DNS ??

Joze

Member
Joined
Feb 25, 2009
Messages
16
Reaction score
0
Hi

I got my DSL last week and pumped it for a test as anyone would do :D

My cap was reached and I was thrown on the local cap.

My service stopped working browsing local ZA and after checking everything with telkom I decided to check my setup again.

I can browse local sites with my laptop linking through to my Wifi through the same adsl router but my pc can't.

I can not resolve IP's by ping but NSLOOKUP does.
I then googled with my 3G to look for answers and only got some vague solutions, no one really have any solid rock reason for this.

I got from them that NET STOP DNSCACHE allows your ping resolution to work and then my PC local ZA browsing also starts working but it also requires that I have to open my firewall for ping. I'd like to close it and get DNS to work the way it should. Note that this was the problem even with ping allowed, only stopping DNSCACHE would allow my browser to start browsing local ZA.

I wonder if this was a problem on my machene or was there someting differant from the Global DNS config and the local?

The techs abroad blames some MS patches and some claims that service pack fixed it. I did not install any patches last week neither is any of my update services enabled, I also checked for spyware, I found a "Zlob.DNS Changer" but removing it did not resolve the problem. For now I am stuck stopping the dnscache.

Any advice out there?
 
Last edited:
Had an undetected (at least by the majority of AV vendors) rootkit sitting on my machine last week. My AV only picked it up as suspicious. Since you had Zlob running around, and with the old "where there's smoke there's fire" it wouldn't surprise me if something meaner was lurking around on your machine.

Basic question but did you check that your DNS server entries under your network connection are correct?

Forgot to mention what the rootkit did:
Changed registry entries so that DNS server addresses for my connection were constantly set to some IP. Changing the setting to allow it to obtain DNS server addresses automatically didn't help - as soon as you opened Properties again, the rogue IP was back.
Opening any browser resulted in the browser crashing 90% of the time before even a page was loaded, but on that 10% that a page did actually successfully load, further browsing was non-existant with the familiar "page not found" error.
 
Last edited:
Sounds like it.

Browser just disappears intermitted browser disappearing acts and some 88.X.X.X or 80.X.X.X dns when you enable DHCP.

Will investigate.

Thanx
 
That it was, found a rootkit, removed it with a symantec tool, Alls OK again.

Veelen Danke
 
Top
Sign up to the MyBroadband newsletter
X