Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

Authorities prepare to close down DNSChanger servers, recommend DNS repair tool

DNSChanger victims should fix their DNS settings until March 8, when the temporary DNS servers will be closed down

German authorities are advising victims of DNSChanger Trojan programs to fix their computers' Domain Name System settings using a free tool developed by antivirus company Avira, because the servers resolving DNS queries on their behalf will be closed down on March 8.

DNSChanger is a family of Trojans for Windows and Mac OS X whose primary function is to replace the DNS servers defined on the victim's computer with rogue ones operated by the malware's authors.

The DNS is a vital part of the Internet infrastructure and is used to resolve domain names into numerical IP addresses. By controlling DNS responses, the DNSChanger gang was able to redirect victims to rogue websites that distributed fraudulent software or displayed money-generating advertisements.

The DNSChanger operation was shut down by the U.S. Federal Bureau of Investigation in November last year following a two-year long investigation. The authorities estimated the number of computers infected with this type of Trojan at 500,000 in the U.S. and over 4 million worldwide.

The FBI worked with ISPs where the DNSChanger gang hosted its rogue DNS resolvers in order to temporarily convert them into legitimate servers. This decision was taken in order to provide victims with sufficient time to clean their computers without disrupting their Internet access.

On Jan. 11, the German Federal Office for Information Security (BSI), announced that the temporary DNS resolvers put in place to service DNSChanger victims will be permanently shut down on March 8. The government agency worked with antivirus firm Avira to provide affected users with a tool that automatically resets their DNS settings to their default values. The tool was released Monday.

"If your computer was infected at some point in time and it was using one of the DNS servers which are now controlled by FBI, after March 8, it will no longer be able to make any DNS requests through these servers," Avira product manager and data security expert Sorin Mustaca said in a blog post. "In layman's terms, you will no longer be able to browse the web, read emails and do everything you usually do on Internet."

The Avira DNS Repair Tool is distributed for free from the company's website, as well as www.dns-ok.de, a website operated by German authorities that can be used to determine if a computer is using one of the temporary DNS servers.

The downside of the tool is that it only works on Windows and doesn't actually remove the Trojan. Users should first clean their computers with an antivirus program and then use Avira's tool to repair their DNS settings.

"Only the [network] adapters which are detected as manipulated will be changed," Mustaca said. "All others which don't have any signs of being altered by the malware will be left untouched."

Since the tool configures network adapters to automatically detect DNS settings via DHCP, it might not work for all network setups. If using the tool doesn't solve the problem, users should call their ISP and ask what their recommended DNS settings are.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: Avira, Deutsche Telekom, etwork, FBI, Federal Bureau of Investigation, SecureSoft Distribution (formerly Avira Distribution)
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: Avira, malware, security
Latest Blog Posts
Whitepapers
  • How progressive companies are using social technologies
    Social networks and collaborative technologies are now commonplace in many workplaces. Having first been used “on the quiet” by highly-networked employees, in increasing numbers they are now being proactively used by businesses keen to connect more effectively with their internal and external audiences. Web collaboration is now viewed as critical to company success and as having multiple benefits and applications to the business. Read on.
    Learn more »
  • Optimizing Data Quality in the Enterprise - How to Tackle Your Bad Information
    Data quality – the measure of data accuracy, completeness, and consistency across a business – has become the core focus of information management efforts among many of today’s organizations. Problems with data quality continue to plague corporations of all types and sizes. In this paper, we will discuss some techniques companies can implement to enhance data quality across the entire enterprise. We will also highlight data quality management solutions, which provide businesses with the ability to effectively and economically enhance the correctness, completeness, and consistency of information in each and every system within their technology infrastructure.
    Learn more »
  • Becoming a Social Business
    As global business accelerates ever faster and companies work to quickly respond to customer demands, competitive threats and rapidly evolving trends, the richness and efficiency of social collaboration plays a key role in enabling future success. The challenge then is finding the best approach. Read on.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments