Help with zlob.DNSChanger

Everything seems to be working fine. He was able to connect to Spybot and download the udpates (something he couldn't do before). In the hijackthis.log, do you have any idea what those 017 entries are? Do you think they're ok to have?

O17 - HKLM\System\CCS\Services\Tcpip\..\{948CEBD2-BAF9-49F2-ACFE-77E6624C2B7F}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220 208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220 208.67.222.222
 
They are OpenDNS DNS servers set by Spybot.

Spybot sets them when it finds wareout infection to ensure that internet connection stays.

You can attempt to fix them; if you loose internet connection, just restore them from HijackThis backups.
 
Shaba,
You know, when we did the system restore I must have lost the antivirus software we installed. Thank you for bringing this back to my attention, I will have him take care of this immediately.

I can not thank you enough for all your help! I know you guys are volunteers, and usually I'm the one in your shoes trying to help people, but this one was out of my comfort zone. I know how frustrating it can be working with people sometimes, so please know, we truly appreciate your patience, help and expertise!

Thanks again!
 
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.

Note: If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than five days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.
 
Back
Top