Warning to BT broadband owners
Discussion
Having personally seen this last week I have no doubt that BT's DNS servers have been hacked. If you go to google (for example) and see dns.sysip.net in your status bar when the page is loading then you are affected by this. I don't use IE but it is easy to see this in firefox. If this is happening to you then look at the page source code and you will see the javascript that has been injected into the page.
http://en.wikipedia.org/wiki/DNS_cache_poisoning
I managed to get rid of it eventually by using ComboFix with ccleaner, running ipconfig.exe /flushdns and then rebooting. Although I had previously got rid of it and it came back again ...
http://en.wikipedia.org/wiki/DNS_cache_poisoning
I managed to get rid of it eventually by using ComboFix with ccleaner, running ipconfig.exe /flushdns and then rebooting. Although I had previously got rid of it and it came back again ...
trackcar said:
My bro in law is on BT broadband .. would this affect him? would he have had to do anything at his end for this re-routing to have taken effect or is it a BT issue ie out of his hands until he notices it's happened?
It could affect anyone who is on BT broadband as far as I know. And yes, it is a BT issue. Most people won't notice it is happening at all.If only I had this problem!! I'm still without a broadband connection, almost a week after reporting the problem. The geniuses at BT "accidentally" put a cease order on my broadband, despite me making it very clear I rely on the link for business, and despite a so-called fasttrack order I'm still without broadband. 
Seriously fed up with BT now. They've cost me a fortune this week in lost sales and time.

Seriously fed up with BT now. They've cost me a fortune this week in lost sales and time.
Presumably, if this was happening then a DNS lookup of an affected name would return the wrong address.
So for example www.google.com currently maps to addresses 66.249.93.104, 66.249.93.147, 66.249.93.99. What do you get if you run nslookup www.google.com on your affected machine?
So for example www.google.com currently maps to addresses 66.249.93.104, 66.249.93.147, 66.249.93.99. What do you get if you run nslookup www.google.com on your affected machine?
More info here:
http://www.digitalspy.co.uk/forums/showthread.php?...
Seems it may be looking for the Firefox 2.0.0.4 user agent because that is what I was using
http://www.digitalspy.co.uk/forums/showthread.php?...
Seems it may be looking for the Firefox 2.0.0.4 user agent because that is what I was using
130R said:
Was either on this post ,or the link that i saw microtrend.WAS with BT broadband - still link to my old bt yahoo a/c , ran XoftSPY SE, the other day, that was result. ----infection in cookies trend micro.
XftSPYSE from ParetoLogic
http://support.paretologic.com/?aid=2&lid=EN&a...
Trial only -finds, won't delete -but tells you where to look.
Edited by Who me ? on Saturday 7th July 20:23
Bumping this since I have only just found out - This turned out to be BT *illegally* testing Phorm last summer.
http://www.theregister.co.uk/2008/02/27/bt_phorm_1...
Unbelievable.
http://www.theregister.co.uk/2008/02/27/bt_phorm_1...
Unbelievable.
Gassing Station | Computers, Gadgets & Stuff | Top of Page | What's New | My Stuff





