View Full Version : DELETE DNSChanger!!!!
godsangel2006
2009-01-30, 14:02
Hey guys!
I'm having difficult times with my laptop since Trojan Zlob.DNSChanger got in to it. My Spybot also found lots of tracking cookies and I have no idea what can I do with it. All the time I'm deleting them, they come back during the second check.
Please, hepl!!!!!!!!!!!!!!!
Nataly
godsangel2006
2009-01-30, 16:21
Here is the log file from Malwere check up:
Malwarebytes' Anti-Malware 1.30
Database version: 1399
Windows 6.0.6001 Service Pack 1
1/30/2009 3:18:51 PM
mbam-log-2009-01-30 (15-18-51).txt
Scan type: Full Scan (C:\|D:\|E:\|F:\|)
Objects scanned: 178533
Time elapsed: 2 hour(s), 21 minute(s), 33 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3cbea290-25ff-4c45-b634-80125ca3f8a6}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.127 85.255.112.141 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{3cbea290-25ff-4c45-b634-80125ca3f8a6}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.127 85.255.112.141 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\{3cbea290-25ff-4c45-b634-80125ca3f8a6}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.127 85.255.112.141 -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Hello godsangel2006
Please see this (http://forums.spybot.info/showthread.php?t=288) next
Please follow the instructions in the above thread and then start a fresh topic with the logs required.
Regards.