DNSChanger Trojan

Chat about just about anything else

DNSChanger Trojan

Postby sunewbie on Fri Mar 02, 2012 3:21 am

Linux Beginners Search Engine | more details | Google CSE Page
Acceptance = Relief, Resistance = Stress | Strength become Habit, Habit becomes Weakness
Be not a traitor in your thoughts. Do everything that is necessary in Proper time.
User avatar
sunewbie
Level 5
Level 5
 
Posts: 509
Joined: Sun Sep 04, 2011 12:55 pm
Location: Mumbai, India

Linux Mint is funded by ads and donations.
 

Re: DNSChanger Trojan

Postby Aging Technogeek on Fri Mar 02, 2012 9:17 am

The first ,and to an extent, the second link you posted read like malware sites themselves, trying to scare people into buying their removal tools (which are more likely to add malware than remove it).

The threat is apparently real, though. And it can infect Linux systems since it attacks the web browser rather than the OS itself.

I would suggest using the link in the third site, http://www.dns-ok.de to do a free check of your system. It will be in German. The response if your system is clean will look like this

Ihr System ist nicht vom Trojaner "DNSChanger" betroffen


If you are clean, just follow all safe browsing practices to minimize the chance of infection.
Image

Registered Linux User 483387
User avatar
Aging Technogeek
Level 13
Level 13
 
Posts: 4557
Joined: Sun Jan 11, 2009 9:54 am
Location: Right about here

Re: DNSChanger Trojan

Postby sunewbie on Fri Mar 02, 2012 9:24 am

oh, I did not realize this. I thought they are blogs, just giving info. It also has a link to an article by FBI. So thought would just post it.

Anyways, should I remove first 2 links?
Linux Beginners Search Engine | more details | Google CSE Page
Acceptance = Relief, Resistance = Stress | Strength become Habit, Habit becomes Weakness
Be not a traitor in your thoughts. Do everything that is necessary in Proper time.
User avatar
sunewbie
Level 5
Level 5
 
Posts: 509
Joined: Sun Sep 04, 2011 12:55 pm
Location: Mumbai, India

Re: DNSChanger Trojan

Postby Aging Technogeek on Fri Mar 02, 2012 9:54 am

No, they are probably valid articles. They just have the sound and feel of some of the alarmist type ads posted by those who sell you malware in the guise of malware removal tools. Since the FBI activity is mentioned in one of the other topics, it tends to validate the entire story. Also, a quick Google search returned enough references to legitimate news sites and other trustworthy sites to rule out a scam.

As I said, if you are worried, go to the site I mentioned above. The site is posted by the company that distributes Avira anti-virus and malware detection systems, so it should be legitimate. It will run a check and instantly let you know if you are clean. And it will not try to sell you anything.
Image

Registered Linux User 483387
User avatar
Aging Technogeek
Level 13
Level 13
 
Posts: 4557
Joined: Sun Jan 11, 2009 9:54 am
Location: Right about here

Re: DNSChanger Trojan

Postby sunewbie on Fri Mar 02, 2012 10:03 am

Ya. The third link is better one. If I remember, Avira also has a LIVE CD (exe) - which can be used as a rescue disk in both Linux and windows.

Just wanted to post this info. Many Linux users use widows, mainly in offices.

Thanks for advice. I will check it out, but march 8 is a national holiday, for Hindu festival of colours Holi :)
Linux Beginners Search Engine | more details | Google CSE Page
Acceptance = Relief, Resistance = Stress | Strength become Habit, Habit becomes Weakness
Be not a traitor in your thoughts. Do everything that is necessary in Proper time.
User avatar
sunewbie
Level 5
Level 5
 
Posts: 509
Joined: Sun Sep 04, 2011 12:55 pm
Location: Mumbai, India

Re: DNSChanger Trojan

Postby Chrisbo on Sat Apr 21, 2012 8:47 am

For detection of this trojan, here's a better link to many different languages: http://www.dcwg.org/detect/
Chrisbo
Level 1
Level 1
 
Posts: 25
Joined: Wed May 13, 2009 12:31 pm

Re: DNSChanger Trojan

Postby sunewbie on Sat Apr 21, 2012 8:52 am

Chrisbo wrote:For detection of this trojan, here's a better link to many different languages: http://www.dcwg.org/detect/


Thanks for the link :)
Linux Beginners Search Engine | more details | Google CSE Page
Acceptance = Relief, Resistance = Stress | Strength become Habit, Habit becomes Weakness
Be not a traitor in your thoughts. Do everything that is necessary in Proper time.
User avatar
sunewbie
Level 5
Level 5
 
Posts: 509
Joined: Sun Sep 04, 2011 12:55 pm
Location: Mumbai, India

Re: DNSChanger Trojan

Postby Habitual on Sat Apr 21, 2012 10:11 am

User avatar
Habitual
Level 7
Level 7
 
Posts: 1609
Joined: Sun Nov 21, 2010 8:31 pm
Location: uid=0(root) gid=0(root) groups=0(root)

Re: DNSChanger Trojan

Postby sunewbie on Sat Apr 21, 2012 10:41 am

thanks @habitual
Linux Beginners Search Engine | more details | Google CSE Page
Acceptance = Relief, Resistance = Stress | Strength become Habit, Habit becomes Weakness
Be not a traitor in your thoughts. Do everything that is necessary in Proper time.
User avatar
sunewbie
Level 5
Level 5
 
Posts: 509
Joined: Sun Sep 04, 2011 12:55 pm
Location: Mumbai, India

Re: DNSChanger Trojan

Postby Habitual on Sat Apr 21, 2012 12:24 pm

You're very welcome.
User avatar
Habitual
Level 7
Level 7
 
Posts: 1609
Joined: Sun Nov 21, 2010 8:31 pm
Location: uid=0(root) gid=0(root) groups=0(root)

Re: DNSChanger Trojan

Postby ginosal on Sun Jul 08, 2012 9:05 am

Hi. I'm having problems with my internet connection. It's very unstable, but only for some pages, which sometimes show this error: Error 105 (net::ERR_NAME_NOT_RESOLVED):. I've got the same problem on my desktop and on my notebook, so I don't think it's a problem of my computers. If there's a problem, it must be in the router or it's a ISP problem. So I've tried to reset my router, but I still get this problem (sometimes, on some pages). So I asked myself: could it be a DNS-Changer problem? I've made the tests you posted, and I always get the green background. Is there anything else I can do in order to discover if my computers or my router have been attacked by malware? Thanks!
Linux Mint 13 'Maya'
ginosal
Level 1
Level 1
 
Posts: 25
Joined: Sat Feb 12, 2011 1:10 pm

Re: DNSChanger Trojan

Postby Habitual on Sun Jul 08, 2012 2:34 pm

http://www.dns-ok.us/ for a visual check in English.

http://www.dcwg.org/?page_id=381

krebsonsecurity says "On July 9, 2012, any systems still infected with the DNSChanger Trojan will be summarily disconnected from the rest of the Internet".
Good, more room for me.

And for the Type As out there just like me...net ranges of rogue servers 8)
Code: Select all
85.255.112.0-85.255.127.255
67.210.0.0-67.210.15.255
93.188.160.0-93.188.167.255
77.67.83.0-77.67.83.255
213.109.64.0-213.109.79.255
64.28.176.0-64.28.191.255


NONE of the articles I perused on this topic mention any Linux hosts. All cleaning instructions are for Win and Mac
User avatar
Habitual
Level 7
Level 7
 
Posts: 1609
Joined: Sun Nov 21, 2010 8:31 pm
Location: uid=0(root) gid=0(root) groups=0(root)

Re: DNSChanger Trojan

Postby KBD47 on Sun Jul 08, 2012 10:32 pm

Now you know why I love Linux:

DNS Changer can infect both Windows and Mac systems. Linux users are safe, as are those using iPhones, iPads, Android devices and other systems.
http://www.forbes.com/sites/adriankings ... come-july/
KBD47
Level 5
Level 5
 
Posts: 888
Joined: Fri Jul 29, 2011 12:03 am

Re: DNSChanger Trojan

Postby tdockery97 on Sun Jul 08, 2012 11:46 pm

Habitual wrote:"On July 9, 2012, any systems still infected with the DNSChanger Trojan will be summarily disconnected from the rest of the Internet".
Good, more room for me.


:lol: :lol:
Image
Mint 15 Cinnamon RC
HP2000 Notebook, 4GB DDR3, ATI Radeon 6310
User avatar
tdockery97
Level 12
Level 12
 
Posts: 4460
Joined: Sun Jan 10, 2010 8:54 am
Location: Salem, Oregon

Re: DNSChanger Trojan

Postby /dev/urandom on Tue Jul 10, 2012 10:14 am

KBD47 wrote:Now you know why I love Linux:

DNS Changer can infect both Windows and Mac systems. Linux users are safe, as are those using iPhones, iPads, Android devices and other systems.
http://www.forbes.com/sites/adriankings ... come-july/

The fact that DNSChanger is not compatible with Linux does not invalidate the fact that Linux systems can be infected by malware.
Linux is not the only answer! :: eD2k/Kad mirrors for Linux Mint and LMDE.
Users who misspell "Windows" as "Windoze" intentionally will be considered stupid.

Image
User avatar
/dev/urandom
Level 4
Level 4
 
Posts: 318
Joined: Sun Jul 17, 2011 8:02 pm

Linux Mint is funded by ads and donations.
 

Return to Open chat

Who is online

Users browsing this forum: No registered users and 3 guests