Ghost in the Machine

used by permission from flattop341 Flickr photostream


 

Trend Micro and the FBI are very pleased to announce today the dismantling of a criminal botnet, in what is the biggest cybercriminal takedown in history.
 
This concerted action against an entrenched criminal gang is highly significant and represents the biggest cybercriminal takedown in history. Six people have been arrested through multinational law enforcement cooperation based on solid intelligence supplied by Trend Micro and other industry partners. more than 4 million victims in over 100 countries have been rescued from the malign influence of this botnet and an infrastructure of over 100 criminal servers has been dismantled with minimal disruption to the innocent victims.
 
If you are worried that you might have been a victim of this criminal activity, the FBI have made an online tool available which will allow you to check if your DNS server settings have been tampered with.
 
First you will need to discover what your current DNS server settings are:
 
On a PC, open the Start menu by clicking the Start button or the Windows icon in the lower left of your screen, in the  Search box type “cmd” and hit return (for Windows 95 users, select “Start“, then “Run“).This should open a black window with white text. In this window type “ipconfig /all” and hit return. Look for the entry that reads “DNS Servers” and note down the numeric addresses that are listed there.
 
On a Mac (yes they can be victims too), click on the Apple icon in the top left of your screen and select “System Preferences“, from the Preferences panel select the “Network” icon. Once this window opens, select the currently active network connection on the left column and over on the right select the DNS tab. note down the addresses of the DNS servers that your computer is configured to use.
 
You can check to see if these addresses correspond to servers used by the criminals behind Operation Ghost Click by using this online tool provided by the FBI, simply enter the IP addreses, one by one and click the “check ip” button.
 
If you feel that you computer may have been infected, you can visit Trend Micro’s HouseCall for a free scan and clean-up and notify the FBI by submitting this form. You should also contact your Internet Service Provider for advice on restoring your legitimate DNS settings.
 
Ongoing updates on this threat can be found on our Operation Ghost Click landing page.
 

Related posts:

  1. Malvertising, who’s responsible?
  2. Google, China, Chicken Little and Cyber Armageddon.
  3. 70 million customers affected by the Sony breach
  4. Sony (not) hacked
  5. Over 10,000 Facebook account details hacked and published

This entry was posted on Wednesday, 9. November 2011 and is filed under "Bad guys always lose, countermeasures, data protection, Family Safety, Mac OS, malware, Underground Economy, vulnerability". You can follow any responses to this entry with RSS 2.0. You can leave a response here, or send a trackback from your own site.

30 Comments to "How to check if you are a victim of Ghost Click"

Esthost taken down – Biggest cybercriminal takedown in history:
Thursday, 10. November 2011 um 12:44 am

[...] more information, Rik Ferguson posted an entry on his CounterMeasures blog on ways to check if you’re a victim of the “Operation Ghost Click” criminal [...]

Cómo saber si nuestro ordenador ha sido víctima de la operación Ghost Click:
Thursday, 10. November 2011 um 4:00 am

[...] trata de la operación Ghost Click, detallada en trendmicro.eu, donde nos dan instrucciones para saber si nuestro ordenador es una de las víctimas de la [...]

FBI cracks longest botnet scheme in history, affecting over 4 million people « Go Digital Apps:
Thursday, 10. November 2011 um 4:56 am

[...] attack, Trend Micro and the FBI have released a way to check if you’ve been affected. You can find it here, below are instructions for Mac [...]

FBI Shuts Down International Cybercriminal Operation That Made 4 Million Victims | Matias Vangsnes:
Thursday, 10. November 2011 um 10:25 am

[...] from fraud and theft,” said NASA Inspector General Paul Martin. Security solutions provider Trend Micro played an important role in the apprehension of the suspects and now, after the whole thing went [...]

FBI shuts down ‘Ghost Click’ botnet - Technology Magazine:
Thursday, 10. November 2011 um 1:59 pm

[...] Rik Ferguson of Trend Micro has a guide to help people find out if their PC was part of the Ghost Click botnet. Both Windows PCs and Apple Macintosh machines can be affected. Trend Micro offers a free scan, [...]

‘Massive’ web crime ring smashed | www.euronewsweek.com:
Thursday, 10. November 2011 um 3:17 pm

[...] FBI has produced a software tool that people can download and run to see if they had been hit by the gang and were being re-directed. The gang reportedly tricked [...]

David Wanner:
Thursday, 10. November 2011 um 3:44 pm

Please check your instructions for Windows. Pressing “Start” then “Search” does not open a black box (DOS) but pressing “Start” then “Run” does.
Imprecise instructions cause a lot of frustration for people that are unfamiliar with computers.

Rik Ferguson:
Thursday, 10. November 2011 um 3:49 pm

Hi David, my instructions for Windows PCs are based on Windows Vista or Windows 7. If you type “cmd” into the search box and hit return you will end up with a command prompt window. I deliberately chose not to advise people to select the “Run” option because this menu item is hidden in a default installation, so I would have had to include instructions on how to enable it.

Thanks for reading,
Rik

DNS Changer botnet smashed in major cyber crime bust | Matias Vangsnes:
Thursday, 10. November 2011 um 4:25 pm

[...] efforts.”Whilst the rogue DNS servers have been replaced, many may still be infected. Head here to learn about how to check if your system is part of the DNS Changer botnet.Email to a friendPrint this pageArticle source: [...]

‘Massive’ web crime ring smashed | Backtogeek's Technology Journey:
Thursday, 10. November 2011 um 6:57 pm

[...] FBI has produced a software tool that people can download and run to see if they had been hit by the gang and were being re-directed. The gang reportedly tricked [...]

‘Massive’ web crime ring smashed | TAWNET:
Thursday, 10. November 2011 um 7:03 pm

[...] FBI has produced a software tool that people can download and run to see if they had been hit by the gang and were being re-directed. The gang reportedly tricked [...]

Operation Ghost Click by FBI – Online advertising scam taken Down « artupas.com | Full Nulled Script | Hacker News | Indonesian News:
Thursday, 10. November 2011 um 8:13 pm

[...] Here's some screenshots from the FBI's "Check to See if Your Computer is Using Rogue DNS" instructions. Trend Micro, which helped supply information to the FBI on DNS Changer, hailed the law enforcement operation as the "biggest cyber criminal takedown in history." Whilst the rogue DNS servers have been replaced, many may still be infected. Head here to learn about how to check if your system is part of the DNS Changer botnet. [...]

‘Massive’ web crime ring smashed « RSS Feeds:
Thursday, 10. November 2011 um 9:03 pm

[...] FBI has produced a software tool that people can download and run to see if they had been hit by the gang and were being re-directed. The gang reportedly tricked [...]

‘Massive’ web crime ring smashed | NewsGlobal TV:
Thursday, 10. November 2011 um 9:14 pm

[...] FBI has produced a software tool that people can download and run to see if they had been hit by the gang and were being re-directed. The gang reportedly tricked [...]

Operation Ghost Click, the Biggest Cyber-Bust Ever, Shuts Down Estonian Bot Ring – Finding Out About:
Thursday, 10. November 2011 um 10:25 pm

[...] That was two years ago. As of today, six Estonians are in custody and facing decades in prison under U.S. indictments. One Russian suspect is still at large. U.S. security firm Trend Micro provided some intel to the FBI for Operation Ghost Click, and if you suspect DNSChanger might have infected your system the company has posted tips on diagnosing and eradicating it here. [...]

Operation Ghost Click by FBI – Online advertising scam taken Down /  Hackersplay.com:
Thursday, 10. November 2011 um 10:42 pm

[...] Operation Ghost Click by FBI – Online advertising scam taken Down Operation Ghost Click by FBI – Online advertising scam taken Down A gang of internet ‘cyber bandits’ who stole $14 million after hacking into at least 4 million computers in an online advertising scam have been arrested following a joint investigation by the FBI and Nasa. Six men are in custody in Estonia, pending extradition to the United States, following a two-year investigation into an “intricate international conspiracy” that “hijacked” millions of computers around the world and stole more than US$14-million. The FBI’s two-year investigation was dubbed “Operation Ghost Click”. Computers in more than 100 countries were infected by the “DNSChanger” malware, which redirected searches for Apple’s iTunes store to fake pages pretending to offer Apple software for sale, as well as sending those searching for information on the U.S. Internal Revenue Service to accounting company H&R Block, which allegedly paid those behind the scam a fee for each visitor via a fake internet ad agency. “These defendants gave new meaning to the term ‘false advertising’,” said Manhattan US Attorney Preet Bharara. “As alleged, they were international cyber bandits who hijacked millions of computers at will and re-routed them to websites and advertisements of their own choosing, collecting millions in undeserved commissions for all the hijacked computer clicks and internet ads they fraudulently engineered.“ Here’s some screenshots from the FBI’s “Check to See if Your Computer is Using Rogue DNS“ instructions. Trend Micro, which helped supply information to the FBI on DNS Changer, hailed the law enforcement operation as the “biggest cyber criminal takedown in history.” Whilst the rogue DNS servers have been replaced, many may still be infected. Head here to learn about how to check if your system is part of the DNS Changer botnet. [...]

Weltweit operierendes Botnetz in Estland lahmgelegt - datensicherheit.de Informationen zu Datenschutz und Datensicherheit:
Thursday, 10. November 2011 um 11:30 pm

[...] TREND MICRO, CounterMeasures, 09.11.2011 How to check if you are a victim of Operation Ghost Click / Article from Rik Ferguson [...]

Brunei News Channel - bruvoice:
Friday, 11. November 2011 um 3:00 am

[...] That was two years ago. As of today, six Estonians are in custody and facing decades in prison under U.S. indictments. One Russian suspect is still at large. U.S. security firm Trend Micro provided some intel to the FBI for Operation Ghost Click, and if you suspect DNSChanger might have infected your system the company has posted tips on diagnosing and eradicating it here [...]

‘Massive’ web crime ring smashed | Best Web Consulting company in Nashik, India with Creative and Professional Website Design, Content Management Systems, Wordpress Experts, Ecommerce SEO, and more..:
Friday, 11. November 2011 um 3:10 am

[...] FBI has produced a software tool that people can download and run to see if they had been hit by the gang and were being re-directed. The gang reportedly tricked [...]

趨勢科技協助 FBI 破獲史上最大的網路犯罪始末 | 雲端防毒是趨勢:
Friday, 11. November 2011 um 3:43 am

[...] Ferguson在他的CounterMeasures部落格介紹了如何檢查自己是否是「Operation Ghost [...]

Blog Nusantara Haxor » Blog Archive » Operasi Ghost Click oleh FBI – Penipuan Iklan Online Diambil Tindakan:
Friday, 11. November 2011 um 5:01 am

[...] di sini untuk belajar tentang bagaimana untuk memeriksa apakah sistem anda adalah bagian dari DNS Changer Botnet. Written on November 11, 2011 by [...]

FBI cracks longest botnet scheme in history, affecting over 4 million people | Tech News Aggregator:
Friday, 11. November 2011 um 5:44 am

[...] attack, Trend Micro and the FBI have released a way to check if you’ve been affected. You can find it here, below are instructions for Mac [...]

On Operation Ghost Click and Esthost Takedown | menardconnect.com:
Saturday, 12. November 2011 um 9:09 am

[...] How to check if you are a victim of Operation Ghost Click by Rik Ferguson [...]

Exploit-ID – Exploit Information Disclosure » Operation Ghost Click by FBI – Online advertising scam taken Down:
Saturday, 12. November 2011 um 7:47 pm

[...] rogue DNS servers have been replaced, many may still be infected. Head here to learn about how to check if your system is part of the DNS Changer botnet. Posted By [...]

Exorcise Ghost Click from Your PC | Got2.Me:
Monday, 14. November 2011 um 12:14 am

[...] activities of Rove and its assorted subsidiaries for more than five years, offers some tips in its CounterMeasures [...]

Exorcise Ghost Click from Your PC | Tech Dott - Daily Technology News Magazine:
Monday, 14. November 2011 um 12:17 am

[...] activities of Rove and its assorted subsidiaries for more than five years, offers some tips in its CounterMeasures [...]

如何檢查自己是否為Operation Ghost Click 的受害者 | 雲端防毒是趨勢:
Monday, 14. November 2011 um 5:59 am

[...] @原文出處:How to check if you are a victim of Operation Ghost Click 作者:Rik Ferguson [...]

밝혀진 거대 봇넷의 정체 – 사상 최대 규모의 사이버범죄를 적발 | Botnet:
Wednesday, 16. November 2011 um 7:48 am

[...] 영문 블로그 ‘CounterMeasures’에서는 ‘Operation Ghost Click’의 수사에서 조사된 이번 사례의 피해에 대한 [...]

Esthost Taken Down – Biggest Cybercriminal Takedown in History | ScamFeed.com:
Tuesday, 22. November 2011 um 11:39 pm

[...] more information, Rik Ferguson posted an entry on his CounterMeasures blog on ways to check if you’re a victim of the “Operation Ghost Click” criminal [...]


Name:

E-Mail (not published)

Website:


Spam protection


© Copyright 2010 Trend Micro Inc. All rights reserved.
Legal Notice | Disclaimer