View Single Post
Old 01-08-2009, 07:39 PM   #10 (permalink)
amateur
Moderator, Analyst, Security Team ; Rangemaster, TSF Academy
 
amateur's Avatar
 
Join Date: Jun 2006
Location: USA
Posts: 7,278
OS: XP SP3


Re: Possible Trojan, DNS problem, Redirecting!!! Despr8

Hi lizbette,

ISP is your Internet Service Provider. If custom settings needed, only your ISP can tell you what they are, I cannot. You can contact them via telephone.

Quote:
as for the kaspersky scan, i have tried doing the scan, but the website refuses to allow the update section, so the scan would not run.
How does it refuse, what does it say?


While you're here, can we do this part of the last fix again. I didn't get the result I was expecting. I think I missed something.
  • Open notepad (Start>All programs>accessories>notepad ) (It must be notepad, not wordpad, or it won't work)
  • Copy the entire contents of the Quote Box below to Notepad.
  • Name the file as CFScript.txt
  • Change the Save as Type to All Files
  • and Save it on the desktop
  • Click Format and ensure Wordwrap is unchecked.

Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Code:
SkipFix::

RegLock::
[HKEY_LOCAL_MACHINE\software\Microsoft\Dbgagt\1*NULL*]
Save this as CFScript.txt, in the same location as ComboFix.exe




Refering to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you. Post that log in your next reply.

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall


===========================

When you're done with that, please repeat the RegQuery part again.
  • Copy the following registry keypath by highlighting the text an pressing CTRL and C at the same time
HKEY_LOCAL_MACHINE\software\Microsoft\Dbgagt
  • Double click RegQuery.exe to run the program
  • Paste the text you have copied using CRTL and V, into the textbox
  • Click the Query button
  • A Notepad file will open. Please paste the contents in your next reply

Sorry for asking you to do it the second time. Thanks.

So, I'll be expecting the Combofix.txt and the RegQuery results.
__________________
My services are free. However, you can donate to TSF to help keep it running.




Member of ASAP since 2005
Member of UNITE since 2006
amateur is offline