Tuesday, 7 February 2012

How to Remove DNS Changer (Uninstall Guide)

If you haven't already, we recommend that you take a few minutes to determine if your computer has been affected by the DNS Changer virus. There are still nearly half a million computers infected by this malicious software or at least using the Rove Digital domain name servers in Europe and the U.S. This DNS infrastructure was formerly used by botnet czars to redirect unsuspecting victims to infected websites, alter user searches, replace ads, block legit anti-virus software and promote fake security products. Cyber crooks earned millions of dollars display false advertisements and redirecting users to wrong websites.

The FBI arrested six Estonians who ran the botnet that infected millions of computers worldwide and took over the control of rogue DNS servers. They now produce correct DNS answers but only until March 8th, 2012 Update: DNS servers will be shut down on Monday, July 9. That's official. The FBI will discontinue to provide this service. Then what? Infected computers will not longer be able to look up names using those name servers. In other words, users who are still affected by this DNS Changer malware won't find anything on the internet. If that had happened, Internet Explorer for example, would say something like "Internet Explorer cannot display the webpage", "No such server", etc.



While there's a slight chance that the FBI will continue to provide this service, I don't think that keeping your computer infected is a good idea. Not only DNS Changer virus causes a computer to use rogue DNS servers, it also disables security updates and blocks anti-virus software/websites. It can also change the DNS settings within small (home) office routers. As you can see, it's rather sophisticated piece of malicious code that very often comes with additional payloads (Trojan.DNSChanger, Trojan.Fakealert, Trojan.Generic). It is thus very important to remove DNS Changer virus. And it isn't only the job of FBI and PC repair technicians. You have to take responsibility for your own security as well. Good luck and be safe online!


So, are you infected?

1. You can check your DNS settings by simply visiting one of the following websites:
RED = your computer is using the DNS Changer rogue name servers and is therefore probably infected.


GREEN = your computer appears to be looking up IP addresses correctly.



2. Visit FBI's website and enter your IP address: https://forms.fbi.gov/check-to-see-if-your-computer-is-using-rogue-DNS

If your computer is infected, you'll see the following notification.



3. Check your DNS settings manually. If your computers' DNS settings use the follow ranges, then you likely have been affected by the DNS Changer virus.

Between this IP...
... and this IP
77.67.83.1 77.67.83.254
85.255.112.1 85.255.127.254
67.210.0.1 67.210.15.254
93.188.160.1 93.188.167.254
213.109.64.1 213.109.79.254
64.28.176.1 64.28.191.254

Here's a very helpful document that explains how to check your DNS settings to see whether you are using bad DNS servers. Please see DNS-changer-malware.pdf

4. Check your router. Compare the DNS servers listed to those in the rogue DNS servers table above. If your router is configured to use one or more of the rogue DNS servers, your computer may be infected with DNSChanger malware. Please reset your router to default factory settings and change passwords.


How to restore DNS settings to default?

Changing DNS server settings on Microsoft Windows XP:

1. Go to Control PanelNetwork Connections and select your local network.
2. Right-click Properties, then select Internet Protocol (TCP/IP).
3. Right-click and select Properties.
4. Click Properties. You should now see a window like the one below.



5. Select Obtain DNS server address automatically and click OK to save the changes.

Changing DNS server settings on Microsoft Windows 7:

1. Go to Control Panel.
2. Click Network and Internet, then Network and Sharing Center, and click Change adapter settings.
3. Right-click Local Area Connection, and click Properties.
4. Select the Networking tab. Select Internet Protocol Version 4 (TCP/IPv4) or Internet Protocol Version 6 (TCP/IPv6) and then click Properties.
5. Click Advanced and select the DNS tab. Select Obtain DNS server address automatically and click OK to save the changes.


How to remove DNS Changer malware?

1. Download and run TDSSKiller. Press the button Start scan for the utility to start scanning.

2. Wait for scanning to finish. Select Cure and click Continue to cure found threat.



3. A reboot might require after disinfection. Click Reboot computer.



4. Download recommended anti-malware software (direct download) and run a full system scan to remove DNS Changer malware from your computer.

That's it! If you have any questions or need extra help removing DNSChanger virus, please leave a comment below.

Tell your friends:

Sunday, 5 February 2012

AV Security Essentials (Uninstall Guide)

Here's another anti-spyware program that we've added to the list of scareware, called AV Security Essentials. As you see in the image below, it impersonates legit anti-virus software from Microsoft. The rogue anti-spyware program states that your computer has been infected with Trojans, keyloggers, spyware and other malware. It then asks you to give your credit card details to upgrade AV Security Essentials in order to remove non-existent viruses. The rogueware also displays greatly exaggerated security alerts and pop-ups stating your PC is in great danger.





Since it's not a new virus, but a slightly modified and re-brander variant of previous scareware, I won't go into details this time. You can read more detailed analysis of this scareware here and here. Just don't purchase it and do not follow the on-screen instructions. AV Security Essentials cannot delete your files or gather and then send personally identifiable information to remote servers. Don't worry about that. To remove AV Security Essentials and associated malicious software from your computer, please follow the quick removal guide below. It does not get any simpler than this. You can follow the manual removal guide too, if the removal guide below is not acceptable. If you have any questions or need extra help removing this malware from your computer, please leave a comment bellow. Good luck and be safe online!


Quick AV Security Essentials removal guide:

1. Click the "Click here if you already have an Activation" button and register the rogue program using any of these debugged registration keys:

U2FD-S2LA-H4KA-UEPB
K7LY-H4KA-SI9D-U2FD
K7LY-R5GU-SI9D-EVFB

Entering debugged reg key makes the removal procedure a lot easier. You can then download recommend anti-malware program to remove AV Security Essentials from your computer.

2. Download recommended anti-malware software (Spyware Doctor) and run a full system scan to remove this malware from your computer.

3. To reset the Hosts file back to the default automatically, download and run Fix it and follow the steps in the Fix it wizard.


Associated AV Security Essentials files and registry values:

Files:
  • %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS]\
  • %AppData%\AV Security Essentials\
  • %AppData%\Microsoft\Internet Explorer\Quick Launch\AV Security Essentials.lnk
  • %UserProfile%\Desktop\AV Security Essentials
  • %UserProfile%\Start Menu\AV Security Essentials
  • %UserProfile%\Start Menu\Programs\AV Security Essentials.lnk
Registry values:
  • HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run\AV Security Essentials = "%AllUsersProfile%\Application Data\78b634\AV83d_9025.exe" /s /d
  • HKEY_CURRENT_USER\software\3
  • HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\[RANDOM].exe\Debugger = svchost.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun = 01000000
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\[1...15]
Tell your friends:

Thursday, 2 February 2012

Avira Giveaways And Deals

Avira AntiVir Premium 2012 - 1 Years license $18.86

You may however choose a 3 years license for just $38.19. For every online purchase, Avira allocates 5 Euro to the Auerbach Foundation. Key components: system scanner, anti-phishing, antiAd/spyware and anti-rootkit.

For more details, please visit https://avira.cleverbridge.com/30/purl-xmas_prem_30off?x-origin=web&x-web=webEN&x-campaigns=xmas&x-xmas=s_freeEN

Bitdefender Giveaways And Deals

BitDefender Lifetime License. Save up to 70% a year.

Get this BitDefender PC lifetime edition and safe. One time payment, no renewals. You can choose either Internet Security 2012 or Antivirus Plus 2012. Both products are great providing PC users with antivirus, anti-spyware and anti-spam protection. Internet Security 2012 includes parental controls and and social network protection.

For more details, please visit http://www.bitdefender.com/2012/lifetime-affn/

Ad-Aware Giveaways And Deals

40% Off Ad-Aware Total Security

All-in-one security solutions for home users. Core features include complete malware protection, anti-rootkit engine, anti-phishing, parental controls and online back up and many more.

For more details, please visit http://go.lavasoft.com/totalsecurity/EN/join.asp?mkey1=newsJuneEN

ZoneAlarm Giveaways And Deals

Up to 50% Off ZoneAlarm 2012 Security Suites

ZoneAlarm Antivirus + Firewall
ZoneAlarm Internet Security Suite
ZoneAlarm Extreme Security

This is a great opportunity to get award winning PC security for half price.

For more details, please visit http://www.zonealarm.com/security/en-us/cdn/2012/display/2012_hp.htm

Wednesday, 1 February 2012

All-Around Digital Security: Bitdefender Sphere for PC& Mac

Desktops, laptops plus smartphones or tablets. The picture-perfect digital environment of a modern home that relies on a variety of devices to connect to the world via the Internet. Speaking of variety, nowadays it's not uncommon to come across PCs and Macs within the same family, a reality that reflects the increasing need to accommodate different tastes and usage habits of Mom, Dad, kids and... well, everybody else. This unity in diversity principle calls for a revisited idea of data security, one that enables families to secure their heterogeneous digital fleet from an array of e-threats.



Sounds a lot like learning to juggle, doesn't it? Not if you've got the right tools on hand. Relying on the #1 ranked protection technology from Bitdefender Antivirus, the new Sphere suite safeguards your privacy and counters e-threats on any combination of Internet connected PCs, Macs and Android-based devices. That's signing up for superior performance and no slowdowns so you can shop, bank, play and work securely wherever you are.

So, what's in it for your PC? Bitdefender Total Security 2012's award-winning protection against malware, loss of personal files and identity theft, with the extra benefits of online backup and parental control. Just enable the Autopilot mode and Bitdefender will make the best security-related decisions without any input from you: no pop-ups, no alerts, nothing to configure. The Bitdefender Safebox component will monitor your important files and instantly back them up to a secure remote server whenever a change is detected.

How about your Mac? Bitdefender Antivirus for Macs steps in to fight off the newest breed of Mac viruses, while also destroying Windows viruses that might unknowingly be passed on to family, friends, and colleagues who use Windows PCs. The no-hassle rule applies here as well. Unlike other antivirus software, Bitdefender keeps memory usage and system impact to a minimum. It'll also adjust its scanning routine to your schedule and get busy when your Mac is not in use.

Your Android-based smart phone or tablet will love Bitdefender Mobile Security's cloud-based threat detection that keeps you away from webpages containing malware, phishing or fraudulent content. Your Android device will stay clean, as Bitdefender will automatically scan any application immediately after it's installed. You will also be able to keep track of each application's permissions and Internet or sensitive data access requirements. Let's not forget that Bitdefender Mobile Security will keep an eye on the apps that might use billable device functions such as making phone calls or sending text messages. To top it off, you've got remote tracking and control features in case your device gets stolen or lost.

An end of year, a Juniper Global Threat Center report pointed out a "472% increase in Android malware samples since July 2011," painting a grim picture for online socialites. No reason to worry for you, as Bitdefender Sphere will block e-threats on Twitter and Facebook, without negatively impacting your mobile devices' battery life. Get your front row tickets to the digital show. Bitdefender Sphere's got you covered.

Tell your friends: