| Windows 7: Detected DNS cache poisoning attack. |
14 Nov 2011
|
#1 | | Windows 7 Ultimate 64bit SP1 |
Detected DNS cache poisoning attack. My Eset Smart Security 5 alert me with this message. Detected DNS cache poisoning attack
Remote IP address:
xxx.xxx.xx.xxx <---<Numbers here.
What exactly is this for? | My System Specs |
| System Manufacturer/Model Number Custom Built by me. OS Windows 7 Ultimate 64bit SP1 CPU Intel Core 2 Quad Q6600 Motherboard Gigabyte GA-X38-DS4 Memory 2X2GB DDR2 PC6400 800MHZ DUAL CHANNEL Graphics Card XFX RADEON HD 6850 1GB GDDR5 Sound Card 2/4/5.1/7.1-channel Realtek High Definition Monitor(s) Displays Samsung LE40A656F1 1080p 100Hz LCD HD TV 50,000:1 Screen Resolution 1366x768 in Desktop,1920x1080p in gaming and video Keyboard Wireless Logitech LX710 Mouse Logitech Wireless Gaming Mouse G700 PSU THERMALTAKE W0229 TOUGHPOWER XT 750W Case A-Case Twin Engine BB Cooling 3 x thermaltake smart case fan II + 1 arctic cooling fan Hard Drives C:\WD VelociRaptor 150 GB,10,000 RPM
E:\WESTERN DIGITAL WD15EADS 1.5TB CAVIAR GREEN SATA2 F:\WESTERN DIGITAL WD15EADS 1.5TB CAVIAR GREEN SATA2 Internet Speed ADSL 12000 plus Other Info Mouse Logitech G700,with 13 buttons who needs keyboard in RPG?
D:\Sony high speed sata Dvd Rewriter
Logitech Cordless Rumblepad 2 |
14 Nov 2011
|
#2 | | Windows 8 Pro with Media Center x64 Southern California, USA |
"Run an Anti spyware program such as Spyware Terminator to clean your system from any malware", as suggested by one person.
I would suggest instead that you install malwarebytes to remove malware. Also, Microsoft Security Essentials is my favorite Antivirus, but I don't know very much about Eset Smart Security (why didn't it remove the problem? It only notifies you of it? Kinda lame isn't it?). DO NOT uninstall an antivirus through the control panel (if that is what you want to do). Rather, download an antivirus removal tool so that you do not corrupt anything in your system.
However, Eset recommends this method of uninstallation of antivirus software: How do I uninstall or reinstall ESET Smart Security/ESET NOD32 Antivirus? (4.x) - ESET Knowledgebase | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Dell Inspiron M5040 OS Windows 8 Pro with Media Center x64 CPU AMD E-450 APU 1.65 GHz Memory 4GB Graphics Card Built-in Radeon HD 6320 Graphics Screen Resolution 1366 x 768 Mouse Microsoft Wireless Mobile Mouse 3500 Cooling fan Hard Drives 500GB Internet Speed 2.86Mbps Download Speed, 2.85Mbps Upload Speed & 26ms Ping Antivirus Defender Browser IE10 |
14 Nov 2011
|
#4 | | Windows 8 Pro with Media Center x64 Southern California, USA |
Is this a networked or a home computer? | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Dell Inspiron M5040 OS Windows 8 Pro with Media Center x64 CPU AMD E-450 APU 1.65 GHz Memory 4GB Graphics Card Built-in Radeon HD 6320 Graphics Screen Resolution 1366 x 768 Mouse Microsoft Wireless Mobile Mouse 3500 Cooling fan Hard Drives 500GB Internet Speed 2.86Mbps Download Speed, 2.85Mbps Upload Speed & 26ms Ping Antivirus Defender Browser IE10 |
14 Nov 2011
|
#5 | | Windows 7 Ultimate 32bit SP1 |
Flush the DNS cache and restore MS's Hosts file ...
Copy and paste these lines in Note pad. @Echo on
pushd\windows\system32\drivers\etc
attrib -h -s -r hosts
echo 127.0.0.1 localhost>HOSTS
attrib +r +h +s hosts
popd
ipconfig /release
ipconfig /renew
ipconfig /flushdns
netsh winsock reset all
netsh int ip reset all
shutdown -r -t 1
del %0
Save as flush.bat to your desktop. Right click on the flush.bat file to run it as Administrator. Your computer will reboot itself.
Now run a full scan with Eset and let me know if it still detects a DNS cache poisoning. | My System Specs | | System Manufacturer/Model Number Bruce ... somewhere in his 40's OS Windows 7 Ultimate 32bit SP1 CPU Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz Motherboard INTEL/D975XBX2 Memory 4 GB Graphics Card ATI Radeon HD 2600 Pro Monitor(s) Displays Samsung SyncMaster 914v Screen Resolution 1280 x 1024 Keyboard Standard PS/2 Keyboard Mouse Microsoft PS/2 Mouse PSU Rocketfish 700 W Case G.Skill Gigabyte Chassis Hard Drives 2/500GB each ... ST3500630AS ATA Device.
One is not connected Internet Speed DSL Antivirus Avira Internet Security Browser IE 9 Other Info ATI HDMI Audio |
15 Nov 2011
|
#6 | | Windows 7 & Windows Vista Ultimate Upstate NY |
Definitely follow Jacee's instructions.
See World's stealthiest rootkit pushes DNS hijacking trojan • The Register for additional information. Quote: End users who want to know if their systems are infected should check the DNS server settings of their operating system and routers. Compromised systems will show server IP addresses within the following ranges:
85.255.112.0 through 85.255.127.255
67.210.0.0 through 67.210.15.255
93.188.160.0 through 93.188.167.255
77.67.83.0 through 77.67.83.255
213.109.64.0 through 213.109.79.255
64.28.176.0 through 64.28.191.255
To check DNS settings on Windows open a command prompt and type "ipconfig /all" and then check the DNS Server field. On a Mac, choose System Preferences and then select Network. Then click on the Advanced button of the active connection. Users may also want to check the DNS servers used by their router. | My System Specs | | OS Windows 7 & Windows Vista Ultimate |
15 Nov 2011
|
#7 | | Windows 7 Ultimate 64bit SP1 |

Quote: Originally Posted by Jacee Flush the DNS cache and restore MS's Hosts file ...
Copy and paste these lines in Note pad. @Echo on
pushd\windows\system32\drivers\etc
attrib -h -s -r hosts
echo 127.0.0.1 localhost>HOSTS
attrib +r +h +s hosts
popd
ipconfig /release
ipconfig /renew
ipconfig /flushdns
netsh winsock reset all
netsh int ip reset all
shutdown -r -t 1
del %0
Save as flush.bat to your desktop. Right click on the flush.bat file to run it as Administrator. Your computer will reboot itself.
Now run a full scan with Eset and let me know if it still detects a DNS cache poisoning. 
Quote: Originally Posted by Corrine Definitely follow Jacee's instructions.
See World's stealthiest rootkit pushes DNS hijacking trojan • The Register for additional information. Quote: End users who want to know if their systems are infected should check the DNS server settings of their operating system and routers. Compromised systems will show server IP addresses within the following ranges:
85.255.112.0 through 85.255.127.255
67.210.0.0 through 67.210.15.255
93.188.160.0 through 93.188.167.255
77.67.83.0 through 77.67.83.255
213.109.64.0 through 213.109.79.255
64.28.176.0 through 64.28.191.255
To check DNS settings on Windows open a command prompt and type "ipconfig /all" and then check the DNS Server field. On a Mac, choose System Preferences and then select Network. Then click on the Advanced button of the active connection. Users may also want to check the DNS servers used by their router. I followed Jacee's instructions.
Everything is fine now.
The command from Jacee is
I keep it for future usage.
Thank you Ladies!! | My System Specs | | System Manufacturer/Model Number Custom Built by me. OS Windows 7 Ultimate 64bit SP1 CPU Intel Core 2 Quad Q6600 Motherboard Gigabyte GA-X38-DS4 Memory 2X2GB DDR2 PC6400 800MHZ DUAL CHANNEL Graphics Card XFX RADEON HD 6850 1GB GDDR5 Sound Card 2/4/5.1/7.1-channel Realtek High Definition Monitor(s) Displays Samsung LE40A656F1 1080p 100Hz LCD HD TV 50,000:1 Screen Resolution 1366x768 in Desktop,1920x1080p in gaming and video Keyboard Wireless Logitech LX710 Mouse Logitech Wireless Gaming Mouse G700 PSU THERMALTAKE W0229 TOUGHPOWER XT 750W Case A-Case Twin Engine BB Cooling 3 x thermaltake smart case fan II + 1 arctic cooling fan Hard Drives C:\WD VelociRaptor 150 GB,10,000 RPM
E:\WESTERN DIGITAL WD15EADS 1.5TB CAVIAR GREEN SATA2 F:\WESTERN DIGITAL WD15EADS 1.5TB CAVIAR GREEN SATA2 Internet Speed ADSL 12000 plus Other Info Mouse Logitech G700,with 13 buttons who needs keyboard in RPG?
D:\Sony high speed sata Dvd Rewriter
Logitech Cordless Rumblepad 2 |
15 Nov 2011
|
#8 | | Windows 8 Pro with Media Center x64 Southern California, USA |
I agree, very nice. Expert opinion nailed the problem exactly. Thats why we should all go to university | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Dell Inspiron M5040 OS Windows 8 Pro with Media Center x64 CPU AMD E-450 APU 1.65 GHz Memory 4GB Graphics Card Built-in Radeon HD 6320 Graphics Screen Resolution 1366 x 768 Mouse Microsoft Wireless Mobile Mouse 3500 Cooling fan Hard Drives 500GB Internet Speed 2.86Mbps Download Speed, 2.85Mbps Upload Speed & 26ms Ping Antivirus Defender Browser IE10 |
15 Nov 2011
|
#9 | | Windows 7 Home Premium x64 SP1 SoCal USA |
Following the advice from both Jacee and Corrine is a very wise thing to do! | My System Specs | | OS Windows 7 Home Premium x64 SP1 |
20 Feb 2012
|
#10 | | Windows Vista Home Premium SP2 64-bit |
Hello - I know this is an old thread, but this is exactly the problem I am having - except I think it is seeing my own IP address? It is the same IP address every time - I only just installed ESET Smart Security yesterday - it is updated and has run a scan with no detection.
I have done the above "flush.bat" instructions and the computer rebooted ok, and as soon as I opened a web page I got the same error as the OP: Detected DNS cache poisoning attack - with my own IP.
I ran Malware Bytes and got this report:
Malwarebytes' Anti-Malware 1.30
Database version: 1306
Windows 6.0.6002 Service Pack 2
21/02/2012 11:09:13 AM
mbam-log-2012-02-21 (11-09-13).txt
Scan type: Quick Scan
Objects scanned: 41351
Time elapsed: 2 minute(s), 33 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EKRN.exe (Security.Hijack) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected) | My System Specs | | OS Windows Vista Home Premium SP2 64-bit CPU i7 930 @2.8 Memory 12GB Detected DNS cache poisoning attack. problems? All times are GMT -5. The time now is 07:08 PM. | |