Chaos Cluster

News => Announcements & Such => Topic started by: Trerro on July 06, 2012, 11:04:48 pm

Title: Major virus spreading - check here if you're clean
Post by: Trerro on July 06, 2012, 11:04:48 pm
We don't normally bother with this sort of announcement, but this virus especially blows, as it makes you use a false DNS server. For those who don't know what that means, it means sites can be redirected to basically anything, and they can block you from loading pretty much anything they want to, as well as doing things like making you log into a false copy of your bank's site to steal your login. We won't be able to help anyone *after* they get hit (this site likely won't load), but we can help you *before* you do, hence the announcement.

Please go here, and click the link to check for infection:
http://www.dcwg.org/

If you're green, you're fine. If you're not, please follow the removal instructions ASAP while you can still download things from the internet. If all else fails and you don't know how to fix DNS stuff, you can always reformat, but that's a royal pain in the tail, and you can fix an infection in 2 minutes via that site IF you do it ASAP. Please do.
Title: Re: Major virus spreading - check here if you're clean
Post by: Bullseye55 on July 07, 2012, 03:48:51 am
This is the Google Redirect Virus, as its Common Name is.

I've gotten it from personal experience. My old computer received it.


Most normal virus detectors do NOT find this virus, nor can they remove it.

Their are a few specialized tools to remove it though.
Title: Re: Major virus spreading - check here if you're clean
Post by: Trerro on July 07, 2012, 09:18:17 pm
A virus scanner can detect the virus as it tries to install, but cannot fix it if it's already there (as it disables checkers)... so it comes down to a question of whether the virus hit first, or the virus scanner updated itself in time. It's definitely not reliable.

As for tools, those are also on the site I linked, as well as a full guide to make absolutely sure you've purged all versions of this thing.