dns poisoning?

Page 1 of 2 12 LastLast

  1. Posts : 6
    windows7 home premium
       #1

    dns poisoning?


    I've two pc's on the network; 1 is windows7, the other XP. The network aslo has a couple of wifi clients (phones and laptops)
    Anyways; I've had it a couple times now, where the home page (google.ca) loads to an adobe update page that insists on having me download an exe for update. This page url is showing Google
    I've scoured the pc and could not find anything; same with results with pcs2(xp).
    I did solve this by ipconfig /flushdns on both pc's and rebooting the router.
    Everything works again?
    Then a couple of days later, this problem returns.
    Is my dns being poisioned, and how? Any Idea's. I'm pretty certain there are no viruses on both of the systems I'm using, and the router is locked down with passwords.
      My Computer


  2. Posts : 25,847
    Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
       #2

    It may not be a virus.
    If it was my computer I would use these two programs.

    http://www.bleepingcomputer.com/download/adwcleaner/

    Malwarebytes : Malwarebytes Anti-Malware FREE

    Let us know if anything was found.
      My Computer


  3. Posts : 6
    windows7 home premium
    Thread Starter
       #3

    already ran malwarebytes


    No findings; I'm usually pretty good with indentifying crap and removal. I've rest browsers to default; cleared caches, and ran virsu scans via safe mode.
    Out of options
      My Computer


  4. Posts : 25,847
    Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
       #4

    Did you try adwcleaner from Bleeping Computer?
      My Computer


  5. Posts : 6
    windows7 home premium
    Thread Starter
       #5

    tried adware now


    It found some things and removed them...stuff like search conduit, which I think were old entries from a long time ago.
    After reboot; adware scan says clean.
    Funny thing I've noticed; even though my hompegae comes up fine for now; If I type in the web address bar http://yahoo.com, I recieve that annoying adobe update page....so the problem still exists.

    I'm not sure if this is external dns (a router problem) or internally manipulated dns (my system infected)
      My Computer


  6. Posts : 10,485
    W7 Pro SP1 64bit
       #6

    raylward102 said:
    ~~~
    ...the home page (google.ca) loads to an adobe update page that insists on having me download an exe for update.
    ~~~
    I did solve this by ipconfig /flushdns on both pc's and rebooting the router.
    ~~~
    I would be tempted to go ahead with the download and then upload it to virustotal... but that is just me. You might not feel comfortable doing that.

    You can disable the service named DNS Client on XP and W7. You will never miss it. Then there will be no DNS cache to be poisoned or flushed. It is not the kindest thing to do to your DNS provider, but it should not cause any problems while you are troubleshooting this issue. You might also consider pointing your DNS to OpenDNS.

    If the redirects still happen while the DNS Client is disabled, then you might want to consider scanning the computers while the operating system is not running (offline) What is Windows Defender Offline?

    Sometimes these offline scanners take a while - so plan to run them overnight.


    I don't pretend to understand the output of the command...
    nslookup -d google.ca
    ...but you might want to compare that info when the redirect is and is not happening.
      My Computer


  7. Posts : 10,485
    W7 Pro SP1 64bit
       #7

    raylward102 said:
    ~~~
    I'm not sure if this is external dns (a router problem) or internally manipulated dns (my system infected)
    Can you test without the router turned on?
    e.g. plug one computer directly into whatever jack the router normally connects to.
      My Computer


  8. Posts : 25,847
    Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
       #8

    Another suggestion.
    Go to Adobe's website and check and see if you need Adobe updated.
    If you need a update take it.
    You will notice that during updating Adobe give you a choice whether you want further updates auto, remind me of updates ect. Select which one.

    If you select remind me you will keep getting the reminder until you update.

    Another place to look is msconfig Startup and Services and see if you have Adobe Updater checked marked.
      My Computer


  9. Posts : 6
    windows7 home premium
    Thread Starter
       #9

    I'm an IT specialist fyi


    Adobe updates prompt for update by application windows only!; not web pages.
    Msconfig has been explored; no changes.
    I'm stumped. System seems to function correctly on all levels except for the stated issue
      My Computer


  10. Posts : 25,847
    Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
       #10

    Did you check with Adobe site and see if you need the Adobe update??
    I'm not a IT specialist may I still make suggestions.
      My Computer


 
Page 1 of 2 12 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 12:38.
Find Us