Jump to the first page
Nov 21st, 2008
0

Re: Problems with a DNS Changer Trojan

Click to Expand / Collapse  Quote originally posted by redrevis ...
I have 'Tuneup Utilities 2008' installed and just assumed it was connected with that in some way.
That's fine just wanted to be certain.
Now I am somewhat confused here....Exactly WHICH computer is the infected computer we are working on at this moment? Have any of the others been infected? Don't tell me anything about the ones that are not. Is the infected one the one on the router or the one directly connected to the internet?
Last edited by jholland1964; Nov 21st, 2008 at 6:20 pm.
Moderator
Featured Poster
Reputation Points: 725
Solved Threads: 339
Posting Expert
jholland1964 is offline Offline
5,497 posts
since Jul 2008
Nov 21st, 2008
0

Re: Problems with a DNS Changer Trojan

Sorry for the confusion. Just trying to give u all the info.

The laptop is not infected. The sever pc is not infected. My personal one is infected. My personal pc and server pc are connected to the wireless router via ethernet cables.

I put "TuneUpDefragService.exe" into google and its malware sites galore that come up.
Reputation Points: 10
Solved Threads: 0
Newbie Poster
redrevis is offline Offline
13 posts
since Nov 2008
Nov 21st, 2008
0

Re: Problems with a DNS Changer Trojan

Quote ...
I put "TuneUpDefragService.exe" into google and its malware sites galore that come up
Yeah, I know that is why I asked.

Also, have to say here I am not familiar with using a router, wireless or otherwise but have found multiple listings while searching that this particular infection does some changes with DNS settings on the router.
Concerning being connected to a wireless router and this particular infection take a look at this;
http://voices.washingtonpost.com/sec..._wirele_1.html

and this one; http://forums.spybot.info/showthread.php?t=35568&page=2
and also this one;
http://extremesecurity.blogspot.com/...-hijacked.html
Last edited by jholland1964; Nov 21st, 2008 at 6:51 pm.
Moderator
Featured Poster
Reputation Points: 725
Solved Threads: 339
Posting Expert
jholland1964 is offline Offline
5,497 posts
since Jul 2008
Nov 21st, 2008
0

Re: Problems with a DNS Changer Trojan

So is it possible that me having Tuneup utilities 2008 is just a coincidence? Or would MBA-M have picked this up if it was actually malware?

Edit- Hmm maybe not. Just done some more searching and it looks legit with having tuneup utilities installed.
Last edited by redrevis; Nov 21st, 2008 at 6:53 pm.
Reputation Points: 10
Solved Threads: 0
Newbie Poster
redrevis is offline Offline
13 posts
since Nov 2008
Nov 21st, 2008
0

Re: Problems with a DNS Changer Trojan

For now I will say it appears to be a legitimate program. You should STOP it from running automatically via services the same way I told you to stop the others. There is no reason for this program to run all the time anyway.
Moderator
Featured Poster
Reputation Points: 725
Solved Threads: 339
Posting Expert
jholland1964 is offline Offline
5,497 posts
since Jul 2008
Nov 21st, 2008
0

Re: Problems with a DNS Changer Trojan

I had a look at those websites and it is interesting how the trojan can actually get into the router and change DNS settings. I don't think this has happened on mine as i didn't see any changes BUT i did realise that i was using some DNS IP's that were recommended on my ISP forum. Just incase these have stopped working i changed them to openDNS.

The "TuneUpDefragService.exe" in services say's is actually not running. It is already stopped, which is strange. So i changed it to disabled for now. See if that helps. Going to do a restart and ill report back.

Edit - OMG i restarted and everything just started to update automatically, was like all my programs were coming alive. Looks like it was my router DNS settings that were the culprit after all. Im changing the username and password on my router right now. Thanks so much for your help. I'm pretty sure evrything is working properly now, but i'll report back if not :-)
Last edited by redrevis; Nov 21st, 2008 at 7:37 pm.
Reputation Points: 10
Solved Threads: 0
Newbie Poster
redrevis is offline Offline
13 posts
since Nov 2008
Nov 21st, 2008
0

Re: Problems with a DNS Changer Trojan

Well I'll be. Like I said, know next to nothing about router usage but when you said you used the router on a couple of the computers I thought maybe that could be the problem, especially since everything else looked clean.
Judy
Moderator
Featured Poster
Reputation Points: 725
Solved Threads: 339
Posting Expert
jholland1964 is offline Offline
5,497 posts
since Jul 2008
Nov 23rd, 2008
0

Re: Problems with a DNS Changer Trojan

Have done some more checking and from what I have found, even though other computers connected to this router have not displayed any signs of this infection all I have found states that ALL should be put through the same clean up procedures, the MBA-M scan should be done on each also just to be sure the infection is not lurking on them to infect the others again. Afterwards you may have to reset the router again.
Moderator
Featured Poster
Reputation Points: 725
Solved Threads: 339
Posting Expert
jholland1964 is offline Offline
5,497 posts
since Jul 2008
Nov 23rd, 2008
0

Re: Problems with a DNS Changer Trojan

OK will do. Thanks for all your help Judy
Reputation Points: 10
Solved Threads: 0
Newbie Poster
redrevis is offline Offline
13 posts
since Nov 2008
Nov 23rd, 2008
0

Re: Problems with a DNS Changer Trojan

Let us know what or if you find anything ok? This will certainly help others as I have now seen this problem twice in this forum in the last week and also on another forum where I do some posting.
Judy
Moderator
Featured Poster
Reputation Points: 725
Solved Threads: 339
Posting Expert
jholland1964 is offline Offline
5,497 posts
since Jul 2008

This thread is solved

Either the thread starter or a moderator has marked this thread as solved. You can most likely trust the responses and answers given. There is most likely no reason for any further responses to be posted here. If you have a related question, please start a new thread in this forum instead.

This thread is more than three months old

No one has posted to this discussion for at least three months. Please let old threads die and do not reply to them unless you feel you have something new and valuable to contribute that absolutely must be added to make the discussion complete. Otherwise, please start a new thread in this forum instead.
Message:
Previous Thread in Viruses, Spyware and other Nasties Forum Timeline: can't delete download
Next Thread in Viruses, Spyware and other Nasties Forum Timeline: Google redirecting adware or something





About Us | Contact Us | Advertise | Acceptable Use Policy
Forum Index | Build Custom RSS Feed


Follow us on Twitter


© 2011 DaniWeb® LLC