• There seems to be an uptick in Political comments in recent months. Those of us who are long time members of the site know that Political and Religious content has been banned for years. Nothing has changed. Please leave all political and religious comments out of the forums.

    If you recently joined the forums you were not presented with this restriction in the terms of service. This was due to a conversion error when we went from vBulletin to Xenforo. We have updated our terms of service to reflect these corrections.

    Please note any post refering to a politician will be considered political even if it is intended to be humor. Our experience is these topics have a way of dividing the forums and causing deep resentment among members. It is a poison to the community. We appreciate compliance with the rules.

    The Staff of SOH

  • Server side Maintenance is done. We still have an update to the forum software to run but that one will have to wait for a better time.

DNSChanger Trojan update

aeromed202

SOH-CM-2014
DNSChanger Trojan


Saw an article about this in the paper today. Don't know how much might be hype about a simple problem but it might also be one of those insidious sleeper type things. It apparently mostly affects large business systems. Below is the reason for the information update, copied from the FBI website...


Update on March 12, 2012: To assist victims affected by the DNSChanger malicious software, the FBI obtained a court order authorizing the Internet Systems Consortium (ISC) to deploy and maintain temporary clean DNS servers. This solution is temporary, providing additional time for victims to clean affected computers and restore their normal DNS settings. The clean DNS servers will be turned off on July 9, 2012, and computers still impacted by DNSChanger may lose Internet connectivity at that time.

And from Gizmodo...

The DNSChanger Trojan originated in Estonia and might be lurking undetected on as many as a half-million computers in the United States, according to Brian Krebs. It has been found on the computers at half of all Fortune 500 companies and at 27 government agencies. The Trojan changes an infected computer's DNS settings to send users to fraudulent websites. What's more, the worm is particularly malicious in that it also prevents you from visiting security websites that might diagnose or fix the problem. While the men authorities suspect are behind the Trojan have been arrested, the Feds, working in concert with the Estonian government, have yet to put the final kill on the worm's botnet.
That's where the Internet shutdown comes in. The FBI has a court order allowing it to set up temporary replacement DNS servers so that those with infected computers or networks can get the worm off of their systems. The court order, however, expires on March 8th. Unless that order gets extended, anybody who hasn't cleaned up their act before it expires, might get cut off from the Internet altogether.


Below are some links for more detail. Searching revealed numerous sites about the story and many cited DCWG for help in fixing the problem.


For the story... http://www.fbi.gov/news/stories/2011/november/malware_110911


For the fix... http://www.dcwg.org/detect/
 
Back
Top