Thursday, November 17, 2011

Simon Heron


Despite federal prosecutors recent success against the infrastructure of DNS Changer and the prosecution of seven Eastern Europeans, it appears that the malware itself still survives. 

With its ability to infect and change systems’ DNS so that users were then redirected to websites of the scammers choosing, DNS Changer allows criminals to make money through a series of ploys. 

The method of choice of the seven accused being to exploit click ads.  It affects both Macs and Windows systems, it has been around for over five years and so it is a pretty serious threat.

So how do you find out if you are infected?  Check your DNS server settings.  On Windows open a command prompt and type “ipconfig /all”. 

This returns a plethora of information but just look for the “DNS Server” entry.  On a Mac, in “System Preferences” select “Network”, and from there select “Advanced”.

Infected systems will show IP addresses in the following ranges (from the FBI):

  • –
  • –
  • –
  • –
  • –
  • –

Companies will need to check their servers and their routers to ensure they have not been compromised.

Cross-posted from RedScan

