Jump to content


Photo

Database 625


  • Please log in to reply
6 replies to this topic

#1 MaB69

MaB69

    Regular Member

  • Experts
  • PipPip
  • 86 posts
  • Gender:Male
  • Location:France

Posted 14 April 2008 - 11:54 AM

Hi,

Fast scan gives 3 detections :

Malwarebytes' Anti-Malware 1.11
Version de la base de données: 625

Type de recherche: Examen rapide
Eléments examinés: 30272
Temps écoulé: 3 minute(s), 1 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 3
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{F7D99B22-E56C-4EA1-91EF-463493EB4822}\NameServer (Trojan.DNSChanger) -> Data: 208.67.222.222,208.67.202.202 -> No action taken. [ScanForBadDNSServers() Function]
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{F7D99B22-E56C-4EA1-91EF-463493EB4822}\NameServer (Trojan.DNSChanger) -> Data: 208.67.222.222,208.67.202.202 -> No action taken. [ScanForBadDNSServers() Function]
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{F7D99B22-E56C-4EA1-91EF-463493EB4822}\NameServer (Trojan.DNSChanger) -> Data: 208.67.222.222,208.67.202.202 -> No action taken. [ScanForBadDNSServers() Function]

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
(Aucun élément nuisible détecté)


I wish that a DNSChanger really hijack a DNS conf to use OpenDNS :P

Regards,

MaB
Posted Image

#2 nosirrah

nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,402 posts
  • Location:Northampton, MA USA

Posted 14 April 2008 - 01:11 PM

fixing
Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#3 nosirrah

nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,402 posts
  • Location:Northampton, MA USA

Posted 14 April 2008 - 03:12 PM

Should be fixed .

I added them to begin with because malware did hijack to this .

A few HJT helpers were removing them so I added them .
Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#4 MaB69

MaB69

    Regular Member

  • Experts
  • PipPip
  • 86 posts
  • Gender:Male
  • Location:France

Posted 14 April 2008 - 05:01 PM

Should be fixed .

I added them to begin with because malware did hijack to this .

A few HJT helpers were removing them so I added them .


Hi Bruce,

Fixed using db 629

Sorry, i did not understand what you mean ? IP in the same range are used to hijack DNS servers ?

Thanks

Regards,

MaB
Posted Image

#5 gerardwil

gerardwil

    True Member

  • Experts
  • PipPipPipPip
  • 413 posts
  • Gender:Male
  • Location:The Netherlands

Posted 14 April 2008 - 05:35 PM

Hi MaB,

Shouldn't the second server be: 208.67.220.220?

Gerard
Gerard

#6 nosirrah

nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,402 posts
  • Location:Northampton, MA USA

Posted 14 April 2008 - 06:13 PM

Hi Bruce,

Fixed using db 629

Sorry, i did not understand what you mean ? IP in the same range are used to hijack DNS servers ?

Thanks

Regards,

MaB



In HJT speak , these were the 017s HJT had listed after the malware installed .

I did find a few HJT experts removing them so I added them to the DNS hijack defs .

This seems to be a case where something nonmalicious was misused .
Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#7 MaB69

MaB69

    Regular Member

  • Experts
  • PipPip
  • 86 posts
  • Gender:Male
  • Location:France

Posted 14 April 2008 - 11:53 PM

Hi,

Thank you Gerard and Bruce,

MBAM ;) shows me that i badly set my secondary DNS server :P

Never paid attention to this

Regards,

MaB
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users