Re: Strangeness.......PLEASE HELP!

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Fizzasist (Fizzasist_at_discussions.microsoft.com)
Date: 01/28/05


Date: Fri, 28 Jan 2005 06:45:05 -0800

I have now determined that it is a DNS problem. When I do a NSLOOKUP from a
differetn (fully functional) machine and use that IP address to surf on the
"infected" machine, the page comes up ok. So it looks like a DNS issue to me
but how it is getting the wrong DNS info on just SOME of the websites....I do
not know.

"Fizzasist" wrote:

> I tried safe mode scanning as well. The entries were not beinbg made in the
> host file they were showing up under tools, Internet options, security,
> restricted sites. I have recently heard of a M$ product that is a spy-ware
> detector that is memory resident and is in BETA and one of the machines had
> this installed and I am wondering if it was adding these sites to the list
> but that was my only idea. (Can't believe anyone would install a M$ BETA
> product--let alone a SPYWARE scanner! ha ha)
>
> "Dave" wrote:
>
> > what are the sites that are being added to the restricted sites?? there
> > used to be a virus that would add anti-virus web sites to the hosts file
> > with 127.0.0.1 ip addresses so you could not get to them, maybe this is a
> > similar attack. you should probably boot those machines to safe mode and
> > try a virus scan with a tool tha is not installed on the machine now to be
> > sure it hasn't been corrupted or disabled by a virus.
> >
> > "Fizzasist" <Fizzasist@discussions.microsoft.com> wrote in message
> > news:89EA0CA8-B868-4EE5-B3DA-613541CAA956@microsoft.com...
> > > I have seen this one on a few different machines and am TOTALLY stumped:
> > I
> > > get a call from a client who is having trouble getting to certain
> > websites.
> > > Ran Spybot and AdAware and they cleaned up a few things (nothing
> > major)....no
> > > viruses either. Checked the restricted sites and there were A TON of them
> > > that the user did not put there. I removed them but was unable to get to
> > the
> > > certain sites. I did an nslookup and in some cases WAS able to go to the
> > > site using the address and not the name so I figured there was something
> > > wrong with the DNS settings. When I change the DNS settings to another
> > DNS
> > > (from Comcast to Qwest for example) I was able to get to some of the
> > sites.
> > > I checked the HOSTS file and it was normal. I decided to add some entries
> > in
> > > the HOST file for some of the critical sites and then it started working
> > ok
> > > but again, could not get to ALL of the sites that I wanted by name.
> > Checked
> > > the restricted sites list again and it had some ADDED to it that were not
> > > there before. I have now had this happen on three different PCs on three
> > > different networks so I am running out of ideas......any one heard of this
> > > before??? Nothing on SARC about it....I figure it is Spyware but it did
> > not
> > > find anything. Also ran HiJack This but it was unable to fix it also.
> > > HELP!!!! Please reply to randycarr@pobox.com
> >
> >
> >



Relevant Pages

  • Re: Preparing network connection after AD install
    ... I didn't install exchange yet. ... known symptoms of having exchange installed on DC and bad DNS ... Do not place the ISP DNS server or any other DNS on the ...
    (microsoft.public.windows.server.active_directory)
  • Re: Domain users
    ... for the DNS Server. ... User in the Domain and an Administrator in Windows XP still has all its ... > "George Hester" wrote in message ... >>> As a regular user they will not be able to install much of anything. ...
    (microsoft.public.win2000.group_policy)
  • Strange Problem(s) After Installing Security Update 818529
    ... administrator for various reasons, but it would not do it anymore ... download and install updates. ... DNS record '97678c29-9955-4573-8105-9baac54a5a47._msdcs.starfleet.gov. ... The local computer account is still listed in the AD ...
    (microsoft.public.win2000.security)
  • Re: Getting New Server - Coming from SBS2003 domain
    ... default login scripts with SBS. ... new Server if the ... addresses and we are thinking of letting the new sever be a DHCP & DNS ... If you want to keep the same name, but not the same domain, meaning to start fresh, then all the workstations will need to be disjoined first prior to unplugging the current machine, because you can't have the current one up and running when you install the new one. ...
    (microsoft.public.windows.server.sbs)
  • Re: promoting a member server to DC
    ... you said "promote it to be a DC in the same domain THEN install ... Did you mean the installing DNS is from add/remove windows components? ... I need to promote a member server to a DC as the second DC in a site. ... Because AD integrated zones are in the actual AD ...
    (microsoft.public.windows.server.active_directory)