Google to help rid PCs of trojan that will prevent web acces

  Google is using its mass reach to notify users whose machines are believed compromised by the insidious DNSChanger trojan, an infection that could result in those computers being unable to connect to the web in six weeks.

  Last month, the Department of Homeland Security estimated in a blog post that more than 84,000 PCs in the United States remained poisoned by the trojan, down from around half a million earlier this year. Another few hundred thousand computers are infected outside of the country. Some of the tainted endpoints are located at Fortune 500 companies and government agencies.

  When activated, the malware is capable of modifying DNS settings to send users to sites of the attacker's choosing. The trojan also can disable anti-virus and other security software.

  But that should not be the immediate concern of infected users. That's because last year the FBI charged six Estonian citizens with masterminding a $14 million fraud campaign involving the DNSChanger trojan.

  As part of the raid, federal agents seized the command-and-control servers that were used to manage the malware. Under a federal court order, the rogue DNS servers were replaced with legitimate servers that were initially meant to operate until March 8, but a judge in March granted a four-month extension for users to purge the trojan from their systems.

  Once deadline day -- July 9 -- comes and goes, computers that still have the trojan installed will no longer be able to connect to the internet. Now, Google is stepping in to help speed up remaining remediation efforts. Using its network traffic monitoring capabilities, the search giant is able to notify users if their computers are infected.

  Damian Menscher, a Google security engineer, said Tuesday in a blog post that this method is undeniably effective, but it is not an exact science. Google provided a similar courtesy service last summer with a strain of rogue anti-virus software that was making the rounds.

  "We believe directly messaging affected users on a trusted site and in their preferred language will produce the best possible results," Menscher wrote. "While we expect to notify over 500,000 users within a week, we realize we won't reach every affected user. Some ISPs have been taking their own actions, a few of which will prevent our warning from being displayed on affected devices. We also can't guarantee that our recommendation will always clean infected devices completely, so some users may need to seek additional help."

  DHS, in the blog post, recommended that users visit the DNSChanger Working Group website to test their computers for infection and to receive instructions on removing the trojan.

(责任编辑:)

分享到:

更多
发表评论
请自觉遵守互联网相关的政策法规,严禁发布色情、暴力、反动的言论。
评价:
表情:
  • 微笑/wx
  • 撇嘴/pz
  • 抓狂/zk
  • 流汗/lh
  • 大兵/db
  • 奋斗/fd
  • 疑问/yw
  • 晕/y
  • 偷笑/wx
  • 可爱/ka
  • 傲慢/am
  • 惊恐/jk
用户名: 验证码:点击我更换图片
资料下载专区
图文资讯

英国官员:让华为参与英国5G建设风险可控

英国官员:让华为参与英国5G建设风险可控

2月21日,英国金融时报报道称,在布鲁塞尔发表的一次演讲中,英国信号情报机构政府通...[详细]

西媒:以色列打造网络安全“硅谷”

西媒:以色列打造网络安全“硅谷”

2月13日报道 西媒称,凭借每年超过10亿美元的企业投资,以色列已经成为全球网络安全领...[详细]

俄罗斯力推脱离互联网计划 确保应急状态下

俄罗斯力推脱离互联网计划 确保应急状态下网络安全

俄罗斯新闻机构 RosBiznesKonsalting(RBK)上周报道称:作为计划实验的一部分,当局正...[详细]

GSMA呼吁欧洲守住网络安全和网络基建供应竞

GSMA呼吁欧洲守住网络安全和网络基建供应竞争力

5G将改变欧洲公民的生活和工作方式。5G作为现有4G网络的补充,与之协同工作将比以往更...[详细]

涉嫌窃取近千政界人士信息 德国20岁黑客遭

涉嫌窃取近千政界人士信息 德国20岁黑客遭逮捕

涉嫌窃取德国近千政界人士信息的黑客落网 政府拟修法加强网络安全 德国当局8日宣布,...[详细]

返回首页 返回顶部