Version: 2008

Comments on: New DNSChanger Trojan variant targets routers

New variant of trojan changes DNS look-up settings on routers, putting any computer on the network at risk of being sent to malicious Web sites.

Add a Comment (Log in or register) (9 Comments)
  • prev
  • 1
  • next
by tacit June 17, 2008 2:27 PM PDT
The people behind the zlob Trojan are getting pretty sophisticated in their attacks. They've targeted a large American ISP called iPower, which has had server security issues since last December, and planted redirectors on iPower-hosted Web sites. They've seeded Google with poisoned keywords which draw Google traffic to malicious sites that try to install Zlob on visitors' computers. They've penetrated large numbers of blogs running on outdated, insecure versions of WordPress, and forums running outdated versions of phpNuke and phpBB, and used them to set up redirectors to sites that try to download Zlob.

I've been following these guys for quite a while. They have built an elaborate network of Web servers intended to distribute this virus, which I've mapped out at

http://tacit.livejournal.com/240750.html
Reply to this comment
by Lerianis June 17, 2008 2:37 PM PDT
If you have been following the trail of these guys, why in the world can't the government follow their trail and put them out of business? Preferably with a 100 year prison term or having their hands cut off so that they cannot make anymore computer viruses.
by idreamincode June 17, 2008 3:55 PM PDT
not sure if OpenDNS.com's DNS servers help with this exploit. Seems like you shouldn't keep your router as the default password.
Reply to this comment
by iThreatResearcher June 18, 2008 7:30 PM PDT
DNSChanger has two executables: EXE for Windows and DMG for Mac OS X. Does it affects Mac users as well? No, here's the explanation http://ithreats.wordpress.com/2008/06/18/new-dnschanger-hacks-router-in-mac/.
Reply to this comment
by PG18 June 22, 2008 11:39 AM PDT
If you wish to test infect yourself with this virus go to this link : http://emes.com.br/index.php

The link got spammed to me to my gmail account today with the following message:

Liv Tyler New mpeg4!!!
Download now

BE CAREFUL, THIS LINK MIGHT AFFECT YOUR PC OR ROUTER IN A VERY UNDESIRABLE WAY.
Reply to this comment
by c|net Reader June 22, 2008 7:17 PM PDT
Why doesn't this blog entry mention the infection vector? Why no mention of steps to protect systems from the problem?
Reply to this comment
by armoredfish November 16, 2008 5:34 AM PST
I need your help/advice. My Dell Server has been infected with a DNS Change type of trojan.

My Internet connection has been disabled. My DNS - both primary and secondary keep changing. A downloaded McAfee 8.5i did detect it on access and whenever I try to put back the ISP given DNS addresses it does not happen. An autorun.inf file shows infected on run and the settings revert back to the DNS addresses of the trojan. I have not been able to remove it even when I ran my Windows 2003 Enterprise server in Safe mode and run McAfee. This Windows incidentally did not have updatedService Packs installed. All this in C : drive.The DNS values change to 85.120 etc.

I then installed Vista Premium on another partition and it accesses the Internet with DHCP without any IP address. I try to run an anti virus package from here but does not help or change things as they were in the C; drive which is infected. I am on the Internet and writing this email through the Vista OS. .

Which Antivirus package to use? And how? Should I run it on C: drive partition or it can run through the drive(G: drive in this case) that has Vista. It is because the C: drive does not have access to the net and browsers do not work because of the wrong DNS addresses which do not match the DNS addresses given by the ISP which provides its connection through its router which is placed on the PC.

Or, should I format C: drive and say good riddance to Win 2003? Hoping like hell that the trojan would be wiped out in C: drive. But then will the computer work again with the MBR gone in the C: drive for the Vista OS which has been installed in a separate G: drive?
Reply to this comment
by ekin_mache December 15, 2008 8:43 AM PST
i cannot remove it for about 7 days
Reply to this comment
by Flotsom February 19, 2009 11:12 PM PST
BEWARE - Don't Load the STOPzilla (listed as ZLOB) so called "anti-virus" program. After claiming to find 27 Viruses (Avira AnitVir did not see them) it crashed my system. It is just an ad program that loads at startup and asks you buy it for $10, and is very difficult to remove - took me 20 minutes and 4 restarts! Also comes with free trojan virus !
Reply to this comment
(9 Comments)
  • prev
  • 1
  • next
advertisement

15 sites that went kaput in 2009

Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.

Top 10 news stories of the decade

Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement