Jump to content

Malwarebytes

DNS CHANGER removal tools..


9 replies to this topic

#1
ShyWriter

    Forum Deity

  • Software Updaters
  • PipPipPipPipPipPip
  • 6,272 posts
  • Gender:Male
.
Posted Image

(Partial excerpt from FORBES' article on this subject)

[...]

DNS CHANGER removal tools..

The DNS Changer Working Group (DCWG), the that’s been maintaining care of the servers since their seizure, has created a website that allows you check if your computer is infected and, if it is, remove the DNSChanger malware.

Back in January of this year the DCWG estimated that some 450,000 systems were still infected with DNS Changer.

If you are infected there are a whole host of removal tools available. Here is a listing: [...]

SOURCE: http://www.forbes.co...cess-come-july/

EDIT: Malwarebytes also protects as well as scans for this problem (per Exile360 - thanks Samuel)

Steve

Edited by ShyWriter, 23 April 2012 - 03:57 PM.

.

People sleep easy in their beds at night only because

rough men stand ready to visit violence on those who

would do them harm. ~~ Orson Wells


#2
Firefox

    Forum Deity

  • Trusted Advisors
  • PipPipPipPipPipPip
  • 7,740 posts
  • Gender:Male
  • Location:USA
Nice article... thanks for sharing...

Posted Image


Dell Precision T7500, Win7 Ultimate 64bit fully updated, McAfee Corp Edition v8.8,
Watchguard Firewall, Intel Xeon E5606CPU, Dual Quad Core Processors, 16GB Ram,
E5606 @ 2.13GHz, Nvidia Quadro NVS420, Raid-1 Dual 1TB Sata 10000 rpm Hard Drives
Dual DVD Burners, IE10, Opera, MBAM


#3
ShyWriter

    Forum Deity

  • Software Updaters
  • PipPipPipPipPipPip
  • 6,272 posts
  • Gender:Male
.
Thanks Firefox.. Unfortunately I run across quite a bit more information/news/help than I can safely post (without getting yelled at :)) so it's doubly nice when I pick out a good one.

Steve

.

People sleep easy in their beds at night only because

rough men stand ready to visit violence on those who

would do them harm. ~~ Orson Wells


#4
hayc59

    Elite Member

  • Moderators
  • PipPipPipPipPip
  • 708 posts
  • Gender:Male
  • Location:I'm Your Huckleberry
Nice and thanks!!

Posted Image
9.11.01
'Never Forget'
Moderator-Beta Tester @
Outpost Users Support Forum

Microsoft® MVP Consumer Security-13


#5
Triple Helix

    Expert

  • Experts
  • PipPip
  • 73 posts
  • Gender:Male
  • Location:Ontario, Canada
  • Interests:Windows Security, NASCAR, Blue Jays Baseball
Great Thanks!

TH
Triple Helix

Posted Image
Microsoft® MVP Consumer Security 2012/14
Posted Image
Official Webroot SecureAnywhere (Prevx) Support Forum Helper

#6
ShyWriter

    Forum Deity

  • Software Updaters
  • PipPipPipPipPipPip
  • 6,272 posts
  • Gender:Male
Thanks for the thanks, guys.. It's greatly appreciated as I'm not in the running for MBAM's Taco give-away.. only 4462 posts.. Day late and 538 short.. *snif*

:P :D :lol:

Steve

.

People sleep easy in their beds at night only because

rough men stand ready to visit violence on those who

would do them harm. ~~ Orson Wells


#7
redmane1981

    New Member

  • Members
  • Pip
  • 2 posts
I have been cleaning virus infected computers for years, like many of you, and I was wondering if the dns changer that's infecting everyone might come in two flavors. One being the standard version which all of these programs may detect, and the second being a boot-time (less common but I've seen it in the past) infected mbr which may reload or reinfect with the first option. Does this sound at all plausable or is it not possible/checked for?

Thanks, love your product!

#8
exile360

    exile

  • Administrators
  • PipPipPipPipPipPip
  • 15,078 posts
  • Gender:Male

View Postredmane1981, on 04 May 2012 - 09:18 AM, said:

I have been cleaning virus infected computers for years, like many of you, and I was wondering if the dns changer that's infecting everyone might come in two flavors. One being the standard version which all of these programs may detect, and the second being a boot-time (less common but I've seen it in the past) infected mbr which may reload or reinfect with the first option. Does this sound at all plausable or is it not possible/checked for?
It's certainly possible, as what you're describing sounds like a rootkit. There are many such rootkits that will redirect a user's system to a malicious DNS server, similar to how the above described infection does.
Samuel E Lindsey
Product Manager

Posted Image

Follow us: Twitter, Become a fan: Facebook

#9
David H. Lipman

    Forum Deity

  • Experts
  • PipPipPipPipPipPip
  • 2,469 posts
  • Gender:Male
  • Location:Jersey Shore USA
  • Interests:Malware Research, dSLR Photography, Numismatics & Surf Fishing
There were a few basic variants.

One that changed the DNS table on a PC

One that changed the DNS table on a PC and poorly secured SOHO Routers

One that changed the DNS table on a PC and had protective rootkit constructs in earlier versions and later teamed with TDSS.

EDIT:

If I remember correctly the web site that pushed DNSChanger variants would look at the Browser User-Agent and subsequently foisted a DMG for Apple computers and a EXE to Windows computers.
David H. Lipman
DLipman@Verizon.Net

#10
redmane1981

    New Member

  • Members
  • Pip
  • 2 posts
thanks for the quick reply. I think that may be useful info for people. Especially if they are experiencing persistant dns changer effects and the recommended solutions aren't helping. Some of those tools listed do detect rootkits too so maybe its just me being overly cautious for people. I find "fixtdss" program to be very useful in detecting infected mbrs.





2 user(s) are reading this topic

0 members, 2 guests, 0 anonymous users

Follow Us