As we have reached today’s FBI deadline to prevent a complete loss of internet connection due to the DNS changer malware virus, millions of internet users over the weekend have flocked to an FBI approved web site to check their computer for the Malware virus and remove it from their computer if infected.
As we mentioned in our article yesterday, today, the FBI will be shutting down some domain name servers (DNS) which had served as a safety net for some 277,000 internet users infected with a Malware virus. As a result any computers still infected with the “DNS Changer” malware virus will be unable to connect to the internet. To help, the FBI has provided a link to an approved web site which can identify an infected computer and show you how to remove the virus.
Below is a recap on the Malware situation and what you can do to scan your computer to check for an infection and how to remove it is you are infected.
What is the DNS Changer Malware Virus and how does it work?
To understand how the virus works, you must first understand how a computer connects to the internet. Every web site on the internet resides on another computer, referred to as a web server. Each web server has a unique numerical address, called an IP address, on the internet that looks something like this 198.255.255.0. Instead of having to type a number like that into your web browser every time to wanted to go to a web site, there is an intermediate step.
Around the world there are a number of computers called DNS (domain name servers). Each server has a master list of domain names (like Amazon.com for example), and the corresponding IP address. All of the DNS machines talk to each other to keep the list updated. When someone types a web address into their web browser, that request is sent to a nearby DNS server which then matches the request to the appropriate IP address and forwards the user to the correct web site.
The DNS Changer Malware sent every internet request from the infected computers through the DNS server of the malicious criminal hackers, who were arrested by a joint international team including the FBI last November. The DNS server of the hackers routed computers through a number of fraudulent pay-per-click advertising schemes defrauding advertisers out of millions of dollars.
If the FBI had shut down the servers over half a million infected internet users would have lost connection. Instead the agency continued to manage the servers, now routing traffic correctly, as a temporary safety net until the infected computer owners could be notified and the virus removed. On Monday however the FBI is shutting down the servers. Infected computers will still try to connect through these servers and therefore will not be able to connect to the internet.
How to check your computer and remove the DNS changer malware virus
To find out if your computer is infected by the malware virus, the FBI recommends a free web site which checks your computer by seeing if your connection currently goes through the DNS servers used by the hackers. If not, it will tell you that your computer is OK. If instead your connection is going through one of the servers now controlled by the FBI, it means that you have the malware on your computer, and the site tells you how to remove the malware from your computer as well. The web site for the malware check and removal in the U.S. is: http://www.dns-ok.us/.