View Single Post
Old 01-06-2009, 09:39 PM   #6 (permalink)
amateur
Moderator, Analyst, Security Team ; Rangemaster, TSF Academy
 
amateur's Avatar
 
Join Date: Jun 2006
Location: USA
Posts: 7,436
OS: XP SP3


Re: Possible Trojan, DNS problem, Redirecting!!! Despr8

Hi,

Quote:
combofix ran in chinese, and i had no idea how to change that. i had enough chinese in my vocab to understand what it was doing though.
Probably the Regional Language settings were set to Chinese via Control Panel. If you wish to reverse it, you can do so. Since this is your father's computer, you may not want to change it though. As far as I am concerned, it's not a problem. If you still want to change it, go to Start>Control Panel>Regional and Language Options>Languages tab and click on the "Details" button. It will open a new window where you can make the changes. It will probably require a reboot.

========================

Please have your g drive inserted during the next scan with Combofix.
  • Open notepad (Start>All programs>accessories>notepad ) (It must be notepad, not wordpad, or it won't work)
  • Copy the entire contents of the Quote Box below to Notepad.
  • Name the file as CFScript.txt
  • Change the Save as Type to All Files
  • and Save it on the desktop
  • Click Format and ensure Wordwrap is unchecked.

Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Code:
File::
g:\resycled\boot.com
c:\windows\Tasks\PerfectOptimzier_OneClick.job

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3d70f482-42ce-11dc-b952-000bdbc46caf}]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Common Files\\Synacast\\SynaLive\\PE.exe"=-

RegLock::
[HKEY_LOCAL_MACHINE\software\Microsoft\Dbgagt]
Save this as CFScript.txt, in the same location as ComboFix.exe




Refering to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you. Post that log in your next reply.

===================================

Please download RegQuery by Noviciate to your desktop
  • Copy the following registry keypath by highlighting the text an pressing CTRL and C at the same time
HKEY_LOCAL_MACHINE\software\Microsoft\Dbgagt
  • Double click RegQuery.exe to run the program
  • Paste the text you have copied using CRTL and V, into the textbox
  • Click the Query button
  • A Notepad file will open. Please paste the contents in your next reply
  • You may now close the RegQuery program

===================================

Please post back the Combofix.txt and the RegQuery text in your next reply. Let me know if you're still being redirected.
__________________
My services are free. However, you can donate to TSF to help keep it running.




Member of ASAP since 2005
Member of UNITE since 2006

Last edited by amateur; 01-07-2009 at 07:36 AM. Reason: removed tags
amateur is offline