Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | DNSchanger trojan?


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion

DNSchanger trojan?
Reply
 
Thread Tools
Old 23-09-2009, 22:28   #1
tvout
cf.geek
 
Join Date: Aug 2006
Location: West Midlands
Services: VM L Broadband (10MB) XL TV V+ HD Box Off peak caller phone HTC Wildfire on T-Mobile UK Freeview
Posts: 578
tvout will become famous soon enoughtvout will become famous soon enoughtvout will become famous soon enough
DNSchanger trojan?

Hi all,
Not sure how many of you may have encountered this but I've now seen it on both my gf's laptop and her parents home PC.

Basically, you go to a supposedly secure site like ebay or a banking site and it brings up a form asking for security information.

Obviously you should never give such info out over e-mail etc but in both cases you would type in the address of the site and it looks like it should do when it loads but then when you enter your user id and password you then get a dodgy web page.
In the instance I was looking at yesterday it was on the Lloyds TSB site, after logging in it then asked for security information including ATM pin code and the security code on the back of the debit card!
It showed the Lloyds web address in the address bar and everything else seemed as normal.
I ran HijackThis, Spybot and checked the Hosts file and although Spybot got rid of tons of stuff this remained.
Installed Firefox and went to the Lloyds website and it didn't bring up this dodgy screen.
Anyone know anything about this if it is a DNSchanger or something and how best to remove it? I tried various AV/Malware/Spyware Programs previously and it never seemed to go. I'm thinking I'd have to manually hack the TCPIP/DNS entries in the registry...
tvout is offline   Reply With Quote
Advertisement
Old 24-09-2009, 16:11   #2
Matty_
cf.geek
 
Matty_'s Avatar
 
Join Date: May 2008
Location: Wherever i lay my hat!
Age: 41
Posts: 735
Matty_ has reached the bronze age
Matty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze age
Re: DNSchanger trojan?

Combofix along with Malwarebytes is able to get rid of this nasty trojan/rootkit.

Go to http://www.bleepingcomputer.com/combofix/ but be careful if you go it alone, read the tutorial a couple of times. You should ideally use it under guidance as it can brick your system if you make a wrong move.
Just be carefull allthough it`s worth trying as i would not do any online activity which involves passwords until it gave the all clear(or you formatted)

Also if you do download combofix make sure it is from the above site of from forospyware.com
There are a few sites with combofix in the name that are not legit
__________________
Have a nice day!!!
Matty_ is offline   Reply With Quote
Old 02-10-2009, 20:43   #3
tvout
cf.geek
 
Join Date: Aug 2006
Location: West Midlands
Services: VM L Broadband (10MB) XL TV V+ HD Box Off peak caller phone HTC Wildfire on T-Mobile UK Freeview
Posts: 578
tvout will become famous soon enoughtvout will become famous soon enoughtvout will become famous soon enough
Re: DNSchanger trojan?

Cheers, I hadn't heard of combofix before. Much appreciated
tvout is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Google Search




All times are GMT +1. The time now is 08:35.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
Copyright © 2003 - 2012, Cable Forum.
(server1.cableforum.co.uk)

SEO by vBSEO 3.3.2