Jump to content
Sign in to follow this  
NUR ASYIKIN

Dns Server Problem

Recommended Posts

QUOTE(ekin_mache @ Dec 15 2008, 10:32 PM) <{POST_SNAPBACK}>
ini hasil scan from hijackthis
yg ekin garis tu..yg discan superantispyware sbg trojan dns changer
ip yg diset tu bermula ngan 85. tu


x kan streamyx set dns yg teruk kot..
biasa streamyx bagi dns 202.188.0.132 tu



Ok lah...dah terang terang IP 85.255.x.x tu memang bukan dari Mesia. Delete jer lah entry tu.

Spoiler :
Information related to '85.255.112.0 - 85.255.127.255'

inetnum: 85.255.112.0 - 85.255.127.255
netname: UkrTeleGroup
descr: UkrTeleGroup Ltd.
admin-c: UA481-RIPE
tech-c: UA481-RIPE
country: UA
org: ORG-UL25-RIPE
status: ASSIGNED PI "status:" definitions
mnt-by: RIPE-NCC-HM-PI-MNT
mnt-lower: RIPE-NCC-HM-PI-MNT
mnt-by: UKRTELE-MNT
mnt-routes: UKRTELE-MNT
mnt-domains: UKRTELE-MNT
source: RIPE # Filtered

organisation: ORG-UL25-RIPE
org-name: UkrTeleGroup Ltd.
org-type: LIR
address: UkrTeleGroup Ltd.
Mechnikova 58/5
65029 Odessa
Ukraine
phone: +380487311011
fax-no: +380487502499
mnt-ref: UKRTELE-MNT
mnt-ref: RIPE-NCC-HM-MNT
mnt-by: RIPE-NCC-HM-MNT
source: RIPE # Filtered
Edited by kerim

Share this post


Link to post
Share on other sites
tolong la plez..da masuk situ semalam..tapi byk sgt tread yg nak dibaca..
n malas nak register..klo pndai..tlg erk

boleh ke delete..x memudaratkan ker..

Share this post


Link to post
Share on other sites
QUOTE(ekin_mache @ Dec 15 2008, 10:49 PM) <{POST_SNAPBACK}>
tolong la plez..da masuk situ semalam..tapi byk sgt tread yg nak dibaca..
n malas nak register..klo pndai..tlg erk

boleh ke delete..x memudaratkan ker..


delete je, ada problem kita handle lain lak

Share this post


Link to post
Share on other sites
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.speedbit.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\user.USER-58B65B6D62\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKLM\..\Policies\Explorer\Run: [Explorer] .vbs
O4 - Startup: [waran tangkap] P2P Acceleration Patch.lnk = C:\Program Files\[waran tangkap] P2P Acceleration Patch\[waran tangkap] P2P Acceleration Patch.exe
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{A43730E8-8208-49D3-9E82-D07B6A84B126}: Domain = 202.188.0.132
O17 - HKLM\System\CCS\Services\Tcpip\..\{A43730E8-8208-49D3-9E82-D07B6A84B126}: NameServer = 85.255.115.51;85.255.112.187
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.51;85.255.112.187
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.115.51;85.255.112.187
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.51;85.255.112.187
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Stormser - Unknown owner - C:\PROGRA~1\RINGZS~1\STORMC~1\Stormser.exe (file missing)
O23 - Service: ThreatFire - Unknown owner - C:\Program Files\ThreatFire\TFService.exe (file missing)
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe

--
End of file - 5359 bytes

Share this post


Link to post
Share on other sites
Adoi aii...dah delete ke blom?

Entry nih kasi buang...

O17 - HKLM\System\CCS\Services\Tcpip\..\{A43730E8-8208-49D3-9E82-D07B6A84B126}: NameServer = 85.255.115.51;85.255.112.187
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.51;85.255.112.187
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.115.51;85.255.112.187
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.51;85.255.112.187 Edited by kerim

Share this post


Link to post
Share on other sites
ok tq..ekin cuba dulu erk Edited by ekin_mache

Share this post


Link to post
Share on other sites
awk...cuba awk delete dulu ye....ikut apa yg kripkorn 2 ckp....lepas 2.....awk restart pc 2....sblm restart 2...awk disconnectedkan dulu....internet 2....lepas 2..baru awk restart..masa restart 2...jgn connectedkan...internet 2....then...bila dah restart....awk guna balik hijackthis 2.....masa awk buat hijackthis 2...jgn connected kat internet lg...bila awk dah abis buat hijackthis 2 lg skali...baru awk connected internet & postkan kat sini balik...nak tengok...kalo offline ada masalah x...

hoho....
Fix kan nie...kwn i suruh....nasib baik dia balas cepat...awk fixkan nie skali...lepas 2...buat lg skali...hijackthis log yg baru punya....

O4 - HKLM\..\Policies\Explorer\Run: [Explorer] .vbs
O4 - Startup: [waran tangkap] P2P Acceleration Patch.lnk = C:\Program Files\[waran tangkap] P2P Acceleration Patch\[waran tangkap] P2P Acceleration Patch.exe

Share this post


Link to post
Share on other sites
da delete n da restart..scan balik..x berubah la..
and ip tu pon still dok situ gak..waaaaaaaaaaaaaaaa

Share this post


Link to post
Share on other sites
dude....u terangkan 1 per 1 kat ekin_mache nie....nanti dia lg xfaham pula....cian dia...awk...dah delete ke....
yg bawah nie....i tengok pun...ada virus 2....

O4 - HKLM\..\Policies\Explorer\Run: [Explorer] .vbs
O4 - Startup: [waran tangkap] P2P Acceleration Patch.lnk = C:\Program Files\[waran tangkap] P2P Acceleration Patch\[waran tangkap] P2P Acceleration Patch.exe Edited by ICEBOX

Share this post


Link to post
Share on other sites
yang ni da x der..


O4 - HKLM\..\Policies\Explorer\Run: [Explorer] .vbs
O4 - Startup: [waran tangkap] P2P Acceleration Patch.lnk = C:\Program Files\[waran tangkap] P2P Acceleration Patch\[waran tangkap] P2P Acceleration Patch.exe


tapi tcp/ip tu x ilang lagi

degil tol..guna clorox pon x lang ..hha

Share this post


Link to post
Share on other sites
mcm nie awk....kalo awk nak fix 2...awk cuma tick yg mana ada masalah 2 je....apa yg kripkorn 2 ckp....yg 2...awk tick juga....yg sy ckpkan 2 juga..awk tick juga...lepas 2...awk tekan button fix 2...ok.....jgn gelabah....nanti..kwn2 kat sini akan cuba tlg awk...ok..

Share this post


Link to post
Share on other sites
owh..baguslah...lor..gitu pula....yg 2 masih ada ye....awk...nie knp file missing nie...awk ada uninstall software nie ye....awk guna anti virus apa skrang nie....kalo awk guna kaspersky internet security....mesti dia detect masalah2 2...

O23 - Service: Stormser - Unknown owner - C:\PROGRA~1\RINGZS~1\STORMC~1\Stormser.exe (file missing)
O23 - Service: ThreatFire - Unknown owner - C:\Program Files\ThreatFire\TFService.exe (file missing)

welcome....kripkorn....u ada idea lg xnak tangani masalah nie.... Edited by ICEBOX

Share this post


Link to post
Share on other sites
x tau ler..kasperky ari tu da pakai..tapi dia x leh nak update..so ekin tukar pakai avast..da lama pakai avast..tapi virus masuk gak..ari tu try trend micro..skang pakai malwarebytes ngan superantispyware jer..yg tu je pon leh detect virus ni

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
Sign in to follow this  

×
×
  • Create New...