Page 1 of 2 1 2 LastLast
Results 1 to 20 of 33

Thread: July 9th Virus     submit to reddit submit to twitter

  1. #1
    An exploitable mess of a card game
    Join Date
    Sep 2008
    Posts
    13,197
    BG Level
    9
    FFXIV Character
    Gouka Mekkyaku
    FFXIV Server
    Gilgamesh
    FFXI Server
    Diabolos

    July 9th Virus

    http://www.technolog.msnbc.msn.com/t...ck-your-736963
    July 9 might be "Internet doomsday" for PC and Mac users who haven't taken steps to make sure their systems are not infected with what's being called DNSChanger malware.

    That's right: Your Internet connection may not work that day because the safety net now in place from the FBI against the malware will be removed then, and if your computer is infected, you won't be able to get to the Internet.

    Let's back up a minute to give you some quick background. Last fall, the FBI arrested six Estonian nationals who were charged with using malware and rogue DNS servers to hijack millions of computers worldwide.

    At that time, Trend Micro's Feike Hacquebord called it the "biggest cybercriminal takedown in history." The company was one of several that worked with the FBI on the takedown, and described the scheme:

    A variety of methods of monetizing the DNSChanger botnet [are] being used by criminals, including replacing advertisements on websites that are loaded by victims, hijacking of search results and pushing additional malware.

    Because the malware is so nasty — it's strong enough to wipe out a computer's anti-virus software — the FBI set up a safety net using government computers to prevent any Internet disruptions for users whose computers may be infected.

    That safety net was set to go away in February, but the date has been extended to July 9 because the agency is concerned that not enough users are aware of the problem.

    Says the FBI:

    To assist victims affected by the DNSChanger malicious software, the FBI obtained a court order authorizing the Internet Systems Consortium (ISC) to deploy and maintain temporary clean DNS servers. This solution is temporary, providing additional time for victims to clean affected computers and restore their normal DNS settings. The clean DNS servers will be turned off on July 9, 2012, and computers still impacted by DNSChanger may lose Internet connectivity at that time.

    So, what do you need to do? Make sure your computer is clean. You can do that first, by visiting this FBI-backed website, DNS-OK, which will tell you whether your computer is infected with DNSChanger malware.

    The FBI says that if you see green, that's good. Red means you're infected. Still, the bureau notes, some systems that appear to be clean may appear that way because of their service provider: "If your ISP is redirecting DNS traffic for its customers, you would have reached this site even though you are infected."

    So the next step, definitely if you're "red," but even a good idea if you're "green," is to go to this site, run by the DNS Changer Working Group. The DNS Changer Working Group will detect whether your computer has been "violated," and if so, will point you to the right fix for your computer.

    The sooner you do this, the better. You don't want to wait until July 9 to chance an "Internet doomsday" happening.
    Media-crazy hype or the real deal?

  2. #2
    hey
    hey is offline
    listen!
    Join Date
    Apr 2011
    Posts
    7,234
    BG Level
    8
    FFXI Server
    Sylph

    edit

    http://www.fbi.gov/news/stories/2011...malware_110911

    Looks like what they did was replace the dns servers that were used by the virus with real ones. Not sure why that required a court order, but anyway, it's legit. You'd have to be retarded to not notice by now though.

  3. #3
    An exploitable mess of a card game
    Join Date
    Sep 2008
    Posts
    13,197
    BG Level
    9
    FFXIV Character
    Gouka Mekkyaku
    FFXIV Server
    Gilgamesh
    FFXI Server
    Diabolos

    Here's the CNN article if this clears up any stuff:

    http://articles.cnn.com/2012-04-23/t...ers?_s=PM:TECH

    In the wake of a multi-million-dollar online scam, more than 300,000 computer users worldwide could find themselves without Web access this summer.

    Luckily for them, it will only take a few clicks to clean things up.

    The FBI announced that it's created a website where users can check whether they're infected with malware and remove it if they are. Check your computer here -- http://www.dcwg.org. The site was at times difficult to access on Monday, presumably due to heavy traffic.

    Let us explain: In November, six Estonian nationals were arrested on charges of fraud after a two-year FBI probe called Operation Ghost Click.

    They're accused of infecting computers worldwide with malware called DNS Changer, which opened up the computers to viruses. The alleged crooks used the access to direct users to their own servers and manipulate online advertising, racking up more than $14 million in illegal income, according to the FBI.

    "They were organized and operating as a traditional business but profiting illegally as the result of the malware," an unnamed FBI agent said in a news release about the arrests. "There was a level of complexity here that we haven't seen before."

    The FBI originally estimated the scam had hit millions of computers worldwide, but has since scaled back those estimates to hundreds of thousands. They think about 350,000 computers are still infected, including 85,000 in the United States.

    The U.S. computers included some at government agencies, including NASA.

    Last month, the FBI announced that it had set up temporary "clean" servers to make sure the users impacted by the attack didn't lose Web access. Those servers will be shut down on July 9, and anyone still infected will be unable to access the Internet afterward.

    If it had merely shut down the rogue servers, many of those infected wouldn't have been able to access the Web at all, the FBI said.

    Most infected users on the FBI servers may not have noticed anything different, although the malware itself may have made their Web access slower and disabled their anti-virus software.

    Domain Name System, or DNS, servers are what online computers visit to reach the website they are seeking. By routing them to rogue servers, criminals can control which websites a computer visits.

    By visiting the website set up by the FBI, users can click to see if their computer is infected. An image with a green background appears if they're OK, while a red one shows up if they're not. If infected, they're then directed to information on how to remove the malware.

    The case against the accused scammers is still pending in federal court. One of them was extradited last week from Estonia to New York to face charges.
    Reading this article, this seems like only people not noticing their AV down would be infected, ya?

  4. #4
    I Am, Who I Am.
    Join Date
    Nov 2005
    Posts
    15,657
    BG Level
    9
    FFXIV Character
    Trixi Sephyuyx
    FFXIV Server
    Excalibur
    FFXI Server
    Ragnarok

    They have one of these scares a few times a year.
    It's all bullshit.

  5. #5
    hey
    hey is offline
    listen!
    Join Date
    Apr 2011
    Posts
    7,234
    BG Level
    8
    FFXI Server
    Sylph

    Quote Originally Posted by SephYuyX View Post
    They have one of these scares a few times a year.
    It's all bullshit.
    It's legit. Anyone infected will suddenly find themselves trying to connect to non-existent dns servers, making it kind of difficult to connect to any websites. There aren't that many people infected, and if you are it's easy to notice, and easy to fix though.

  6. #6
    I Am, Who I Am.
    Join Date
    Nov 2005
    Posts
    15,657
    BG Level
    9
    FFXIV Character
    Trixi Sephyuyx
    FFXIV Server
    Excalibur
    FFXI Server
    Ragnarok

    Let me rephrase.
    While the viruses may be real, it's never "doomsday" worthy.

  7. #7
    Hyperion Cross
    Join Date
    Jan 2007
    Posts
    8,902
    BG Level
    8
    FFXIV Character
    Kai Bond
    FFXIV Server
    Gilgamesh

    Siding with SephYuyX I'm jaded by these dumb scares nowadays. I want to know the real deal/detail of all this -- what exactly is it changing? What files are being modified, what's the process name called? Why is typing in July 9th Virus into Google not producing ANY result (like you would with any other malware/spyware) for any of the well known AV websites that usually produces some sort of tool to get it fixed for you?

    What's even more dumb is, skimming over that "FBI" site why is it intent on providing vague instructions on how to check it ourselves? Why not just tell us to right click our internet connection properties, click on the networking tab, click on IPv4/IPv6 and see if the DNS entries have anything in them? (most average home users won't).

    What's even more dumb is why is that site, the "FBI created site" got the following details?

    omain ID:D163784402-LROR
    Domain Name:DCWG.ORG
    Created On:04-Nov-2011 19:06:39 UTC
    Last Updated On:23-Apr-2012 17:10:37 UTC
    Expiration Date:04-Nov-2013 19:06:39 UTC
    Sponsoring Registrar:GoDaddy.com, LLC (R91-LROR)
    Status:CLIENT DELETE PROHIBITED
    Status:CLIENT RENEW PROHIBITED
    Status:CLIENT TRANSFER PROHIBITED
    Status:CLIENT UPDATE PROHIBITED
    Registrant ID:CR97261582
    Registrant Name:Barry Greene
    Registrant Street1:11692 Westshore Court
    Registrant Street2:
    Registrant Street3:
    Registrant City:Cupertino
    Registrant State/Province:California
    Registrant Postal Code:95014
    Registrant Country:US
    Registrant Phone:+1.4082184669
    Registrant Phone Ext.:
    Registrant FAX:
    Registrant FAX Ext.:
    Registrant Email:http://source.domaintools.com/email....;]=transparent
    Admin ID:CR97261584
    Admin Name:Barry Greene
    Admin Street1:11692 Westshore Court
    Admin Street2:
    Admin Street3:
    Admin City:Cupertino
    Admin State/Province:California
    Admin Postal Code:95014
    Admin Country:US
    Admin Phone:+1.4082184669
    Admin Phone Ext.:
    Admin FAX:
    Admin FAX Ext.:
    Admin Email:http://source.domaintools.com/email....;]=transparent
    Tech ID:CR97261583
    Tech Name:Barry Greene
    Tech Street1:11692 Westshore Court
    Tech Street2:
    Tech Street3:
    Tech City:Cupertino
    Tech State/Province:California
    Tech Postal Code:95014
    Tech Country:US
    Tech Phone:+1.4082184669
    Tech Phone Ext.:
    Tech FAX:
    Tech FAX Ext.:
    Tech Email:http://source.domaintools.com/email....;]=transparent
    This guy seems legit but he doesn't work for the FBI: http://www.linkedin.com/in/barryrgreene

    Besides, for people like us, we'd just laugh it off, backup and reformat. Win. We're way too savvy to get caught by some dumb scare. In fact I've never ever seen anyone at work or personally be affected by any of these huge virus scares.

    EDIT: Just to clarify, I'm sure this is real but it just seemed to have got out of hand and all over the place. But it just seems way too odd/dumb to be afraid of anything. I'm just very intrigued in general, and why no AV websites seem to be reporting on this -- without going on them directly.

    EDIT2: Sorry, I failed to notice the manual instructions there. Funny that they failed to produce one for Vista though. I mean, what's so different between them? Why is an "expert" who produced these guides failed to produce one for vista using exactly the same commands a XP/7 (more or less)

    EDIT3: Sorry this has got me really interested. I just saw the FBI published PDF. Some of the screenshots are so horrible I wonder who the hell approved of it. This is of a FBI published document here, I expected better lol

    EDIT4: After reading the PDF, and exactly as I expected, this all doesn't seem like anything new... infact, it's rather dull now. From hosts file to a DNServer, just the same really, except on a bigger scale lol

    EDIT5: I think i need to sleep now ... 20 hours awake and I don't think I'm thinking correctly anymore lol ... but this was the first thing to catch my eye when i arrived home from work

  8. #8
    True skill only comes from macro switching all your e-peen gear thru 10 pages
    Join Date
    Sep 2007
    Posts
    4,740
    BG Level
    7
    FFXI Server
    Quetzalcoatl

    Welcome Stig to 'Murika the land where we half-ass everything! Oh and people are afraid of everything.

  9. #9
    hey
    hey is offline
    listen!
    Join Date
    Apr 2011
    Posts
    7,234
    BG Level
    8
    FFXI Server
    Sylph

    Quote Originally Posted by SephYuyX View Post
    Let me rephrase.
    While the viruses may be real, it's never "doomsday" worthy.
    Oh, yeah. That's about right.

    Honestly, i don't know why they didn't just configure the dns server to redirect everything to the fbi.gov page explaining they have a virus, and how to remove it.

  10. #10

    Sweaty Dick Punching Enthusiast

    Join Date
    Jan 2010
    Posts
    9,355
    BG Level
    8
    FFXI Server
    Leviathan

    Inb4 "install this on your computer" and fbi/government start sniping people for pirating. Calling it now

  11. #11
    An exploitable mess of a card game
    Join Date
    Sep 2008
    Posts
    13,197
    BG Level
    9
    FFXIV Character
    Gouka Mekkyaku
    FFXIV Server
    Gilgamesh
    FFXI Server
    Diabolos

    Quote Originally Posted by AidenCarby View Post
    Inb4 "install this on your computer" and fbi/government start sniping people for pirating. Calling it now
    This was my thought as well.

  12. #12

    ▲▲

    Join Date
    Aug 2005
    Posts
    6,803
    BG Level
    8
    FFXIV Character
    Pikarya Saisei
    FFXIV Server
    Excalibur

  13. #13
    I Am, Who I Am.
    Join Date
    Nov 2005
    Posts
    15,657
    BG Level
    9
    FFXIV Character
    Trixi Sephyuyx
    FFXIV Server
    Excalibur
    FFXI Server
    Ragnarok

    I'll vouch for that suite; it's pretty reliable.
    Been using it for over 10 years.

  14. #14
    hey
    hey is offline
    listen!
    Join Date
    Apr 2011
    Posts
    7,234
    BG Level
    8
    FFXI Server
    Sylph

    Quote Originally Posted by Pikarya View Post
    This can be difficult for some people to configure, but once you've got it running, it works really well.

  15. #15
    Sleep Deprived Galka BLM
    Join Date
    Nov 2007
    Posts
    1,183
    BG Level
    6
    FFXI Server
    Odin

    I think the estimate was that as many as 64000 computers in America could be affected. That's like, 0.0002133333333% of Americans that could be at risk.

  16. #16
    D. Ring
    Join Date
    Apr 2006
    Posts
    4,738
    BG Level
    7
    FFXI Server
    Siren

    That's true.

    But YOU might be the person who has to spend several hours needlessly driving and fixing your mom's/aunt's PC because they can't play Farmville or make the Googles. Do you want to be that guy? Huh? Well do ya? I thought not.

  17. #17

    ▲▲

    Join Date
    Aug 2005
    Posts
    6,803
    BG Level
    8
    FFXIV Character
    Pikarya Saisei
    FFXIV Server
    Excalibur

    Just don't fix their shit. Let them suffer for being mentally retarded.

  18. #18
    Hyperion Cross
    Join Date
    Jan 2007
    Posts
    8,902
    BG Level
    8
    FFXIV Character
    Kai Bond
    FFXIV Server
    Gilgamesh

    Quote Originally Posted by Omniyoji View Post
    Welcome Stig to 'Murika the land where we half-ass everything! Oh and people are afraid of everything.
    Maybe because recently I've been involved in helping the client with content management which made me nitpick that PDF. One more thing that annoyed me is the lack of any official FBI logos or print around the document lol.

    So where can I pick up this "virus" lol. I'm curious of the damage.

  19. #19
    D. Ring
    Join Date
    Jun 2006
    Posts
    4,855
    BG Level
    7
    FFXI Server
    Ragnarok
    WoW Realm
    Nazjatar

    just change your dns to a random series of numbers, should have the same effect

  20. #20
    Hyperion Cross
    Join Date
    Jan 2007
    Posts
    8,902
    BG Level
    8
    FFXIV Character
    Kai Bond
    FFXIV Server
    Gilgamesh

    Nonono, I want to experience this "floodgate" of viruses that will be unleashed upon me if I connect to these acid DNS servers

Page 1 of 2 1 2 LastLast