Jump to content

Malwarebytes

FBI Pulls The Plug On DNSChanger Network, Infected PCs Lose Internet Access [Updates]


5 replies to this topic

#1
ShyWriter

    Forum Deity

  • Software Updaters
  • PipPipPipPipPipPip
  • 6,298 posts
  • Gender:Male
.
Posted Image

FBI Pulls The Plug On DNSChanger Network, Infected PCs Lose Internet Access [Updates]

July 10, 2012
By Matt Smith

Posted Image

On July 9th, 2012 at 12:01am the FBI finally pulled the plug on a set of rogue DNS servers used by the trojan known as DNSChanger, potentially leaving hundreds of thousands without access to the Internet.

The malware has kept itself in the headlines because it changes the DNS settings of infected computers. Once changed, those computers have their traffic routed through servers set up by the hackers who developed the trojan.

FBI agents have long since caught up with the hackers responsible and captured the servers used to route traffic. But this presented the FBI with a problem – it could not shut down the servers because the infected PCs would suddenly lose Internet access.



Posted Image


An awareness campaign was launched to let users known of the potential threat. It included a site created by the DNS Changer Working Group that could inform visitors if their computer was infected. This has reduced the number of infected computers to around 250,000. Now, however, the servers are finally down for good – so those victims who remain infected are in the dark.

If you, or a friend, have suddenly experienced an unexplained Internet outage on one of your PCs there is a decent chance that DNSChanger is responsible. To remove it, visit the DCWG fix page on a computer that still has Internet access and download one of the many malware removal tools listed.

After you’ve removed the bug, check our coverage of the best free anti-virus programs and download one to keep your computer protected.

Source: CNET, DNS Changer Working Group

Steve

.

Posted Image


#2
DarkSnakeKobra

    Love thyself and thy penguin

  • Honorary Members
  • PipPipPipPipPipPip
  • 5,128 posts
  • Gender:Male
  • Location:USA
  • Interests:Security, scripting, Linux, fishing, camping
Um, anyone else first notice they got the date wrong? :blink:

Computer Specs given when asked.
Bleeping Computer Malware Study Hall Junior


#3
mountaintree16

    birds <3

  • Honorary Members
  • PipPipPipPipPipPip
  • 7,236 posts
  • Gender:Not Telling
  • Location:USA
  • Interests:Hiking, walking, reading, birds, bird watching, animals, computer security, poetry...
Yeah wrong date.

At any rate, I hope the people had enough warning to fix it first... & likely their AV's were shut off too so hopefully they get that going when they are back on-line again...
Good actions give strength to ourselves and inspire good actions in others.
-Plato-

#4
DarkSnakeKobra

    Love thyself and thy penguin

  • Honorary Members
  • PipPipPipPipPipPip
  • 5,128 posts
  • Gender:Male
  • Location:USA
  • Interests:Security, scripting, Linux, fishing, camping
Yeah I hope these people get this fixed. :)

Computer Specs given when asked.
Bleeping Computer Malware Study Hall Junior


#5
sho-dan

    कैंसर योद्धा

  • Malware Hunters
  • PipPipPipPipPipPip
  • 3,227 posts
  • Gender:Not Telling
  • Location:Jah Jersey Shore
Malwarebytes gets a kind word right after the Trojan image at bottom from the author of this story. Click on DNSChanger under march 9th

or

Story URL addy http://www.makeuseof...break-internet/

#6
Elowan

    New Member

  • Members
  • Pip
  • 2 posts
Despite repeated efforts at removal - DNSChanger is still on my system.. Furthermore even after 'removing' the malware and seeing it listed in Quarantine - a repeat scan 'detects' it again and it shows up again in the list in addition to the results of the first scan.

Any ideas?





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us