FBI internet virus screen shutting down?

juniper

Always curious.
Requiescat In Pace
Registered
Joined
Mar 1, 2010
Messages
4,129
Reaction score
678
Location
Forever on the island
Well, this is the first I've heard of an FBI internet virus screen that's apparently been protecting some folks from some virus. And now the screen is being shut down and so some folks won't be able to access the internet after July 9.

Yeah, I know that's vague, but that's all I got on it. Here's the link to a local tv station article:

http://www.kgw.com/news/local/Many-may-lose-Internet-in-July-when-FBI-shuts-down-virus-screen-148307275.html

So, legit to click on that FBI link to check to see if I'm infected? And I'm on a Mac, did that virus affect Macs too? Or maybe just my husband's PC?
 

BunnyMaz

Ruining your porn since 1984
Super Member
Registered
Joined
Feb 14, 2011
Messages
2,295
Reaction score
412
Age
42
My first instinct is that this is a blatant scam. Why would the FBI a- run a virus screen and b- direct people to a non-affiliated website that "checks" whether or not you're infected with a "virus" that will prevent you from accessing the internet? And how would their virus screen shutting down mean you'll lose the internet? Also, I can't find a single other website referring to this. You'd think if this was real, the FBI would issue an announcement to more places than one random, unknown website. Maybe they'd notify actual news stations, you know?
 

PeteDutcher

Twitter: @petedutcherjr
Super Member
Registered
Joined
Apr 19, 2011
Messages
498
Reaction score
19
Location
Bradenton, FL, USA
Website
www.facebook.com
I don't know anything about it, but it would be simple to do a Google search and find out if it's a scam...there are a couple websites that expose internet scams.
 

BunnyMaz

Ruining your porn since 1984
Super Member
Registered
Joined
Feb 14, 2011
Messages
2,295
Reaction score
412
Age
42
That article is posted by one of the local tv station websites in Portland, Oregon. That's what made me curious as to its legitimacy.

Mmm, but if you google, you'll notice it's the only result that turns up about the same thing. Everything else is about unrelated virus scams. Also, if this was real, you'd expect national news stations, not local ones, to be informed.
 

benbradley

It's a doggy dog world
Super Member
Registered
Joined
Dec 5, 2006
Messages
20,321
Reaction score
3,513
Location
Transcending Canines
It's called DNS changer, and it's a real threat.

ETA: The site in the Associated Press and other news stories is a legit site for detecting and removing it:

http://www.dcwg.org

And yes, it can affect Macs too.
 
Last edited:

FalconMage

Rob J. Vargas
Sockpuppet
Banned
Joined
Apr 18, 2012
Messages
218
Reaction score
17
Location
Midwest, USA
Based on the FBI information that juniper posted, this isn't a screen, per se.

FBI said:
The FBI has uncovered a network of rogue DNS servers and has taken steps to disable it. The FBI is also undertaking an effort to identify and notify victims who have been impacted by the DNSChanger malware. One consequence of disabling the rogue DNS network is that victims who rely on the rogue DNS network for DNS service could lose access to DNS services. To address this, the FBI has worked with private sector technical experts to develop a plan for a private-sector, non-government entity to operate and maintain clean DNS servers for the infected victims. The FBI has also provided information to ISPs that can be used to redirect their users from the rogue DNS servers to the ISPs’ own legitimate servers. The FBI will support the operation of the clean DNS servers for four months, allowing time for users, businesses, and other entities to identify and fix infected computers. At no time will the FBI have access to any data concerning the Internet activity of the victims.

Basically, they worked with ISP's and others to step in on these rogue DNS servers, to take them down, and then to try to help not disable Internet for infected machines. It was always intended as a temporary measure. At least, that's how I read it. Something to give infected folks a chance to recover before those DNS settings stop working.

This is a big issue. DNS is a protocol that (basically) trusts itself. There's no backup that checks to confirm that the results are valid. There are some initiatives out there to try to "harden" DNS against attacks like this and other "poisoning" attacks.
 

benbradley

It's a doggy dog world
Super Member
Registered
Joined
Dec 5, 2006
Messages
20,321
Reaction score
3,513
Location
Transcending Canines
Infected computers will lose Internet access this MONDAY!

http://www.wsbradio.com/news/ap/general/malware-may-knock-thousands-off-internet-on-monday/nPmpH/

WASHINGTON —
The warnings about the Internet problem have been splashed across Facebook and Google. Internet service providers have sent notices, and the FBI set up a special website.
But tens of thousands of Americans may still lose their Internet service Monday unless they do a quick check of their computers for malware that could have taken over their machines more than a year ago.
Despite repeated alerts, the number of computers that probably are infected is more than 277,000 worldwide, down from about 360,000 in April. Of those still infected, the FBI believes that about 64,000 are in the United States.
Users whose computers are still infected Monday will lose their ability to go online, and they will have to call their service providers for help deleting the malware and reconnecting to the Internet.


...
To check whether a computer is infected, users can visit a website run by the group brought in by the FBI: http://www.dcwg.org .
 

The_Riskbreaker

knows bears make everything worse
Super Member
Registered
Joined
Jun 7, 2012
Messages
123
Reaction score
3
Location
Union Aerospace Corporation Sewage Plant
benbradley is right. I work in the IT field, and the DNS Changer is a real issue. I see articles about it every day. And a lot of people don't know they have it because not every piece of AV ware out there can detect it. Funny thing is, I thought it was 500,000 that were going to lose access. Maybe it's an estimate.

I run Linux and I checked my system, just to be certain. Mainly because this isn't a traditional virus. It's modifying DNS settings and such. I don't think any OS is safe. Not even DOS or OS/2
 

kenebaker

Master of Meh!
Super Member
Registered
Joined
Jun 15, 2012
Messages
371
Reaction score
14
Website
www.kenebaker.com
Here is an article about the DNS changer, what it is, what it means for you, and how to sort it out. It is definitely not a scam, although I am sure there are scam sites out there that are trying to get on the bandwagon.

Check out this article and read through the instructions. http://www.makeuseof.com/tag/fbi-dns-changer-shutdown-break-internet/

It's pretty self-explanatory, and also gives you genuine links to check if you have this issue or not.