<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Fake Flash Player and Trojan DNSChanger.gen</title>
	<atom:link href="http://blog.novirusthanks.org/2008/12/fake-flash-player-and-trojan-dnschangergen/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.novirusthanks.org/2008/12/fake-flash-player-and-trojan-dnschangergen/</link>
	<description>Security News and Malware Analysis</description>
	<lastBuildDate>Tue, 18 Oct 2011 16:33:27 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: eddie</title>
		<link>http://blog.novirusthanks.org/2008/12/fake-flash-player-and-trojan-dnschangergen/#comment-725</link>
		<dc:creator>eddie</dc:creator>
		<pubDate>Thu, 29 Jan 2009 06:25:27 +0000</pubDate>
		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=526#comment-725</guid>
		<description>Hello again Robert. Once again thank you so much for all of your help, it means a lot.  The night I last posted I came across the site malwareremoval.com and have just begun trouble shooting to get rid of this thing.  Its a site that helps people with their virus woes and serves as a training program for &#039;virus vigilantes&#039; as I like to call them. It seams like a great site, there&#039;s nothing that I should be weary of, is there?  

As far as my issue. . .Avast is my current virus protection program as well as windows defender. I&#039;ve received Avast warnings regarding the virus and am unable to move it to the chest or do anything to it for that matter. I believe the virus prohibits my comp from downloading and installing updates from defender (and probably other programs I am unaware of).  It seems as though there are a number of different virus. Though I&#039;ve scene a couple different names  the only one I have been able to document is:

 C:\Windows\System32\msqpdxmewtfbso.dll</description>
		<content:encoded><![CDATA[<p>Hello again Robert. Once again thank you so much for all of your help, it means a lot.  The night I last posted I came across the site malwareremoval.com and have just begun trouble shooting to get rid of this thing.  Its a site that helps people with their virus woes and serves as a training program for &#8216;virus vigilantes&#8217; as I like to call them. It seams like a great site, there&#8217;s nothing that I should be weary of, is there?  </p>
<p>As far as my issue. . .Avast is my current virus protection program as well as windows defender. I&#8217;ve received Avast warnings regarding the virus and am unable to move it to the chest or do anything to it for that matter. I believe the virus prohibits my comp from downloading and installing updates from defender (and probably other programs I am unaware of).  It seems as though there are a number of different virus. Though I&#8217;ve scene a couple different names  the only one I have been able to document is:</p>
<p> C:\Windows\System32\msqpdxmewtfbso.dll</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert</title>
		<link>http://blog.novirusthanks.org/2008/12/fake-flash-player-and-trojan-dnschangergen/#comment-649</link>
		<dc:creator>Robert</dc:creator>
		<pubDate>Sat, 24 Jan 2009 01:19:39 +0000</pubDate>
		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=526#comment-649</guid>
		<description>Hi eddie,

I&#039;ve created a video that show how to set permissions for regedit and regedt32 in this article:

http://novirusthanks.org/blog/?p=799

View it as it should help you to delete the &quot;protected&quot; keys setting the right permissions.
About your HiJackThis Logs it seem that your computer is safe : )
Anyway can you describe wich problem is giving you the computer ?</description>
		<content:encoded><![CDATA[<p>Hi eddie,</p>
<p>I&#8217;ve created a video that show how to set permissions for regedit and regedt32 in this article:</p>
<p><a href="http://novirusthanks.org/blog/?p=799" rel="nofollow">http://novirusthanks.org/blog/?p=799</a></p>
<p>View it as it should help you to delete the &#8220;protected&#8221; keys setting the right permissions.<br />
About your HiJackThis Logs it seem that your computer is safe : )<br />
Anyway can you describe wich problem is giving you the computer ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: eddie</title>
		<link>http://blog.novirusthanks.org/2008/12/fake-flash-player-and-trojan-dnschangergen/#comment-617</link>
		<dc:creator>eddie</dc:creator>
		<pubDate>Thu, 22 Jan 2009 06:16:41 +0000</pubDate>
		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=526#comment-617</guid>
		<description>It took a couple attempts to get all of these posts up today, and again, I truly apologize if they all come through at some point. . .I don&#039;t think that will be the case though.  I expressed my gratuity in one of the posts that didn&#039;t make through but, want to make sure you know I&#039;m grateful.  Following is the final part(s) of my HijackThis Log

O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe</description>
		<content:encoded><![CDATA[<p>It took a couple attempts to get all of these posts up today, and again, I truly apologize if they all come through at some point. . .I don&#8217;t think that will be the case though.  I expressed my gratuity in one of the posts that didn&#8217;t make through but, want to make sure you know I&#8217;m grateful.  Following is the final part(s) of my HijackThis Log</p>
<p>O23 &#8211; Service: Agere Modem Call Progress Audio (AgereModemAudio) &#8211; Agere Systems &#8211; C:\Windows\system32\agrsmsvc.exe<br />
O23 &#8211; Service: Apple Mobile Device &#8211; Apple Inc. &#8211; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 &#8211; Service: avast! iAVS4 Control Service (aswUpdSv) &#8211; ALWIL Software &#8211; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
O23 &#8211; Service: Automatic LiveUpdate Scheduler &#8211; Symantec Corporation &#8211; C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br />
O23 &#8211; Service: avast! Antivirus &#8211; ALWIL Software &#8211; C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
O23 &#8211; Service: avast! Mail Scanner &#8211; ALWIL Software &#8211; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
O23 &#8211; Service: avast! Web Scanner &#8211; ALWIL Software &#8211; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
O23 &#8211; Service: Bonjour Service &#8211; Apple Inc. &#8211; C:\Program Files\Bonjour\mDNSResponder.exe</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: eddie</title>
		<link>http://blog.novirusthanks.org/2008/12/fake-flash-player-and-trojan-dnschangergen/#comment-609</link>
		<dc:creator>eddie</dc:creator>
		<pubDate>Thu, 22 Jan 2009 06:00:33 +0000</pubDate>
		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=526#comment-609</guid>
		<description>Here it is. . .It may spread among a couple seperate posts.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:42:55 PM, on 1/21/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\AirPort\APAgent.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\igfxsrvc.exe
C:\Users\test\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe</description>
		<content:encoded><![CDATA[<p>Here it is. . .It may spread among a couple seperate posts.</p>
<p>Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 9:42:55 PM, on 1/21/2009<br />
Platform: Windows Vista SP1 (WinNT 6.00.1905)<br />
MSIE: Internet Explorer v7.00 (7.00.6001.18000)<br />
Boot mode: Normal</p>
<p>Running processes:<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe<br />
C:\Windows\RtHDVCpl.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Windows\system32\wbem\unsecapp.exe<br />
C:\Program Files\Launch Manager\QtZgAcer.EXE<br />
C:\Program Files\Alwil Software\Avast4\ashDisp.exe<br />
C:\Program Files\AirPort\APAgent.exe<br />
C:\Windows\System32\igfxtray.exe<br />
C:\Windows\System32\hkcmd.exe<br />
C:\Windows\System32\igfxpers.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe<br />
C:\Windows\system32\igfxsrvc.exe<br />
C:\Windows\system32\igfxext.exe<br />
C:\Windows\system32\igfxsrvc.exe<br />
C:\Users\test\AppData\Local\Temp\RtkBtMnt.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: eddie</title>
		<link>http://blog.novirusthanks.org/2008/12/fake-flash-player-and-trojan-dnschangergen/#comment-607</link>
		<dc:creator>eddie</dc:creator>
		<pubDate>Thu, 22 Jan 2009 05:57:44 +0000</pubDate>
		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=526#comment-607</guid>
		<description>For some reason my posts are not showing up. . .I really hope you won&#039;t be barraged with them all at once.  

First off, I tried to follow the instructions in the above posts, but couldn&#039;t quite get the ball rolling past step one.  I did manage to open up the registry editor and read as much as I could to help me, but could not figure out how to give permissions to regedit32 nor could I figure out how to localize the keys. 

I did manage to get a hijackThis log though!</description>
		<content:encoded><![CDATA[<p>For some reason my posts are not showing up. . .I really hope you won&#8217;t be barraged with them all at once.  </p>
<p>First off, I tried to follow the instructions in the above posts, but couldn&#8217;t quite get the ball rolling past step one.  I did manage to open up the registry editor and read as much as I could to help me, but could not figure out how to give permissions to regedit32 nor could I figure out how to localize the keys. </p>
<p>I did manage to get a hijackThis log though!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert</title>
		<link>http://blog.novirusthanks.org/2008/12/fake-flash-player-and-trojan-dnschangergen/#comment-593</link>
		<dc:creator>Robert</dc:creator>
		<pubDate>Wed, 21 Jan 2009 10:38:30 +0000</pubDate>
		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=526#comment-593</guid>
		<description>Hi eddie,
your post is correct : )
About your Avast log, if the malware is not removed you can follow the info in the previous comments to remove it and remember to delete this file when you are in Safe Mode:

C:\Windows\System32\msqpdxmewtfbso.dll

Also if you want try to post an HiJackThis log here so I can analyze it and check if your computer is infected by other malware too.</description>
		<content:encoded><![CDATA[<p>Hi eddie,<br />
your post is correct : )<br />
About your Avast log, if the malware is not removed you can follow the info in the previous comments to remove it and remember to delete this file when you are in Safe Mode:</p>
<p>C:\Windows\System32\msqpdxmewtfbso.dll</p>
<p>Also if you want try to post an HiJackThis log here so I can analyze it and check if your computer is infected by other malware too.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: eddie</title>
		<link>http://blog.novirusthanks.org/2008/12/fake-flash-player-and-trojan-dnschangergen/#comment-590</link>
		<dc:creator>eddie</dc:creator>
		<pubDate>Wed, 21 Jan 2009 02:55:22 +0000</pubDate>
		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=526#comment-590</guid>
		<description>also, I have to admit that my blogging and message board posting experience is limited and I do not know the proper etiquette that comes with them.  So i apologize if it is inappropriate to paste a previous post (like I did above), and I will do my best to post properly.  I appreciate any help you could extend to me.  Thank you so much.</description>
		<content:encoded><![CDATA[<p>also, I have to admit that my blogging and message board posting experience is limited and I do not know the proper etiquette that comes with them.  So i apologize if it is inappropriate to paste a previous post (like I did above), and I will do my best to post properly.  I appreciate any help you could extend to me.  Thank you so much.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: eddie</title>
		<link>http://blog.novirusthanks.org/2008/12/fake-flash-player-and-trojan-dnschangergen/#comment-589</link>
		<dc:creator>eddie</dc:creator>
		<pubDate>Wed, 21 Jan 2009 02:46:50 +0000</pubDate>
		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=526#comment-589</guid>
		<description>Hello. So I&#039;ve been dealing with a virus problem akin to those mentioned here.  Its a pesky trojan horse detected by Avast. It causes my computer to shut down frequently and cannot be moved to the chest because it is supposedly being used by other processes, nor can I find it on my computer.  I know this may not be the only virus, but its a start.  My question for you is - could I simply follow the advice given in the post that i&#039;ve pasted here? Or is that a misdiagnosis on my part?

The info I get from my avast scan is:
FILE NAME: C:\Windows\System32\msqpdxmewtfbso.dll
MALEWARE NAME: Win32:Fasec [tri]
 


RobertDecember 29th, 2008 at 9:53 pm

@jim try to do this:

1) go in safe mode (press f8 when windows start)
2) give permissions with regedt32
3) localize the keys:
HKLM\SOFTWARE\Classes\msqpdxvx
HKLM\SYSTEM\ControlSet001\Services\msqpdxserv.sys
HKLM\SYSTEM\ControlSet003\Services\msqpdxserv.sys
HKLM\SYSTEM\CurrentControlSet\Services\msqpdxserv.sys

NOTE:
check also the possible presence of other registry keys as hans found other keys:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msqpdxserv.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msqpdxserv.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MSQPDXSERV.SYS
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSQPDXSERV.SYS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_MSQPDXSERV.SYS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\msqpdxserv.sys

Then delete the keys and look if are present these files in the harddisk:

    C:\DOCUME~1\user\LOCALS~1\Temp\jah30006.exe
    C:\autorun.inf
    C:\Program Files\homeview
    C:\Program Files\homeview\Uninstall.exe
    C:\Documents and Settings\user\Start Menu\Programs\homeview\Uninstall.lnk
    C:\resycled\boot.com
    C:\WINDOWS\system32\drivers\msqpdxpqxtoiqh.sys
    C:\WINDOWS\system32\msqpdxosvnnrse.dll 

If these files are present just delete them, now restart your PC and check (with the anti rootkit or manually with regedit) if the registry keys are present.

@Andy from the HiJackThis Log seem that your computer is clean, anyway try to scan your PC with Rootkit Revealer (you can find it here http://novirusthanks.org/blog/?p=16) and paste here the logs : )

-Robert</description>
		<content:encoded><![CDATA[<p>Hello. So I&#8217;ve been dealing with a virus problem akin to those mentioned here.  Its a pesky trojan horse detected by Avast. It causes my computer to shut down frequently and cannot be moved to the chest because it is supposedly being used by other processes, nor can I find it on my computer.  I know this may not be the only virus, but its a start.  My question for you is &#8211; could I simply follow the advice given in the post that i&#8217;ve pasted here? Or is that a misdiagnosis on my part?</p>
<p>The info I get from my avast scan is:<br />
FILE NAME: C:\Windows\System32\msqpdxmewtfbso.dll<br />
MALEWARE NAME: Win32:Fasec [tri]</p>
<p>RobertDecember 29th, 2008 at 9:53 pm</p>
<p>@jim try to do this:</p>
<p>1) go in safe mode (press f8 when windows start)<br />
2) give permissions with regedt32<br />
3) localize the keys:<br />
HKLM\SOFTWARE\Classes\msqpdxvx<br />
HKLM\SYSTEM\ControlSet001\Services\msqpdxserv.sys<br />
HKLM\SYSTEM\ControlSet003\Services\msqpdxserv.sys<br />
HKLM\SYSTEM\CurrentControlSet\Services\msqpdxserv.sys</p>
<p>NOTE:<br />
check also the possible presence of other registry keys as hans found other keys:<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msqpdxserv.sys<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msqpdxserv.sys<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MSQPDXSERV.SYS<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSQPDXSERV.SYS<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_MSQPDXSERV.SYS<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\msqpdxserv.sys</p>
<p>Then delete the keys and look if are present these files in the harddisk:</p>
<p>    C:\DOCUME~1\user\LOCALS~1\Temp\jah30006.exe<br />
    C:\autorun.inf<br />
    C:\Program Files\homeview<br />
    C:\Program Files\homeview\Uninstall.exe<br />
    C:\Documents and Settings\user\Start Menu\Programs\homeview\Uninstall.lnk<br />
    C:\resycled\boot.com<br />
    C:\WINDOWS\system32\drivers\msqpdxpqxtoiqh.sys<br />
    C:\WINDOWS\system32\msqpdxosvnnrse.dll </p>
<p>If these files are present just delete them, now restart your PC and check (with the anti rootkit or manually with regedit) if the registry keys are present.</p>
<p>@Andy from the HiJackThis Log seem that your computer is clean, anyway try to scan your PC with Rootkit Revealer (you can find it here <a href="http://novirusthanks.org/blog/?p=16" rel="nofollow">http://novirusthanks.org/blog/?p=16</a>) and paste here the logs : )</p>
<p>-Robert</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kris Williams</title>
		<link>http://blog.novirusthanks.org/2008/12/fake-flash-player-and-trojan-dnschangergen/#comment-462</link>
		<dc:creator>Kris Williams</dc:creator>
		<pubDate>Thu, 08 Jan 2009 08:00:13 +0000</pubDate>
		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=526#comment-462</guid>
		<description>Thank you so much Simon, been searching for this answer for hours</description>
		<content:encoded><![CDATA[<p>Thank you so much Simon, been searching for this answer for hours</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: michi</title>
		<link>http://blog.novirusthanks.org/2008/12/fake-flash-player-and-trojan-dnschangergen/#comment-441</link>
		<dc:creator>michi</dc:creator>
		<pubDate>Tue, 06 Jan 2009 09:39:58 +0000</pubDate>
		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=526#comment-441</guid>
		<description>FOR ANYONE WITH THIS ISSUE:

quickest way to get rid of this is COMBOFIX, works even when your system is not running anymore virus scanners.

this virus took me three hours!

good luck everyone</description>
		<content:encoded><![CDATA[<p>FOR ANYONE WITH THIS ISSUE:</p>
<p>quickest way to get rid of this is COMBOFIX, works even when your system is not running anymore virus scanners.</p>
<p>this virus took me three hours!</p>
<p>good luck everyone</p>
]]></content:encoded>
	</item>
</channel>
</rss>

