What is the DNS Changer Malware?

 
On November 8, 2011, the FBI, the NASA-OIG and Estonian police arrested several cyber criminals in “Operation Ghost Click”. The criminals operated under the company name “Rove Digital”, and distributed DNS changing viruses, variously known as TDSS, Alureon, TidServ and TDL4 viruses.

However, let's start with the basics. What is DNS and what does it do? DNS stands for Domain Name System. Every computer connected to the Internet is given an IP (Internet Protocol) address, and every website is also assigned an IP address. For instance, when you try to find PCHELL.COM in your web browser, the DNS looks up the IP address of the domain and finds the corresponding web server on the Intenet where that domain is hosted. This is how the Internet is connected and how you can find information that is located all over the world. The DNS is like a giant table of contents for the Internet.



What these DNS Changing viruses do is reroute your lookup for a domain to an infected server, that might serve you ads, viruses, or just the wrong site to your web browser. So, when you type PCHELL.COM into your web browser you might end up on google.com or any other site where the DNS has rerouted your request.

What does the DNS Changer Malware do?

 
The botnet operated by Rove Digital altered user DNS settings, pointing victims to malicious DNS in data centers in Estonia, New York, and Chicago. The malicious DNS servers would give fake, malicious answers, altering user searches, and promoting fake and dangerous products. Because every web search starts with DNS, the malware showed users an altered version of the Internet.

What these DNS Changing viruses do is reroute your lookup for a domain to an infected server, that might serve you ads, viruses, or just the wrong site to your web browser. So, when you type PCHELL.COM into your web browser you might end up on google.com or any other site where the DNS has rerouted your request. When you try to run Windows Update you might be met with an error 80244019 in Windows Vista or 7 that simply states it cannot reach the correct server.

Under a court order, expiring July 9, 2012, the Internet Systems Consortium is operating replacement DNS servers for the Rove Digital network. This will allow affected networks time to identify infected hosts, and avoid sudden disruption of services to victim machines.

This means if your system is infected with the DNSChanger trojan, you won't be able to access anything on the Internet after July 9, 2012 because those DNS servers will be offline.

How Do I Know if I'm Infected with the DNSChanger Trojan?


To manually check your computer for a DNSChanger infection, follow these steps:

in Windows XP
  • Click on Start, Run
  • Type CMD and press Enter
  • Type IPCONFIG /ALL and press Enter
  • Find the line starting with DNS Servers. there should be IP numbers there. Refer to the table below to see if these numbers match any of the known DNSChanger IPs
In Windows Vista
  • Click on the Windows orb in the lower left of the Start bar
  • Click in the Search box and type CMD and press Enter
  • At the command prompt, type IPCONFIG /ALL and press Enter
  • Find the line starting with DNS Servers. there should be IP numbers there. Refer to the table below to see if these numbers match any of the known DNSChanger IPs
In Windows 7
  • Click on the Windows orb in the lower left of the Start bar
  • Click in the Search box and type CMD and press Enter
  • At the command prompt, type IPCONFIG /ALL or IPCONFIG /ALLCOMPARTMENTS /ALL and press Enter
  • Find the line starting with DNS Servers. there should be IP numbers there. Refer to the table below to see if these numbers match any of the known DNSChanger IPs
DNSChanger Infected IPs
Starting IP Ending IP CIDR
85.255.112.0 85.255.127.255 85.255.112.0/20
67.210.0.0 67.210.15.255 67.210.0.0/20
93.188.160.0 93.188.167.255 93.188.160.0/21
77.67.83.0 77.67.83.255 77.67.83.0/24
213.109.64.0 213.109.79.255 213.109.64.0/20
64.28.176.0 64.28.191.255 64.28.176.0/20

If your DNS looks like any of the IPs in the table above, you are infected with the DNSChanger trojan and you need to remove it to maintain Internet connectivity after July 9, 2012.

You may also visit the following site setup by the FBI to check for infections.

http://www.dcwg.org

Easiest Way to Remove the DNSChanger Trojan


If the DNSChanger trojan is on your computer chances are you may be infected with more viruses or trojans. One of my favorite programs for finding these problems is MalwareBytes Anti-Malware. Its a fantastic removal program for almost any type of infection.

Download MalwareBytes Anti-Malware by clicking on the link below. Save the file to your desktop. When the download completes, double-click on the file and install it. Then run an update and start a full scan of your computer.

Download MalwareBytes Anti-Malware

If you use MalwareBytes Anti-Malware to scan your computer, you'll find information in the log file similar to the following if the DNS Changer trojan is found.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.116.148 85.255.112.223 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{806586a1-a695-45bb-9075-88b9ef4addf6}\NameServer (Trojan.DNSChanger) -> Data: 85.255.116.148,85.255.112.223 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.116.148 85.255.112.223 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\{806586a1-a695-45bb-9075-88b9ef4addf6}\NameServer (Trojan.DNSChanger) -> Data: 85.255.116.148,85.255.112.223 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.116.148 85.255.112.223 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{806586a1-a695-45bb-9075-88b9ef4addf6}\NameServer (Trojan.DNSChanger) -> Data: 85.255.116.148,85.255.112.223 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.116.148 85.255.112.223 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Tcpip\Parameters\Interfaces\{806586a1-a695-45bb-9075-88b9ef4addf6}\NameServer (Trojan.DNSChanger) -> Data: 85.255.116.148,85.255.112.223 -> Quarantined and deleted successfully.

Another great tool for removing these infections is TDSSKiller by Kaspersky

After removing the infections, try some of the sites that you may not have been able to reach before, or visit the DCWG.org site to check your system again.



Buy Anti-Virus Software


If you don't already have antivirus software loaded on your computer. You should download and install an antivirus product immediately. The popular commercial antivirus products like McAfee and Norton are ok, but there are also excellent free antivirus solutions available. Listed below are some of the popular free and commercial antivirus software products.

Learn more information about Viruses at the PC HELL Virus Center


Written by Mark Hasting





Links to Other Important Information

Support for Windows XP and Windows Vista without latest service packs ends in 2010

How to Fix 500 Internal Server Error in PHP 5.4 script

Computer shows Stop error and Continously Reboots after SP3 installed.

Product Key Does Not Match Current Windows SKU Error

Review of FastAgain PC Booster and How to Uninstall it

How to Remove MSBLAST.EXE worm

How to Remove Content Advisor Password in Internet Explorer

How to Fix Google Chrome not Opening Web Pages or Settingsnew

How to Remove Incredimail Automatically

How to Fix Problem of Limited or No Connectivity After installing Windows XP Service Pack 2

How to Recover From a Corrupted Registry in Windows XP

How to Speed Up Windows Boot Time

Acer ERecovery Service is Not Available

Acer Recovery CD Restore Failed Reason: 0xf0000051

How to Fix Problem with No Active Mixer Devices Available in Windows XP

Parents Guide to MySpace.com - a report every parent should read

Save and Restore Desktop Layout of Icons

What is Windows Genuine Advantage and How to Overcome Problems With It

Change Forgotten Administrator Password in Windows XP/2000/Vista

Not Enough Server Storage Error When Connecting to Computer on Network

Installing Windows Vista Upgrade on a Blank Hard Drive

How to Delete Your Windows Vista Logon Password

Remove Unwanted Icons from the Windows Vista Welcome Center

Cannot Connect to Network Printer with Windows Vista

How to Wipe, Delete, Degauss, and Destroy Data on a Hard Drive

Fixing RTHDCPL.EXE - Illegal System DLL Relocation Error in Windows XP

How to Fix Blank or Missing Title Bar in IE9

Unable to Open New Tab in IE9 - Spinning Favicon

Fix 404 Errors for /apple-touch-icon-precomposed.png and /apple-touch-icon.png

What is the Config.Msi folder and Can I Delete It?

Flash Player Installation Issues

How to Set Yahoo Mail as your Default Email Program

Unknown File in Winsock LSP - NWPROVAU.DLL - Can it be Removed?

How to Delete a Service in Windows Vista

How to Disable the On-Screen Keyboard in Windows Vista

Make Disk Cleanup Run Faster

What is CTFMON.EXE and How Can I Remove It

How to Export MSN Favorites to Internet Explorer

How to Fix Registry Editing Has Been Disabled By Your Administrator Error

How to Change Default Editor in Windows and Fax Viewer

How to Fix Problem when Windows Security Center reports multiple antivirus programs installed

How to Fix Problem when Windows Updates will download but will not install

How to Fix Problem when Windows Automatic Updates Service wont Start

Cannot Download Files With Internet Explorer

How to Keep Your Computer Up-to-Date

How to Fix the Prompt for Click to Run an ActiveX Control on this webpage

How to Remove "This Page Contains Both Secure and NonSecure Items" Warning Message

How to Fix Problem with Blank Add/Remove Control Panel

How to Fix Windows Vista Update Error 80244019

Troubleshooting An Error Occurred During Directory Enumeration

How to View and Decipher Minidump files created by Blue Screen error messages

How to Fix BLService Error on HP Computer in Vista

Google Adsense Hijacking - How to Respond

Windows Defrag Does Not Complete

Review of BigString Recallable Email

Fix Incorrect Time Stamp on Hotmail Messages

Deleting or Editing Typed URLs in the Internet Explorer Address Bar

Belarc Advisor - Quick Computer Inventory Software

How to Get Out of Full Screen Mode in Internet Explorer

How to Correct Missing "Copy to CD" option in My Pictures Tasks

How to Fix Code 39 error with CD or DVD Drive

How to Fix Problems When Windows Installer Popups Error With Missing .MSI Files

How to Fix Problems When Network Setup Wizard and Network Connections Won't Open

How to Fix Problems with Windows Help Errors

How to Delete Individual Entries from Run Command History

Foxit - Adobe Reader Alternative

How to Fix Autochk Program Not Found error

Difference between Master/Slave and Cable Select on a Hard Drive

How to Use Microsoft SyncToy to backup your important files

How to Delete Temporary Internet Files, Cookies, and History files

Review of PCDecrapifer Software Removal Tool

How to Fix Security Flaw in Adobe Reader

Computer Speakers Sound like Chipmunks

How to SVCHOST.EXE Application Error 0x745f2780

Troubleshooting the Unmountable Boot Volume Error in Windows XP

How to Disable, Uninstall, and Remove Windows Messenger instant messaging from Windows XP

How to Remove Windows Messenger in Windows XP

Free DVD Decoder Software and Help

Free CD Burning Software and Help

How to Use Remote Desktop to Access Multiple Computer on Your LAN

HijackThis Tutorial for removing Spyware

Review of Adsense Detective, Getting Stats and Results from Adsense

How to Disable System Restore in Windows ME or Windows XP

How to Uninstall Internet Explorer 7

How to Install NetBEUI in Windows XP

What is the KB891711.exe file in Windows 98 or Windows ME?

How to Troubleshoot and Solve USB Device Error Code 10

Spooler Subsystem App has encountered a problem and needs to close Error and How to Fix it

How to Fix Problem opening Microsoft Outlook

How to Disable News Headlines in Netscape

How to Bring Back Missing Folders in Netscape Communicator

How to Fix Access Denied Error when Using MSCONFIG

How to Fix HPQKBFiltr.Sys Keylogger Error in Kaspersky Antivirus

How to Backup and Restore Outlook Express Mail, Address Book, Blocked Senders List and other Settings

How to Fix Error 501 Permission Denied when changing fonts in Outlook Express

What is the Tilde (~) File on my Desktop?

What is the thumbs.db file and can I remove it

Password is Not Saved in Outlook Express or Outlook in Windows XP

Allow Viewing of Attachments in Outlook Express 6

How to Fix Problem of No Spell Check in Outlook Express

How to Fix Problems Viewing or Accessing Secure Web Sites

How to Start or Boot Windows into Safe Mode

What is the Winmail.dat file attached to emails?

How to Correct Unreadable Fonts in Norton Antivirus or Norton Systemworks

How to correct issue with No Visible Menu Bar or Tabs in Windows XP Task Manager

How Disable/Enable the Windows XP Welcome Screen

How to Fix RTLGINA2.DLL error with Windows XP Welcome Screen and Netgear WG111

How to Fix Windows Update Error 0x80070420

PopUp Ad Removal Software and Help

Review of ErrorNuker program to identify and fix problems with the Windows Registry

Spyware and Adware Removal Help

Review of Netflix Online DVD Rental

Recommended Software for PC Hell Visitors