INTRO ( source f-secure )
DNSChanger is a trojan that will change the infected system's Domain Name Server (DNS) settings, in order to divert traffic to unsolicited, and potentially illegal sites.The trojan is usually a small file (about 1.5 kilobytes) that is designed to change the 'NameServer' Registry key value to a custom IP address. This IP address is usually encrypted in the body of a trojan. As a result of this change a victim's computer will contact the newly assigned DNS server to resolve names of different webservers.
Top DNS Changer Infections by Country
+----+------------+ | cc | unique_ips | +----+------------+ | US | 69517 | | IT | 26494 | | IN | 21302 | | GB | 19589 | | DE | 18427 | | FR | 10454 | | CN | 10304 | | ES | 10213 | | CA | 8924 | | AU | 8518 | | MX | 7054 | | AR | 6078 | | BR | 6074 | | JP | 5867 | | PL | 4916 | | RU | 4383 | | HU | 4021 | | TR | 3884 | | TH | 2941 | | CZ | 2134 | | CL | 2004 | | GR | 1886 | | NL | 1733 | | BE | 1721 | | PK | 1682 | +----+------------+ link : http://www.dcwg.org/top-dns-changer-infections-by-country/
As Posted on FBI site check your pc
http://www.dns-ok.us/
http://www.dns-ok.de/
http://www.dns-ok.fi/
http://www.dns-ok.ax/
http://www.dns-ok.be/
http://www.dns-ok.fr/
http://www.dns-ok.ca/
http://www.dns-ok.lu/
http://dns-ok.nl/ Dutch/English SIDN
as posted in details on f-secure blog :
other resources and link


No comments:
Post a Comment
leave your comments
Thanks !