Industry guru Dave Taylor offers tech support on technical and business topics, including iPhone, iPod, Microsoft Windows, Sony PSP, cellphones, online advertising, CSS, Web design, business, Unix, Linux, SEO, Mac OS X, and shell script programming.     


Malware virus DNSChanger could kill your Internet connectivity

It sounds like one of those rumors that seem to be created by anti-virus software companies to sell their software, a terrifying warning that in 48 hours all of your programs will stop working and your address book will be sent to some shadowy organization in Eastern Europe to analyze, but in fact the DNSChanger malware is a legitimate problem and is known -- through dissecting and analyzing the code -- to be poised to effectively disable your ability to look up any domain names starting on Monday, July 9, 2012.

Without the ability to look up domains using the Domain Name System (DNS) your computer will indeed be effectively cut off from the Internet, and restarting or unplugging and re-plugging in your modem won't solve a thing.

Not good.

Here's how you can test to see if you've been infected by DNSChanger, and if so, what you can do to remedy the situation...

In case you are still skeptical, turns out that the Federal Bureau of Investigation (FBI) has issued a general warning about this, part of what it sees as the growing threat of cyberattacks: DNS Malware: Is Your Computer Infected? In that article, they explain that it's not that the malware is going to start working on July 9, but that the temporary system they set up so that if it is running on your computer you can still get to the Internet is going to be shut down on July 9:

"Update on March 12, 2012: To assist victims affected by the DNSChanger malicious software, the FBI obtained a court order authorizing the Internet Systems Consortium (ISC) to deploy and maintain temporary clean DNS servers. This solution is temporary, providing additional time for victims to clean affected computers and restore their normal DNS settings. The clean DNS servers will be turned off on July 9, 2012, and computers still impacted by DNSChanger may lose Internet connectivity at that time."

If you have been infected, this means that the FBI has let you ignore the problem, possibly for months. But as of the next few days, their hidden solution will stop solving and you'll be in a right pickle.

So let's have a look at an easy way you can test to see if you're infected.

If you know how to get to your own DNS information on your computer (Mac users, this is easily done via System Preferences, as I detail here: Find your DNS servers on a Mac, while Windows users can get the same info by clicking "Run..." from the Start menu and type "ipconfig /all").

Compare what you have with this table of rogue DNS servers from the FBI:

Fortunately, you don't have to be a geek to test things. Instead, simply go to http://www.dns-ok.us/ and it'll hopefully pop up this message:

*phew*

If you are infected, here's what you'll see instead:

Don't panic. You know that there's a problem and there are a number of companies that are offering their anti-virus or anti-malware utilities for free. Here are few to consider:

Pick your favorite, run it, let it try and fix the problem, then check the result against http://www.dns-ok.us/ until you get things working.

Tip: Always have good backups of your files. If you've been infected by DNSChanger, you might well have other malware on your computer too. Be safe, be paranoid and be redundant for anything that it would be painful to lose.

I hope that everyone tests their system to confirm it's clear and, if you do have a problem, fix it before that July 9 deadline rolls around and you're offline. Good luck.


More Useful Articles and Reviews Articles:
✔   Review: Verticus for iPad
iOS gamers everywhere are familiar with the genre of infinite forward progress apps - Mega Jump, Canabalt, and a host of other run/jump/fly-until-you-die...
✔   Review: Clear Spot Voyager 4G wifi hotspot
Clear Voyager 4g HotspotI'm constantly on the go and with just about every site I visit available via secure SSL connection, I typically...
✔   Review: Dropcam HD wifi video camera
Whether you're security paranoid, want to keep an eye on the nanny, have a summer or winter home you'd like to peek in...
✔   Audiovox Car Connection Review
I have the smartest house on the block with a wifi-enabled thermostat and garage door opener, along with a complex web of wireless...
✔   Review: Slingbox 500
I should start with a candid admission: I'm not a huge television watcher. I catch soccer matches on Fox Soccer Channel, and watch...

Let's stay in touch!
Sign up for my weekly AskDaveTaylor Newsletter and you'll receive even more tech and gadget help right to your inbox, along with exclusive news and industry updates. It's good stuff. I promise!
    Enter your name: and your email addr:  





Categorized: Articles and Reviews   (Article 10420, Written by )
Tagged: anti-malware software, anti-virus software, cyberattacks, cybercrime, dns attacks, dnschanger, fbi, malware, pc infections, viruses
Previous: Set up Tweetgrid for a Twitter Chat?
Next: Add a Bing Search Box to my Web Site?




Reader Comments To Date: 6

Whitney said, on July 7, 2012 10:30 AM:

Wow, I had no idea. Thanks for the info!

Dave Taylor said, on July 7, 2012 10:50 PM:

Hopefully you tested negative, Whitney? I'd appreciate hearing from someone who tests positive, btw. Just use that handy contact form...

Angsuman Chakraborty said, on July 7, 2012 10:56 PM:

In Mac and Linux, as you know, it is not possible to change DNS address without root / sudo access.
As such I suspect it would be a Windows only issue.

MaryKay said, on July 8, 2012 9:56 PM:

Hey Dave,
Thanks - the link is coming up Server Not Found. Perhaps they are over run?
") MaryKay

Dave Taylor said, on July 9, 2012 12:50 AM:

Apparently they are rather drowning in users testing their computers. I'd try tomorrow morning but if you can still get online tomorrow, you're probably good to go anyway, MaryKay.

Kevin B. said, on July 9, 2012 5:59 AM:

Sir i have a question. what if i got infected by the DNS changer malware/virus and i use the system restore will the malware/virus remain in my system/hardware? thank you in advance =3

Starbucks coffee cup I do have a lot to say, and questions of my own for that matter, but first I'd like to say thank you, Dave, for all your helpful information by buying you a cup of coffee!

I do have a comment, now that you mention it!











I will never send you any unsolicited email. Ever.






Check This Out Too...

 
Look for Answers
Need Help? Ask Dave Taylor!


Follow Me on Pinterest

Find Me on Google+
ADT on G+
© 2002 - 2013 by Dave Taylor. All Rights Reserved.

Note: This web site is for the purpose of disseminating information for educational purposes, free of charge, for the benefit of all visitors. We take great care to provide quality information. However, we do not guarantee, and accept no legal liability whatsoever arising from or connected to, the accuracy, reliability, currency or completeness of any material contained on this web site or on any linked site. Further, please note that by submitting a question or comment you're agreeing to my terms of service, which are: you relinquish any subsequent rights of ownership to your material by submitting it on this site. My lawyer says "Thanks".
"Ask Dave Taylor®" is a registered trademark of Intuitive Systems, LLC.