Shopping Cart
Your Cart is Empty
Quantity:
Subtotal
Taxes
Shipping
Total
There was an error with PayPalClick here to try again
CelebrateThank you for your business!You should be receiving an order confirmation from Paypal shortly.Exit Shopping Cart

Your Pc Surgeon, LLC

Transparency  and Simplicity of Technology

PC Surgical News

PC Surgical News

DOOMSDAY OF INTERNET APPROACHES-ARE YOU GOING TO BE AFFECTED?

Posted by Andy Branka A+, N+ on May 16, 2012 at 7:45 AM

 

Many times I am being ased what is the most dangerous type of the malware that can infect your computer?

Daily few hundreds are discovered "in the wild" and some of them make to the mainstream of thousands of PC's, but I think DNS Changer is one of the most malicious of them all.

I colaborated with  Alfonso Barreiro from Tech Republic to provide short overview of the problem and solutions.

Please contact me  for more information or if you think you are being affected by it.

If after visiting the site listed below your  result is red not green /as pictured/, please contact me immediately as you will lose your Internet on July 9th.

The DNS Changer malware family silently replaces the Domain Name System (DNS) settings of the computers that it infects (both Windows PCs and Macs) with the addresses of the malicious servers and routers (yes, small office/home office routers that were still using their default admin usernames and passwords). Affected users then would be directed to sites that served malware, spam or large advertisements when they tried to go to popular websites such as Amazon, iTunes and Netflix. Additionally, some variants of the malware blocked access to anti-malware and operating system update sites to prevent its removal. The operators of this botnet would receive advertising revenues when the pages were displayed or clicked on, generating them over $14 million in fees.

 

Due to the potential impact the removal of these DNS servers would have on millions of users, the FBI had the malicious servers replaced with machines operated by the Internet Systems Consortium, a public benefit non-profit organization, to give affected users time to clean their machines. Originally these temporary servers were to be shut down in March, but the FBI obtained a court order authorizing an extension because of the large number of computers still affected. The new deadline is July 9, giving more time to those still infected to fix their computers. As of March, the infected still included 94 of all Fortune 500 companies and three out of 55 major government entities, according to IID (Internet Identity), a provider of technology and services.

 

How do I check if I’m infected?

 

If you are a network admin or IT pro, and you are pretty confident your organization is in the clear, you still may want to share these instructions with your users so that they are aware that their home systems could be infected and so that they can perform the self-checks.

 

Both the FBI and the DNS Changer Working Group have provided detailed step-by-step instructions for manually checking Windows XP, Windows 7 and Mac OS X computers for infection. Essentially, if your DNS servers listed include one or more of the addresses in the following list, your computer might have been infected:

 

85.255.112.0 through 85.255.127.255

67.210.0.0 through 67.210.15.255

93.188.160.0 through 93.188.167.255

77.67.83.0 through 77.67.83.255

213.109.64.0 through 213.109.79.255

64.28.176.0 through 64.28.191.255

If your computer checks out okay, you should also check your SOHO router settings. Consult your product documentation on how to access your router settings and compare its DNS servers to those on the list above. If your router is affected, a computer on your network is likely infected with the malware.

 

There are also several self check tools that can help check your machine. One such tool is provided by the DNS Changer Working Group athttp://www.dns-ok.us/. This site will display an image with a red background if the machine or router is infected. On a clean machine, it will be a green background:

 

Depending on your organizations’ network configuration, you could set up alerts when machines from your internal network attempt to reach any of the listed addresses or you can block them outright. Be careful if you opt to block them though, as any infected machine will essentially lose its Internet connectivity since they won’t be able to resolve any Internet server name they attempt to reach. Of course, this will also be a big clue that something is wrong, if the support phone lines fire up on July 9 with users reporting mysterious Internet outages!

 

I found an infection! How do I fix it?

 

As with detection, there are also a number of tools available to fix an infection. Since the DNS Changer was delivered through different mechanisms over the years, some infections may be more difficult to remove than others. In some extreme cases, only a full reinstall of the operating system will ensure a successful repair. Some removal tools available include:

 

Kaspersky Labs TDSSKiller

McAfee Stinger

Microsoft Safety Scanner

Trend Micro Housecall

MacScan

Avira DNS Repair Tool

This is by no means a complete list; most anti-malware companies should be able to detect this particular threat. But be aware that your mileage may vary. DNS Changer was also part of some web exploitation kits and other types of malware (backdoors, keyloggers, etc.) might have hitched a ride and complicated the removal process. If you have an affected router, you should also change its default admin password to something else (and don’t use an easily guessable password - it will be only a matter of time before someone else tries a similar attack).

 

What if my machine remains infected after the deadline?

 

Machines that remain infected or are served by an affected router after the temporary servers are removed will, for all intents and purposes, lose their Internet connectivity. How to fix it will remain the same, but with the added wrinkle that you will probably need a second, clean machine with Internet access for diagnostics and to obtain removal tools.

 

Get IT Tips, news, and reviews delivered directly to your inbox by subscribing to TechRepublic’s free newsletters.

 

 

About Alfonso Barreiro

 

Alfonso is a technology specialist with experience in multiple IT roles with the latest one being in information security.

Your Pc Surgeon is local tech consulting firm specialising in new systems, networks and technology implementation for indyviduals and small businesses.


 


Categories: None

Post a Comment

Oops!

Oops, you forgot something.

Oops!

The words you entered did not match the given text. Please try again.

Already a member? Sign In

4721 Comments

Reply lsdmuzic
8:54 AM on June 2, 2023 
nike blazer gt grigio 47 brand boston red sox hat year pittsburgh steelers nfl official sideline sport knit hat hat los angeles lakers 20 timofey mozgov alternate white new swingman jersey air max snakeskin supreme nike air max tavas dark rojo
lsdmuzic http://www.lsdmuzic.com/
Reply putcosales
7:53 AM on June 2, 2023 
lord taylor evening dresses blush satin slip dress the great gatsby dress up jordan hats pink quart brian dawkins eagles jersey for cheap nfl knit hats seahawks 5k
putcosales http://www.putcosales.com/
Reply vicksfabs
1:12 AM on June 2, 2023 
red youth football pants new era atlanta braves hat for sale white revolve dress 14s jordans black and yellow boston red sox cap nike 2014 air jordan 13 low all black shoes
vicksfabs http://www.vicksfabs.com/
Reply progoodies
8:47 PM on June 1, 2023 
adidas womens running shoes white liverpool kit 1982 adidas ace 17.1 leather cheap blue and grey shoes
progoodies http://www.progoodies.com/
Reply Timothycem
4:45 PM on June 1, 2023 
????? ?????? ????????????? ? ?????????????? ?????? ?? ????????: [email protected]

??? ????? ZennoPoster?
ZennoPoster – ??????? «??? ? ?????» ??? ????????????? SEO ?????. ?????????? ?? ??????? SEO, ?? ???????? ??? ????? ??????? ? ?????.

ZennoPoster ??????????? ???????? ??? ????????????? ????? ???????? ? ????????. ?? ????????? ?????? ?? ??????? ???????????????? ????? ?????? ? ????????, ??????? ?? ???????? ????????? ???????.

??? ????????????? ZennoPoster ??? ?? ??????????? ?????-???? ??????????? ?????? ? ??????, ??? ????? ??????, ??? ??????????? ????!

?????? ????????!
??????????? SEO ????? ?? ????? ?????????? ?????? ? ????????, ?? ??????? ??? ???????. ? ZennoPoster ?? ??????? ????????? ???? ???????? ???, ??? ?????? ?? ????? ??? ???????! ????? ??????? ??????? ?????? ?????? ??????. ???? ?????? ????? ? ???????? ???? ?????????? ?????? SEO-?????, ?? ?? ????????? ????? ??????? ???????????? ?????? ????? ?????! ????? ????????? ?????????? ????? ?? ??????? ?????? ?????, ?????????? ?? ? ?????, ? ????? ? ??????? ???????? ? ?? ????? ???????!
http://elkonmobile.ru, http://uspehfishing.ru, http://arpanetvlg.ru, http://avangard-ro.ru, http://gotula.ru, http://hirurgcentr.ru, http://clubtennis.ru, http://dunaspb.ru, http://antario-print.ru, http://niramed.ru, http://respect-reklama.ru, http://danidar.ru, http://autochuvsu.ru, http://itidoc.ru, http://rodnoyspb.ru, http://seo61.ru, http://izbagifts.ru, http://kupi-kuhnu.ru, http://ecoparkdubrava.ru, http://kubanjurist.ru, http://izbavitsya-ot-cellyulita.ru, http://budy-mamoy.ru, http://shvejka.ru
? ?????, ????????? ??? ??????????? ??????????? ??? SEO ?????????? ??? ??? ?????? ? ?????? ???????, ??? ??????????? ???????? ?????? ?? ??????, ??????? ??? ?????????? ??? ?????? ???????. ???? ?? ?????? ?????? ?????? SEO ??? ?????????? ? ???????, ?? ALL Submitter-?????? ??????? ??? ???. ????? ????????? ???? ?????????, ????????? ??? ??????? ??? ????? ?????????? ??? ???, ??????????? ?????? SEO-???????????? ??????????? “??? ???????????”.

Allsubmitter ?? ?????? ?????????? ??? ?????????? ??????? ??? ??????? ? ?????????? ????????. ?? is ????? ?????????? ??? ?????? ????????? ?????? ?? ???????? ??????-?????????.

a, b, c, d, e, f, g, h, i, j, k, l, m, n, o, p, q, r, s, t, u, v, w
rsspqsosuQn5qA
Reply karunasoap
4:12 PM on June 1, 2023 
used football shirts for cheap iriza pump louboutin florida state seminoles top of the world ncaa grinder adjustable cap adidas gazelle originals rojo replica kobe bryant jersey
karunasoap http://www.karunasoap.com/
Reply vanllen
4:02 PM on June 1, 2023 
latest formal dresses for wedding therma long sleeve jersey for cheap
vanllen http://www.vanllen.com/
Reply andylampert
11:59 AM on June 1, 2023 
plus size womens western boutique clothing baby clothes websites how to knit a baby baseball hat quick ulcer america blank away short sleeves mens adults 2016 2017 club soccer jerseys rvca cap uk nike air max 1 ultra essentials dark grey
andylampert http://www.andylampert.net/
Reply malvernbadminton
10:35 AM on June 1, 2023 
elite derek cox youth jersey minnesota vikings 37 road white nfl phoenix suns draft hat for sale yeezy 350 v2 black for sale nba jerseys new york knicks chauncey billups 4 white home jerseys mens 2015 nike nfl kansas city chiefs t shirts 23
malvernbadminton http://www.malvernbadminton.net/
Reply mygohotels
8:58 AM on June 1, 2023 
nike blazer gt grigio 47 brand boston red sox hat year pittsburgh steelers nfl official sideline sport knit hat hat los angeles lakers 20 timofey mozgov alternate white new swingman jersey air max snakeskin supreme nike air max tavas dark rojo
mygohotels http://www.mygohotels.com/
Reply wanakahomes
4:32 AM on June 1, 2023 
air jordan 33 red and blackblack & yellow jordan 12 noiradidas superstar plata frontnike mercurial superfly fg all grey red washington wizards mitchell ness nba dripped snapback cap white bridesmaid gown poland soccer shirtdee ford jersey 49ersbayern m?nich clothingnba new jersey design wholesale tan phillies hat washington nationals college hats 5e
wanakahomes http://www.wanakahomes.com/
Reply wanakahomes
12:02 AM on June 1, 2023 
mets 4 lenny dykstra blue(grey no.) cool base stitched youth mlb jersey nike air max 2014 todas blanco navy san francisco giants hat liners numberssan francisco giants navy blue hat usinew york yankees cap lids hsnboston red sox running hat 60 barmah bronco hat retro 1 bred mid zegna long sleeve polo
wanakahomes http://www.wanakahomes.com/
Reply stevedekay
11:57 PM on May 31, 2023 
mets 4 lenny dykstra blue(grey no.) cool base stitched youth mlb jersey nike air max 2014 todas blanco navy san francisco giants hat liners numberssan francisco giants navy blue hat usinew york yankees cap lids hsnboston red sox running hat 60 barmah bronco hat retro 1 bred mid zegna long sleeve polo
stevedekay http://www.stevedekay.com/
Reply kbnmart
11:01 PM on May 31, 2023 
limited devin mccourty womens jersey new england patriots super bowl xlix 32 home navy blue nfl jordan retro 11 low snakeskin para venta san francisco giants mesh hat capabilities side dori frock design black and brown ua yeezys for sale
kbnmart http://www.kbnmart.com/
Reply cefashion
2:55 PM on May 31, 2023 
limited devin mccourty womens jersey new england patriots super bowl xlix 32 home navy blue nfl jordan retro 11 low snakeskin para venta san francisco giants mesh hat capabilities side dori frock design black and brown ua yeezys for sale
cefashion http://www.cefashion.net/
Reply sommarbutik
1:31 PM on May 31, 2023 
bodycon dresses long sleeve knee length nike air max 1 black hyper crimson for cheap women nike san francisco 49ers 76 anthony davis game red team color nfl jersey sale nike air max 1 all black junior for cheap
sommarbutik http://www.sommarbutik.com/
Reply bonekwani
7:26 AM on May 31, 2023 
sketchers womens sneakers new york yankees franchise fitted game cap by 47 review oversized short dress oh deer red bottom shoesred bottom flats on salewhat brand of women's shoes have red soleslouboutin 12 cm kansas city royals cooperstown hat 2016 football nike hoodieronnie lott autographed footballnew york nets throwback jerseysuns hardwood classic jersey
bonekwani http://www.bonekwani.com/
Reply alniam
6:50 AM on May 31, 2023 
pumas jersey 2019 lilac classic crocs dear summer off white collection banana republic pink dress nike air huarache cheap blue and grey shoes cloud white ultra boost
alniam http://www.alniam.com/
Reply webdooni
1:12 AM on May 31, 2023 
kennedy blue jade dresscream tank dressvelvets clothingprairie wedding dress limited ego ferguson womens jersey chicago bears 95 road white nfl lightweight long sleeve button up shirts 2021 lakers city jersey miami dolphins hat target xbox onenew era miami dolphins bobble hat vietnamesenew york yankees cap black and whiterealtree miami dolphins hat march
webdooni http://www.webdooni.com/
Reply sugotogo
11:20 PM on May 30, 2023 
nemeziz 19.4 indoor womens north face black giletcute western shirtsamerican fighter long sleevet shirt oversize outfit gamma blue 12 mens 2015 nike nfl san diego chargers t shirts 60 nike red dress
sugotogo http://www.sugotogo.com/