Rabu, 11 Juli 2012

DNS Changer Malware

Bagi rekan-rekan blogger yang sering mengalami gangguan koneksi internet, dan dirasa internetnya lambat, tidak sesuai dengan speed dari paket yang dibeli, ada kemungkinan komputer rekan blogger terinfeksi malware DNS changer, untuk memastikan bisa di cek dengan DNS OK (untuk langsung ke site nya skip add) ato bisa juga di DNS OK2 atau di bisa dilakukan manual 

WIN 7 

Manually Checking for DNS Changer Infections

The following are the original manual checks to see if you computer is infected with any of the DNS Changer malware.
To check if your Windows 7 machine is infected, first click the “Start” icon.





This opens the Windows Menu. Click on the “Search” field at the bottom.





Type in cmd, and hit enter.






This opens a DOS shell. In the DOS shell, type in the command:
ipconfig /allcompartments /all
and hit enter. (Windows users might be used to just typing “ipconfig /all“. This also works, but might not list all the routing compartments if you have a VPN setup in Windows7.)


The output will be very long, since Windows7 by default has support for IPv6. Most likely, you want to look for the IPv4 information under the section entitled “Ethernet adapter…”. Look for the “DNS Servers” line, and write down these numbers. There may be two IP addresses listed there.

Are Your DNS Settings OK?

The malicious Rove viruses changed some peoples DNS settings to use computers they operated. Compare your DNS settings with the known malicious Rove DNS settings listed below:
Starting IPEnding IPCIDR
85.255.112.085.255.127.25585.255.112.0/20
67.210.0.067.210.15.25567.210.0.0/20
93.188.160.093.188.167.25593.188.160.0/21
77.67.83.077.67.83.25577.67.83.0/24
213.109.64.0213.109.79.255213.109.64.0/20
64.28.176.064.28.191.25564.28.176.0/20       

WIN XP

Manually Checking for DNS Changer Infections

The following are the original manual checks to see if you computer is infected with any of the DNS Changer malware.
To check if your Windows XP machine is infected, first click the “Start” button.
Clicking the start button opens the Windows menu. Locate the “Run” option in the menu and
select it.
In the dialog, type in “cmd”, as the name of the program to run. (This opens a DOS shell. This is also available under other parts of the Windows Menu.)
  In DOS shell, type in the command:
ipconfig /all
and hit enter.
The command you entered displays information about your computer’s network settings. Read the line starting with "DNS Servers". There might be two or more IP addresses listed there. These are the DNS servers your computer uses. Write down these numbers

Are Your DNS Settings OK?

The malicious Rove viruses changed some peoples DNS settings to use computers they operated.
Compare your DNS settings with the known malicious Rove DNS settings listed below:
Starting IPEnding IPCIDR
85.255.112.085.255.127.25585.255.112.0/20
67.210.0.067.210.15.25567.210.0.0/20
93.188.160.093.188.167.25593.188.160.0/21
77.67.83.077.67.83.25577.67.83.0/24
213.109.64.0213.109.79.255213.109.64.0/20
64.28.176.064.28.191.25564.28.176.0/20

 MAC OSX

Manually Checking for DNS Changer Infections

The following are the original manual checks to see if you computer is infected with any of the DNS Changer malware.
To check if your OSX computer is infected, first click the Apple icon in the top left.





Then, select “System Preferences…”





This opens the System Preferences dialog box. Locate the “network” icon. HINT: Type “network” in the top right corner search field.





This opens the Network settings dialog box. Read the “DNS Server” line. Write down these IP addresses.

Are Your DNS Settings Ok?

The malicious Rove viruses changed some peoples DNS settings to use computers they operated. Compare your DNS settings with the known malicious Rove DNS settings listed below:
Starting IPEnding IPCIDR
85.255.112.085.255.127.25585.255.112.0/20
67.210.0.067.210.15.25567.210.0.0/20
93.188.160.093.188.167.25593.188.160.0/21
77.67.83.077.67.83.25577.67.83.0/24
213.109.64.0213.109.79.255213.109.64.0/20
64.28.176.064.28.191.25564.28.176.0/20

Bagaimana kalo terinfeksi? kalo ada dari rekan blogger yang memiliki masalah dengan DNS Changer Malware, bisa dapatkan tool untuk memperbaikinya di :

1. Hitman Pro (32bit and 64bit versions)
2. Kaspersky Labs TDSSKiller
3. McAfee Stinger
4. Microsoft Windows Defender Offline
5. Microsoft Safety Scanner
6. Norton Power Eraser
7. Trend Micro Housecall
8. MacScan
9. Avira

Tentang cara-cara menggunakan tool DNS Changer cleaner dapat di lihat di :

1. Microsoft's Safety and Security Center
2. Apple's Security Page with pointers to keep your MAC safe
3. DSL Report’s Security Cleanup FAQ
4. Andrew K’s Malware Removal Guide
5. Public Safety Canada’a Malware Infection Recovery Guide
6. Australia’s Stay Smart Online Factsheet to help Remove Malware

Tentang DNS Changer malware lebih detail dapat di baca di :

FBI DNSChanger arrests

atau download pdf document di
 
FBI DNSChanger document 


Semoga bermanfaat.


  

Tidak ada komentar:

Posting Komentar