Quantcast
Channel: Security forum
Viewing all articles
Browse latest Browse all 12072

DNS.exe is sending out hundreds of requests, ultimately killing all internet usage.

$
0
0

Scenario: Internet usage came to a grinding halt this afternoon. After doing some digging around, I venture into the resource monitor app within Win Server 2008 r2. It appears that I've got a slew of outgoing requests, using dns.exe, heading out to completely random sites. It's literally getting hammered. 

I check out my Kaspersky network AV; Kaspersky is seeing this as a standard windows process, as it's dns.exe, so no biggie.  I check out the ports and it's using hundreds of ports varying within 54,000 to 59,000.  I make some setting changes within Kasperksy to alleviate the complete barrage, and now I can get some use out of my Internet access. 

I've got an older Snapgear Firewall in front of all this; it doesn't do the best job of micro managing apps.  I've used a couple of network monitor apps on it but haven't turned up much other than the IP addresses it's heading to.  I've checked the outside world for DNS poisoning and things checked out fine.  From what I can tell I'm not relaying, but I'm not 100% certain.  Kasperksy and Malwarebytes have both turned up nothing.  I'm searching for any suggestions here!   Any and all help is greatly appreciated. 


Viewing all articles
Browse latest Browse all 12072

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>