Tech Support Guy banner
  • IMPORTANT: Only authorized members may reply to threads in this forum due to the complexity of the malware removal process. Authorized members include Malware Specialists and Trainees, Administrators, Moderators, and Trusted Advisors. Regular members are not permitted to reply, and any such posts will be deleted without notice or further explanation. Notice
Status
Not open for further replies.
1 - 7 of 7 Posts

· Registered
Joined
·
3 Posts
Discussion Starter · #1 ·
Did a HijackThis today and I got a Reg Key alert, which I checked:


HKLM\System\CCS\Services\Tcpip\parameters\interfaces\{3C111BD0-F4EA-4753-86DA-C8EF71AE7025}: NameServer = 200.72.1.11 200.72.1.5


removed it whereupon IE did not work any more!!

so had to restore it again.

Upon reboot the HijackThis still recognises it as a threat.
Any ideas where it comes from and did it overwrite a value ?

Lorn
 

· Retired Moderator Retired Malware Specialist
Joined
·
56,593 Posts
First Name -
Derek
post the full log and we can see what is going on

HJT doesn't see anything as a threat it just lists all the entries in certain places and lets YOU (or someone else) make a decision based on klnowledge and experience and judgement
 

· Retired Moderator Retired Malware Specialist
Joined
·
56,593 Posts
First Name -
Derek
Those IP numbers are a genuine ISP in CHILE so if you are in chile it's good, if not then we need to have a careful look at what has happened
 

· Registered
Joined
·
3 Posts
Discussion Starter · #6 ·
OK to the above.
But I do not understand why removing this key disables my IE browser, since it is not that of my ISP, it must be an intruder?.
Will try redirecting it to MSN address.
thanx.
 

· Retired Moderator Retired Malware Specialist
Joined
·
56,593 Posts
First Name -
Derek
without something in there you are unable to look up DNS

please post a full HJt log and we can advise how to cure the problem
 
1 - 7 of 7 Posts
Status
Not open for further replies.
Top