About a quarter-million computer users around the world are at risk of losing Internet access today (Monday 9 July 2012) because of malicious software at the heart of a hacking scam that U.S. authorities shut down last November.
Some blogs and news reports hyped the risk of an outage, warning of a potential “blackout” and describing the Alureon malware as the “Internet Doomsday” virus.
Yet experts said only a tiny fraction of computer users were at risk, and Internet providers would be on call to quickly restore service. They said they considered the threat to be small compared with more-prevalent viruses such as Zeus and SpyEye, which infect millions of PCs and are used to commit financial fraud.
As of this week, about 245,000 computers worldwide were still infected by Alureon and its brethren, according to security firm Deteque.
The viruses were designed to redirect Internet traffic through rogue DNS servers controlled by criminals, according to the FBI. DNS servers are computer switchboards that direct Web traffic.
When authorities took down the rogue servers, a federal judge in New York ordered that temporary servers be kept in place while the victims’ machines were repaired. The temporary servers will shut down at 12:01 a.m. EDT (0401 GMT) on Monday, which means the infected PCs that have not been fixed will no longer be able to connect to the Internet.
Information on how to identify and clean up infections can be found on a website that a group of security firms and other experts set up: http://www.dcwg.org.
“It’s a very easy one to fix,” said Gunter Ollmann, vice president of research for security company Damballa. “There are plenty of tools available.”
Many of the machines that remain infected are probably not in active use since most victims were notified of the problem, said security expert Johannes Ullrich, who runs the Internet Storm Center, which monitors Web threats.
Here are some free tools to check whether you are at risk:
- Malware check: http://dns-ok.us/
- FBI: https://forms.fbi.gov/check-to-see-if-your-computer-is-using-rogue-DNS
- DNS Changer Working Group: http://www.dcwg.org/
- Facebook: http://www.facebook.com/notes/facebook-security/notifying-dnschanger-victims/10150833689760766
- McAfee: http://www.mcafee.com/dnscheck
Related articles
Flame virus can sabotage computers: Symantec
Beware free public Wi-Fi: Kaspersky
Megaupload shutdown was Joe Biden’s idea

























Join the conversation