New DNS Spyware - YotaTech Forums
YotaTech Forums  

Go Back   YotaTech Forums > Toyota Forums Available > Electronics > Computer Talk

Notices

Welcome to Yotatech!
Welcome to Yotatech,

You are currently viewing our forum as a guest, which gives you limited access to view most discussions and access our other features. By joining our community, at no cost, you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is free, fast and simple, so please join our community today!


Reply
 
Thread Tools Search this Thread
Old 06-10-2007, 08:33 AM   #1 (permalink)
Co-Founder/Administrator
Staff
 
Corey's Avatar
 
Join Date: May 2002
Location: Auburn, Washington
Posts: 26,071
New DNS Spyware

New spyware out today that comes in through your Comcast connection via the DNS server.

If you get a webpage that says it is from supportcomcast or something like that wherever you attempt to surf, you are infected, but it is not an actual file on your PC.

They want you to put in your private info on the website, do not.
Also the phone # they list is bogus, it is a busy signal, thus tricking you to use your browser to give them your info.

I ran my spyware apps many times this morning, with no fix.

Comcast told me on the tele a bit ago how to fix it.

Go to your start button and find the run command.
Once there type in cmd, hit enter.

In the text box type in
ipconfig /release
hit enter, and all commands after typing in ipconfig have a space after that word and before the / symbol.

Now type in ipconfig /flushdns
hit enter

Now type in ipconfig /renew
hit enter

Go to your Control Panel on your start button.
Choose Internet Options, and delete cookie and temp. internet files.

Then go below and clear your history.

This is new today, someone took over the dns somehow and it redirecting you to that spyware page.

Hopefully Comcast will add this info to their website soon.
This ad is not displayed to registered members.
Register your free account today and become a member on Yotatech!
Corey is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-10-2007, 08:46 AM   #2 (permalink)
Co-Founder/Administrator
Staff
 
Corey's Avatar
 
Join Date: May 2002
Location: Auburn, Washington
Posts: 26,071
PS, it just happened to me again as soon as I posted this.
I had to go through all the above steps and do them all over again.

Whoever created this dns spyware thing needs to be shot.

I am sure it will effect me again very soon.

Here is some info member Drew found over on DLS Reports site.
http://www.dslreports.com/forum/remark,18480900
Corey is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-10-2007, 11:09 AM   #3 (permalink)
Co-Founder/Administrator
Staff
 
Corey's Avatar
 
Join Date: May 2002
Location: Auburn, Washington
Posts: 26,071
If anyone has problems, try getting rid of your Comcast DNS numbers and use the Open DNS ones as detailed in the URL I posted above.

I have been attacked about 5 times this morning, but since switching over to the new DNS #s, it seems to be working OK.

I bet Comcast is having a major blowout on with this issue.
Pretty scary when someone can take control of your surfing like that.
Corey is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-10-2007, 11:26 AM   #4 (permalink)
Contributing Member
 
arjan's Avatar
 
Join Date: Sep 2002
Location: Mission, British Columbia
Posts: 1,558
Hey corey about the opendns thing, all you should have to do is change the dns settings in your network properties page for your network adapter. I downloaded the image with the settings:
Attached Thumbnails
new-dns-spyware-start_win6.gif  
__________________
2006 4Runner V8 Sports Edition
Red 1997 4Runner 3.4L Bushwacker Flares, 5spd, E locker
arjan is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-10-2007, 11:49 AM   #5 (permalink)
Registered User
 
91TPU's Avatar
 
Join Date: Oct 2006
Location: NorthWest NJ
Posts: 1,604
Send a message via AIM to 91TPU
i have comcast and havent gotten anything...
__________________
87' 4runner...22re...31" Bridgestone Dueler AT-New project rig and winter dd.
91' 3vze...190k...31" BFG All Terrain's...K&N FIPK-SOLD
07' Civic Si-The Daily Driver.


Quote:
Originally Posted by Sonofmayhem View Post
god hates you.
91TPU is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-10-2007, 11:58 AM   #6 (permalink)
Co-Founder/Administrator
Staff
 
Corey's Avatar
 
Join Date: May 2002
Location: Auburn, Washington
Posts: 26,071
Thanks Arjan, I inputted as I described over on DSL's forum in both places.
All is working well, the problem has not come back.

From what I read over there, the speculation is somehow the dns servers for Comcast in WA., OR., ID., and CO. were taken over by some perp who started the attack.

91, it should not effect you since you are on the Eastern side of things.

What was frustrating earlier today was that I thought I actually had the spyware on my PC, but the repeated tests did not reveal anything thing out of the ordinary.

And I bet a lot of people will fall for that fake page and enter their info, I almost did, and I never fall for Internet scams.
Calling that 800 # on the page will get you nowhere, that is how they they trap you into getting into the chat session which is bogus, but you have already entered your info to get into the chat.

What I think they would then do with your info is setup multiple email accounts and then start mass spamming via your hi-jacked email accounts.

And here is a screenshot of the page that I and many others were seeing earlier.
It did not matter what you typed in your URL bar or what bookmark you clicked on, this screen would come up in your browser.

Whoever created it did a lot of planning on this one.

Corey is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-10-2007, 12:38 PM   #7 (permalink)
Contributing Member
 
arjan's Avatar
 
Join Date: Sep 2002
Location: Mission, British Columbia
Posts: 1,558
I thought I read somewhere that the opendns website wasn't accesable, that's why I posted the dns server addresses.
__________________
2006 4Runner V8 Sports Edition
Red 1997 4Runner 3.4L Bushwacker Flares, 5spd, E locker
arjan is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-10-2007, 12:43 PM   #8 (permalink)
Co-Founder/Administrator
Staff
 
Corey's Avatar
 
Join Date: May 2002
Location: Auburn, Washington
Posts: 26,071
I got on the site just fine, and read through the FAQ over there about them.

Seems now the page I and others were being redirected to may be legit after all, and not a hackers attempt to get our info.

But Comcast still fubared up something bigtime for us to get that page.
I bet they keep it hush hush, but it will leak out to some websites as to how it happened.
Corey is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-10-2007, 01:17 PM   #9 (permalink)
Contributing Member
 
ocdropzone's Avatar
 
Join Date: Oct 2005
Location: PDX, OR
Posts: 4,709
Stuff like this, plus the never ending price increases is one reason I ditched comcast...though I will admit I miss the speed...
ocdropzone is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 12-08-2007, 09:39 AM   #10 (permalink)
Registered User
 
CAM 1's Avatar
 
Join Date: Mar 2004
Location: N.Y.
Posts: 369
Well..this thing made it to the east coast. I'm having the same problem, I get re-directed to there web page every time I search. I'm trying to work it out right now. McAfee and the newest AVG can't find anything. and cablevision is no help what-so-ever!


Craig.
__________________
2001 Tacoma prerunner Dlb cab TRD Limited
Stuff: Manik brush guard,100 Watt Hella 500's, Extended diff breather, 265/75/16 Bridgestone REVO A/T's.
98% of all Ford Trucks are still on the road......The other 2% made it home.

Last edited by CAM 1; 12-08-2007 at 09:40 AM.
CAM 1 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 12-08-2007, 09:53 AM   #11 (permalink)
Co-Founder/Administrator
Staff
 
Corey's Avatar
 
Join Date: May 2002
Location: Auburn, Washington
Posts: 26,071
Cablevision, that is your ISP?
See is anything comes up here.
http://www.dslreports.com/forums/4

By the way, I am still using Open DNS's numbers, I have not gone back to Comcasts.

The only thing is you have to type in .com .net, ect after an URL, or it will bring up Open DNS's search page.
Corey is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 12-08-2007, 11:49 AM   #12 (permalink)
Registered User
 
isaac338's Avatar
 
Join Date: Jul 2006
Location: Halifax, NS, Canada
Posts: 849
for the more nerdy amongst us it's relatively simple to run your own nameserver locally and avoid this kind of thing from happening ever again. if you're using unix or mac os x it's easy as pie. you could probably find some kind of strange bind port for windows if you wanted, too.
__________________
1994 Xtracab pickup, 180,000km
1987 4Runner, 510,000km
isaac338 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 01-19-2009, 05:34 PM   #13 (permalink)
Registered User
 
Join Date: Oct 2007
Location: NC
Posts: 20
Send a message via AIM to jasonszion Send a message via MSN to jasonszion Send a message via Yahoo to jasonszion
lol sounds like you have a nice little browser hijack... Try running Malwarebytes... (its a free download) to rid yourself of those nasty little things... I work in a computer repair shop and I see that all the time...
btw watchout for the virus called antivirus2009 its horrible...
__________________
'92 Toy 4x4, 22re. 108k miles
jasonszion is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 01-20-2009, 01:59 AM   #14 (permalink)
Co-Founder/Administrator
Staff
 
Corey's Avatar
 
Join Date: May 2002
Location: Auburn, Washington
Posts: 26,071
Quote:
Originally Posted by jasonszion View Post
lol sounds like you have a nice little browser hijack... Try running Malwarebytes... (its a free download) to rid yourself of those nasty little things... I work in a computer repair shop and I see that all the time...
btw watchout for the virus called antivirus2009 its horrible...
Nope, it was not spyware on my end.
Many got hit with it as seen at Comcasts forum on DSL Reports.
http://www.dslreports.com/forum/comcast

Comcast was the one that got hijacked actually, they just did not want to fess up to it.
It effected many people that day.
Corey is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 01-20-2009, 07:27 AM   #15 (permalink)
Registered User
 
Windsor's Avatar
 
Join Date: Dec 2008
Location: DFW, Texas!
Posts: 794
When there are DNS-based attacks like this, you can always just hardcode your DNS server to something away from the hijacked servers.

One I use for network testing is 4.2.2.2, a leftover from Genuity (previously BBN Planet).
__________________
'87 T4R Deluxe, mall crawler
every non-SR5 option installed (sans AT), as well as:
* Cruise Control (dealer installed)
* Michelin LTX A/T2 31s on 1st-gen alloy rims
* SmittyBilt granny step bar
* SR5 Instrument Cluster
Windsor is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Tags
at2, caused, change, comcast, cruiser, dns, find, fix, fj, ipconfig, ltx, mcafee, michelin, problem, problems, server, setting, spyware, test

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
spyware Memphis_Yota Computer Talk 19 03-17-2005 06:56 PM
Spyware!!!! FUGGRWE Computer Talk 22 07-26-2004 07:43 PM
GoDaddy users... how do I setup the DNS so my domain names point to my IP? jacksonpt Off Topic Talk 6 03-29-2004 11:39 AM
Spyware Shootout BT17R Off Topic Talk 0 02-19-2004 06:04 PM
DNS servers Corey Off Topic Talk 4 11-07-2003 08:48 AM


All times are GMT -8. The time now is 05:56 PM.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Powered by vbWiki Pro . Copyright ©2006, NuHit, LLC
2009 InternetBrands, Inc.