Fortinet Blog | News and Threat Research

  • Products
  • Solutions
  • Service & Support
  • Partners
  • Corporate
  • Resources
  • How to Buy

DNSChanger Virus Will Bump Infected Users Offline

by RSS Stefanie Hoffman  |  July 06, 2012  |  Category: Industry Trends & News

That said, come Monday, many users with the DNSChanger virus plaguing their computers will be kicked offline until the nasty bug is removed.

The problem reared its ugly head over the last several years when Estonian malware authors created DNSChanger, which—true to its name—rerouted users’ search traffic to their own infected servers. From the users’ perspective, the redirect took them to bogus Websites, which pummeled them with spam, phishing attacks and adware.

The malicious campaign wreaked havoc on users’ computers around the world, altogether netting the miscreants profits that reached close to $14 million in illegal ads, according to the FBI, and infecting an estimated four million machines at its peak.

The FBI caught wind of their shenanigans and, with the help of a few international partners, initiated a crackdown in November of last year resulting in the arrest of six Estonians.  As part of the operation, the FBI and other international law enforcement agencies shut down the infected DNS servers, but not before creating a temporary safety net of servers in their place that prevented hundreds of thousands of users from being cut-off from Internet connectivity.

Initially, those temporary servers were scheduled to be shut down in March of this year, but the deadline got extended to allow victims more time to clean their computers. Even still, more than 300,000 computers worldwide still housed DNSChanger by mid-June, according to the FBI’s latest report.

Now, almost eight months later, those temporary servers are slated to finally be taken offline—perhaps leaving hundreds of thousands of users in the lurch if they fail to rid their machines of the virus before the July 9 deadline.

Thus far, there are still an estimated 350,000 users with infections remaining on their computers, according to the DNS Changer Working Group, which means it will be curtains for their Internet connectivity if they don’t clean up their machines.

Fortunately for them, the FBI and the DCWG offer free online tools on their sites that can detect infection in a matter of seconds, simply by entering their IP addresses or clicking a button.

If the tools fail to detect an infection, users will be able to access the Internet with impunity come Monday. However, if DNSChanger is found on the victim’s computer, not to fear–there is still time to address the threat before the FBI pulls the plug.

Specifically, DCWG recommends that users with the DNSChanger malware on their machines first backup and save all their external files so as not to lose any sensitive data during the cleaning process.

Next, users will be required to install a removal tool, several of which are listed on the DCWG site. To ensure that the threat is entirely removed, the DCWG recommends using more than one.

And as with any infection, users will want to carefully review bank statements and credit card bills, while changing all passwords and logins.

Remember, in light of the availability, accessibility and relative speed of the fixes, the DNSChanger virus does not signify the end of the world. But for those that lose Internet connection July 9th, it might feel like it.

by RSS Stefanie Hoffman  |  July 06, 2012  |  Category: Industry Trends & News
Tags: adware Anti-Spam Conficker worm DCWG DNS Changer Working Group DNSChanger DNSChanger virus FBI phishing attacks Y2K
comments powered by Disqus

Category

  • All
  • RSS Subscribe
  • Security Research
  • RSS Subscribe
  • Industry Trends & News
  • RSS Subscribe

FortiGuard Labs on the Web

  • Twitter Twitter
  • Facebook Facebook
  • LinkedIn LinkedIn
  • Youtube Youtube

Monthly Archives

  • May 2013 7
  • April 2013 17
  • March 2013 12
  • February 2013 11
  • January 2013 12
  • December 2012 8
  • November 2012 7
  • October 2012 4
  • September 2012 7
  • August 2012 7
  • July 2012 9
  • June 2012 17
  • May 2012 14
  • April 2012 16
  • March 2012 15
  • February 2012 11
  • January 2012 6
  • December 2011 4
  • November 2011 6
  • October 2011 11
  • September 2011 2
  • August 2011 2
  • July 2011 4
  • June 2011 6
  • May 2011 6
  • April 2011 5
  • March 2011 7
  • February 2011 5
  • January 2011 7
  • December 2010 8
  • November 2010 11
  • October 2010 3
  • September 2010 8
  • August 2010 4
  • July 2010 9
  • June 2010 9
  • May 2010 9
  • April 2010 6
  • March 2010 8
  • February 2010 6
  • January 2010 9
  • December 2009 8
  • November 2009 6
  • October 2009 6
  • September 2009 8
  • August 2009 5
  • July 2009 8
  • June 2009 7
  • May 2009 4
  • April 2009 7
  • March 2009 9
  • February 2009 4
  • January 2009 1
  • Older

Popular topics

network security Anonymous microsoft symbianos exploit Antivirus BYOD apple reverse engineering Firewall mobile malware adobe Malware facebook virut Mac OS X zitmo conference Threat Landscape android sms Mobile Security Windows UTM botnet Fortinet iphone mobile phones mobile phone challenge google FortiGate webinar bredolab privacy Security mobile symbos/yxes Zeus SpyEye symbian derek manky trojan hashdays stuxnet Cryptography Research Anti-Spam hacking challenge reversing