DNS Changer
circleid.com
circleid.com
All the information we could find on this was from 2007-2009. It seemed like this software was out-of-date and no longer in the wild. So I always wondered why we were being contacted, especially now.
This write-up was greatly appreciated as it finally shed some light on why were contacted about it -- and more so, how the FBI were involved.
Generally I'd say that you'll know you're infected rather quick. Some evidence:
- advertising disconnected from the websites you're visiting. Random pop-up ads for example.
- most malware have ability to download and install MORE malware, which AVG will catch some of. So you'll start to randomly get AVG hits for files you did not download because the malware downloaded and attempted to install them.
- some malware will succeed in installing and end up trying to scam you out of $40.
In her case she was infected with an extremely lethal (and interesting) piece of malware called TDL3:
http://www.securelist.com/en/analysis/204792180/TDL4_Top_Bot
It hides really well by creating an encrypted partition at the end of the disk, and its primary goal is to just download and execute other malware which the authors charge a per-install fee to the other authors. It is nearly impossible to get rid of. She would randomly get infected with other more obvious viruses all the time due to this infection vector.
Running an up-to-date anti-virus still isn't going to give you 100% protection. A customer of mine recently was infected by a virus while running an up-to-date McAfee, because the virus was released before the virus definitions were updated to catch it. In the two days before McAfee updated their definitions, my customer got the virus.
There's not much reason to check if you're infected unless you suspect you are. With Conficker and DNS Changer, for example, there are symptoms of the virus. DNS Changer would reroute your search results to their own search page. The best thing to do is keep a running AV up to date, do some research on any exe you're about to run (is the distributor reputable?) and watch for sudden signs of slowness, instability, or any modifications to how your system normally behaves. If you notice changes, there are forums where people can tell you how to clean the infection. HijackThis! is a popular analytical tool (but don't change anything using it without posting it on the forums first).
Any unexpected popup requiring the administrative user's password is usually enough to know something bad is about to happen... and if software doesn't require Administrative rights to install it is usually either easy to remove or exploiting Windows in a way that's unavoidable once it's hit the machine.
Go to chrome://plugins and kill everything
When you need one of the two, run them in a separate (updated) browser in a separate guest account (fast user switching ftw).
Yeah, nobody is going to do that. Chrome has an option to have 3rd party plugins blocked by default (click to activate) and Firefox has Flashblock. That's about as much as you can expect users to do.
I do. Once you force yourself to do it once or twice it is actually pretty quick (2 keystrokes), but you rarely need Flash today anyway. There are far too many web rootkits going around for it to be worth running flash and java (OSX and windows)
see: http://krebsonsecurity.com/2010/10/java-a-gift-to-exploit-pa...
If you spend any amount of time on the web there is a chance that you have visited a page running an exploit pack. Their penetration rates are 10-20%. There is even a chance that you have been exploited right now and don't even know it.
Any extension that claims to block in Chrome doesn't actually block, since the extension API doesn't allow that - it is only hiding using CSS or some other Javascript trick that still leaves the plugins vulnerable. Flashblock for Firefox also doesn't prevent exploits of vulnerable browser plugins.
All those plugins create a false sense of security
And what do you mean flashblock in Firefox doesn't help? If you don't intentionally activate the plugin it can't hurt you.
Chrome is definitely vulnerable. They are a few versions away from making the blocking API non-experimental.
I am sure that Geek Squad would pay a substantial amount of money to be listed as one of the repair options.
The idea that network administrators should have to spend hours hunting down these people is ridiculous. When/if they find them, they're just going to shut them off anyway.
If you're relying on the internet for anything important, you probably want to know that e.g. every key you type is going to some server somewhere.
It seems to me that the right thing to do is to implement the blanket redirect centrally. If ISPs want to implement something different for their traffic, they are free to do so.
The IPs are probably now no good to anyone anyway - they will be in too many blacklists.
If it is, I don't understand why to bother at all with keeping them running. Just stop them. Internet will break for the people affected, they will someone let "repair" their computer, and you get rid of all the infected clients. This needs to be done anyway sooner or later. Why defer it?
Those people may rely on the Internet for their job, studies or social life, so you shouldn't be so quick to just pull the plug because they were unfortunate enough to get infected. To add insult to injury, you would be forcing them to spend possibly significant amounts of money to get it working again, something that not everyone has ready access to.
Shutting down this rogue DNS server will have little to no serious consequence on people's lives - it's not like the "internet" is a reliable service. People who do need reliability, have things like SONET with dual-entrance, multiple providers, and multiple data centers located in separate disaster zones with aggressive power redundancy facilities.
Depending on who you are, what you do and where you live, internet access may well be as vital to you as a land line. In fact, I'm not sure I'd notice if my landline stopped working.
75.75.75.75
75.75.76.76
2001:558:FEED::1
2001:558:FEED::2
Somebody needs to pay the money. In this case, it appears to be the taxpayer. I'm not sure I like this. I'd prefer software companies writing vulnerable software to pay the bill, or the people using the vulnerable software, or perhaps the ISPs (who are being paid by the people using the vulnerable software).
I don't like the taxpayer paying for it because software businesses are making more money by taking security shortcuts and as long as the taxpayer pays for the cost of this then there's no incentive for them to stop.
$ man crontab