Most of these attacks are similar to another, however they have additional features that are not available in the other similar variants. For example, DNSChanger modified the DNS settings on a infected computer. At this time, the most documented variant is DNSChanger. In this case, the attacker can make the target computer believe it is connecting to the desired website, but the desired information is changed so that it points to a malicious website. The DNSChanger variant is the most dangerous as far as security is concerned. This is because it can be used to affect the address displayed in a browser. This can allow the attacker to trick the user into visiting a malicious website that then can install malware. The DNSChanger variant targets the Windows operating system. However, it is also possible that it will run on Unix or Linux operating systems. Figure 13.11 shows a sample DNSChanger attack. 13.11 Uninstall DNSChanger through Windows If you want to remove the DNSChanger variant, you must uninstall the malicious application that is installed on your computer. Close any browsers that are currently running. Complete the following steps to uninstall the malicious application and to set your computer's DNS settings to original settings: 1. Click Control Panel in the Start menu. Figure 13.11. Description: DNSChanger 2. Click System and Maintenance. 3. Click Add or Remove Programs. 4. Select both DNS Changer and the check box next to Remove. 5. Click OK. This will remove the DNSChanger variant. 6. Click OK to restart your computer. This will change the DNS settings back to their original settings. 13.10 Uninstall DNSChanger through Internet Connection Setup DNSChanger installed through Internet Connection Setup is the simplest variant of DNSChanger. When installing the program, Internet Connection Setup will detect and install a malicious application. If the malicious application is detected and you have not yet fixed the DNS settings, it will also install DNSChanger. However, in this case, DNSChanger will not run automatically when you start your computer. You must manually start it. Complete the following steps to remove Internet Connection Setup and change your DNS settings: 1. Click Control Panel in the Start menu. Figure 13.12. DNSChanger 2. Click Internet Options in the left panel.


