• On CBS MoneyWatch: 5 Great Jobs for Lousy Times
June 17, 2008 1:36 PM PDT

New DNSChanger Trojan variant targets routers

by Elinor Mills
  • Font size
  • Print
  • 9 comments

Secure Computing researchers have discovered a new variant of the DNSChanger Trojan in the wild that attacks routers, meaning any Web surfing computer on that network could be at risk of being redirected to a malicious Web site.

The DNSChanger Trojan changes the DNS settings to point to a host Web site address supplied by the attackers, Sven Krasser, director of data mining research at Secure Computing, said in an interview with CNET News.com on Tuesday.

"Your network is essentially reconfigured to do all the (domain) name resolutions over this malicious name server," he said.

The DNSChanger Trojan is able to access all the settings and functions on the router. It only knows about a few popular router Web interface URLs that it can use to change DNS settings at this time, but that is expected to change and more routers will be affected, according to a Secure Computing blog entry.

The Trojan is believed to be created by the creators of the family of malware called "Zlob," which masquerades as an ActiveX video codec.

A new variant of the DNSChanger Trojan attacks routers so that non-existing domain names are added by the malware. These rogue DNS servers, located in the Ukraine, resolve any domain name you provide and redirect to Web sites that look like the one in this screenshot.

(Credit: Secure Computing)
Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
Recent posts from News Blog
Nvidia puts NForce chipset development on hold
Opera 10 browser is here
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission
Add a Comment (Log in or register) (9 Comments)
  • prev
  • 1
  • next
by tacit June 17, 2008 2:27 PM PDT
The people behind the zlob Trojan are getting pretty sophisticated in their attacks. They've targeted a large American ISP called iPower, which has had server security issues since last December, and planted redirectors on iPower-hosted Web sites. They've seeded Google with poisoned keywords which draw Google traffic to malicious sites that try to install Zlob on visitors' computers. They've penetrated large numbers of blogs running on outdated, insecure versions of WordPress, and forums running outdated versions of phpNuke and phpBB, and used them to set up redirectors to sites that try to download Zlob.

I've been following these guys for quite a while. They have built an elaborate network of Web servers intended to distribute this virus, which I've mapped out at

http://tacit.livejournal.com/240750.html
Reply to this comment
by Lerianis June 17, 2008 2:37 PM PDT
If you have been following the trail of these guys, why in the world can't the government follow their trail and put them out of business? Preferably with a 100 year prison term or having their hands cut off so that they cannot make anymore computer viruses.
by idreamincode June 17, 2008 3:55 PM PDT
not sure if OpenDNS.com's DNS servers help with this exploit. Seems like you shouldn't keep your router as the default password.
Reply to this comment
by iThreatResearcher June 18, 2008 7:30 PM PDT
DNSChanger has two executables: EXE for Windows and DMG for Mac OS X. Does it affects Mac users as well? No, here's the explanation http://ithreats.wordpress.com/2008/06/18/new-dnschanger-hacks-router-in-mac/.
Reply to this comment
by PG18 June 22, 2008 11:39 AM PDT
If you wish to test infect yourself with this virus go to this link : http://emes.com.br/index.php

The link got spammed to me to my gmail account today with the following message:

Liv Tyler New mpeg4!!!
Download now

BE CAREFUL, THIS LINK MIGHT AFFECT YOUR PC OR ROUTER IN A VERY UNDESIRABLE WAY.
Reply to this comment
by c|net Reader June 22, 2008 7:17 PM PDT
Why doesn't this blog entry mention the infection vector? Why no mention of steps to protect systems from the problem?
Reply to this comment
by armoredfish November 16, 2008 5:34 AM PST
I need your help/advice. My Dell Server has been infected with a DNS Change type of trojan.

My Internet connection has been disabled. My DNS - both primary and secondary keep changing. A downloaded McAfee 8.5i did detect it on access and whenever I try to put back the ISP given DNS addresses it does not happen. An autorun.inf file shows infected on run and the settings revert back to the DNS addresses of the trojan. I have not been able to remove it even when I ran my Windows 2003 Enterprise server in Safe mode and run McAfee. This Windows incidentally did not have updatedService Packs installed. All this in C : drive.The DNS values change to 85.120 etc.

I then installed Vista Premium on another partition and it accesses the Internet with DHCP without any IP address. I try to run an anti virus package from here but does not help or change things as they were in the C; drive which is infected. I am on the Internet and writing this email through the Vista OS. .

Which Antivirus package to use? And how? Should I run it on C: drive partition or it can run through the drive(G: drive in this case) that has Vista. It is because the C: drive does not have access to the net and browsers do not work because of the wrong DNS addresses which do not match the DNS addresses given by the ISP which provides its connection through its router which is placed on the PC.

Or, should I format C: drive and say good riddance to Win 2003? Hoping like hell that the trojan would be wiped out in C: drive. But then will the computer work again with the MBR gone in the C: drive for the Vista OS which has been installed in a separate G: drive?
Reply to this comment
by ekin_mache December 15, 2008 8:43 AM PST
i cannot remove it for about 7 days
Reply to this comment
by Flotsom February 19, 2009 11:12 PM PST
BEWARE - Don't Load the STOPzilla (listed as ZLOB) so called "anti-virus" program. After claiming to find 27 Viruses (Avira AnitVir did not see them) it crashed my system. It is just an ad program that loads at startup and asks you buy it for $10, and is very difficult to remove - took me 20 minutes and 4 restarts! Also comes with free trojan virus !
Reply to this comment
(9 Comments)
  • prev
  • 1
  • next
advertisement

The browser battles go on and on

roundup From Firefox to IE and from Chrome to Opera and Safari, there's no sitting still for browser makers looking to keep their products fresh and competitive.

3G wireless still holds promise

The next generation of 4G wireless may get all the headlines, but advanced 3G technology will likely dominate services for the next few years.

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right