Results 1 to 5 of 5

Thread: DNS Changer Rootkit

Threaded View

Previous Post Previous Post   Next Post Next Post
  1. #1
    Diamond Member AndyD's Avatar
    Join Date
    Jan 2010
    Location
    Cape Town
    Posts
    4,924
    Thanks
    576
    Thanked 934 Times in 755 Posts

    DNS Changer Rootkit

    If the internet goes dark on March 8th then chances are you have a rootkit infection known as DNS Changer. It originally rerouted your internet connection via a botnet system in Estonia. It also prevents security updates for antivirus applications and Windows OS. The malicious servers have been taken off-line and substituted by the FBI but your internet connection will fail March 8th onwards if you have the infection.

    It's a very small neat script that makes use of known security holes and effects several registry changes on a Windows PC. Linux users are immune. It started out as a scam to redirect internet users to malicious websites but now the servers have been substituted by the FBI it's just a general infection/security issue. There's a fairly extensive infection footprint and I came across the little critter the other day on somebody elses network. In most cases the user will be unaware of the infection until the substitute servers are pulled in a couple of weeks. Cleaning an infected PC is tricky but possible. For most victims a reinstall is the easiest way to go.

    Happy surfing!!


    http://www.pcworld.com/article/25029...html#tk.hp_pop

    http://www.infosecurity-magazine.com...o-its-victims/
    _______________________________________________

    _______________________________________________

  2. Thanks given for this post:

    Dave A (26-Feb-12)

Did you like this article? Share it with your favourite social network.

Did you like this article? Share it with your favourite social network.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •