Jump to content


 

Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Detected DNS Cache Poisoning Attack


  • Please log in to reply
47 replies to this topic

#31 cryptodan

cryptodan

    Bleepin Madman

  • Inactive Staff
  • PipPipPipPipPipPip
  • 19,032 posts
  • Gender:Male
  • Location:Catonsville, Md

Posted 27 May 2012 - 11:16 PM

Yes please perform the uninstall of combofix as instructed in the last post.

 

  • BC Ads
  • BleepingComputer.com

#32 bin101

bin101

    Member

  • Members
  • PipPip
  • 29 posts

Posted 28 May 2012 - 12:11 AM

Yes please perform the uninstall of combofix as instructed in the last post.


done, what is the next step?

#33 cryptodan

cryptodan

    Bleepin Madman

  • Inactive Staff
  • PipPipPipPipPipPip
  • 19,032 posts
  • Gender:Male
  • Location:Catonsville, Md

Posted 28 May 2012 - 12:19 AM

Are you using Windows Firewall by any chance?

Also what kind of CD-ROM do you have, the below will let me know that information.

Please perform the following, so that we can get the exact specs of your computer. This will better assist us in helping you more.

Publish a Snapshot using Speccy

The below is for those who cannot get online

Please take caution when attaching a text file to your post if you cannot copy/paste the link to your post, you will need to edit it to make sure that your Windows Key is not present.

#34 bin101

bin101

    Member

  • Members
  • PipPip
  • 29 posts

Posted 28 May 2012 - 12:28 AM

http://speccy.piriform.com/results/LMOfzWdkzzS7k8qQjlHZcjj

Can I request that the information in this thread be deleted afterwards? it seems to be showing quite alot of my information within my computer...
(even this link to be removed)

According to Sneakycyber, my cdrom is out of date and needed an update, but he/she told that process will be after fixing the problem. And yes, I have Windows Firewall activated at the moment

Edited by bin101, 28 May 2012 - 12:31 AM.


#35 cryptodan

cryptodan

    Bleepin Madman

  • Inactive Staff
  • PipPipPipPipPipPip
  • 19,032 posts
  • Gender:Male
  • Location:Catonsville, Md

Posted 28 May 2012 - 12:41 AM

Yes that link can be deleted by you, and lets take care of a few things first.

Are you using the firewall within Eset or is it disabled? If you are using Eset as your firewall then you need to disable Windows Firewall.

Also lets go disable Windows Defender which is running. Go to Control Panel then to Administrative Tools then to Service scroll down and disable Windows Defender from starting.

Having multiple active scanners going can cause issues.

#36 bin101

bin101

    Member

  • Members
  • PipPip
  • 29 posts

Posted 28 May 2012 - 12:47 AM

Yes that link can be deleted by you, and lets take care of a few things first.

Are you using the firewall within Eset or is it disabled? If you are using Eset as your firewall then you need to disable Windows Firewall.

Also lets go disable Windows Defender which is running. Go to Control Panel then to Administrative Tools then to Service scroll down and disable Windows Defender from starting.

Having multiple active scanners going can cause issues.


Done

Guess I'll delete everything if this can be solved...
I have Windows Firewall disabled at the moment and have ESET firewall running. But would it be better to run the opposite? Disabling ESET's firewall and using Windows (since as I recall was suggested by someone else)

#37 cryptodan

cryptodan

    Bleepin Madman

  • Inactive Staff
  • PipPipPipPipPipPip
  • 19,032 posts
  • Gender:Male
  • Location:Catonsville, Md

Posted 28 May 2012 - 12:55 AM

Well lets do this for now and see if the attacks continue to appear. Also what is the exact model number of your Sony Lap top?

This can be found on the bottom on the label.

#38 bin101

bin101

    Member

  • Members
  • PipPip
  • 29 posts

Posted 28 May 2012 - 01:04 AM

Well lets do this for now and see if the attacks continue to appear. Also what is the exact model number of your Sony Lap top?

This can be found on the bottom on the label.


I purchased this online, its a VPCSA26GG
I am getting the message less frequent compared to before, but I actually did get before I did the uninstalling of ComboFix and Speccy.

I just wanted to know, were these the steps to "removing the registry remnant and any others from my computer" mentioned by Sneakycyber?

UPDATE: I just received 2 notification with the same error again... >.<

Edited by bin101, 28 May 2012 - 01:12 AM.


#39 cryptodan

cryptodan

    Bleepin Madman

  • Inactive Staff
  • PipPipPipPipPipPip
  • 19,032 posts
  • Gender:Male
  • Location:Catonsville, Md

Posted 28 May 2012 - 01:17 AM

Lets go ahead and disable Eset's firewall then enable Windows Firewall.

Also can you navigate to Device Manager via right clicking on My Computer then go to Properties. On the left click on Device Manager.

go to CD/DVD-ROMS and expand it. Right click on it and go to Properties then the Details Tab and select HardwareID's copy and paste the information into your next post.

I want to make sure that I am giving you the right link to upgrade the CD-ROM Drivers.

#40 bin101

bin101

    Member

  • Members
  • PipPip
  • 29 posts

Posted 28 May 2012 - 01:29 AM

Lets go ahead and disable Eset's firewall then enable Windows Firewall.

Also can you navigate to Device Manager via right clicking on My Computer then go to Properties. On the left click on Device Manager.

go to CD/DVD-ROMS and expand it. Right click on it and go to Properties then the Details Tab and select HardwareID's copy and paste the information into your next post.

I want to make sure that I am giving you the right link to upgrade the CD-ROM Drivers.


I have Eset's personal firewall disabled and now with Windows Firewall enabled, hopefully that does the trick. I am unfamiliar with what I have, is the router I have a firewalled router? I've been told that running Windows firewall + firewalled router should be enough as protection, is the router already automatically setup to protect? or again, is there another procedure in setting it up?

And this is what I have under the tab you mentioned:

IDE\CdRomMATbleepA_DVD-RAM_UJ8A2AS________________1.20____
IDE\MATbleepA_DVD-RAM_UJ8A2AS________________1.20____
IDE\CdRomMATbleepA_DVD-RAM_UJ8A2AS________________
MATbleepA_DVD-RAM_UJ8A2AS________________1.20____
GenCdRom

Edited by bin101, 28 May 2012 - 01:40 AM.


#41 cryptodan

cryptodan

    Bleepin Madman

  • Inactive Staff
  • PipPipPipPipPipPip
  • 19,032 posts
  • Gender:Male
  • Location:Catonsville, Md

Posted 28 May 2012 - 01:42 AM

Here is the user manual for your router: ftp://ftp.dlink.com/Gateway/dir615/Manual/dir615_manual_100.zip in there it will discuss the firewall and its options.


Lets look for some files:

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

64-bit users go HERE
  • Double-click SystemLook.exe to run it.
  • Vista\Win 7 users:: Right click on SystemLook.exe, click Run As Administrator
  • Copy the content of the following box into the main textfield:
    :filefind
    cdrom.sys
    cdrom.inf
    
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

#42 bin101

bin101

    Member

  • Members
  • PipPip
  • 29 posts

Posted 28 May 2012 - 01:50 AM

Here is the user manual for your router: ftp://ftp.dlink.com/Gateway/dir615/Manual/dir615_manual_100.zip in there it will discuss the firewall and its options.


Lets look for some files:

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

64-bit users go HERE

  • Double-click SystemLook.exe to run it.
  • Vista\Win 7 users:: Right click on SystemLook.exe, click Run As Administrator
  • Copy the content of the following box into the main textfield:
    :filefind
    cdrom.sys
    cdrom.inf
    
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt


Thanks, I'll read over my manual and see if I am able to get anything out of it, or find some alternative or something hahaha

Here are the results:

SystemLook 30.07.11 by jpshortstuff
Log created at 23:44 on 27/05/2012 by sony
Administrator - Elevation successful

========== filefind ==========

Searching for "cdrom.sys"
C:\Windows\System32\drivers\cdrom.sys --a---- 147456 bytes [03:23 21/11/2010] [03:23 21/11/2010] F036CE71586E93D94DAB220D7BDF4416
C:\Windows\System32\DriverStore\FileRepository\cdrom.inf_amd64_neutral_0b3d0d1942ab684b\cdrom.sys --a---- 147456 bytes [03:23 21/11/2010] [03:23 21/11/2010] F036CE71586E93D94DAB220D7BDF4416
C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7601.17514_none_bdcf6151ba66f48b\cdrom.sys --a---- 147456 bytes [03:23 21/11/2010] [03:23 21/11/2010] F036CE71586E93D94DAB220D7BDF4416

Searching for "cdrom.inf"
C:\Windows\inf\cdrom.inf --a---- 9878 bytes [05:31 14/07/2009] [03:28 21/11/2010] 55F752CB20B82A4424CE33D1ABCFA755
C:\Windows\System32\DriverStore\FileRepository\cdrom.inf_amd64_neutral_0b3d0d1942ab684b\cdrom.inf --a---- 9878 bytes [03:23 21/11/2010] [03:23 21/11/2010] 55F752CB20B82A4424CE33D1ABCFA755
C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7601.17514_none_bdcf6151ba66f48b\cdrom.inf --a---- 9878 bytes [03:23 21/11/2010] [03:23 21/11/2010] 55F752CB20B82A4424CE33D1ABCFA755

-= EOF =-

#43 cryptodan

cryptodan

    Bleepin Madman

  • Inactive Staff
  • PipPipPipPipPipPip
  • 19,032 posts
  • Gender:Male
  • Location:Catonsville, Md

Posted 28 May 2012 - 01:56 AM

Thanks, I'll read over my manual and see if I am able to get anything out of it, or find some alternative or something hahaha

Here are the results:

SystemLook 30.07.11 by jpshortstuff
Log created at 23:44 on 27/05/2012 by sony
Administrator - Elevation successful

========== filefind ==========

Searching for "cdrom.sys"
C:\Windows\System32\drivers\cdrom.sys --a---- 147456 bytes [03:23 21/11/2010] [03:23 21/11/2010] F036CE71586E93D94DAB220D7BDF4416

Searching for "cdrom.inf"
C:\Windows\inf\cdrom.inf --a---- 9878 bytes [05:31 14/07/2009] [03:28 21/11/2010] 55F752CB20B82A4424CE33D1ABCFA755

-= EOF =-


You have the latest version of the CD-ROM Files:

SystemLook 30.07.11 by jpshortstuff
Log created at 06:52 on 28/05/2012 by cryptodan
Administrator - Elevation successful

========== filefind ==========

Searching for "cdrom.sys"
C:\Windows\System32\drivers\cdrom.sys --a---- 147456 bytes [17:17 08/09/2011] [01:19 20/11/2010] F036CE71586E93D94DAB220D7BDF4416


Searching for "cdrom.inf"
C:\Windows\inf\cdrom.inf --a---- 9878 bytes [05:31 14/07/2009] [17:47 08/09/2011] 55F752CB20B82A4424CE33D1ABCFA755


-= EOF =-

#44 bin101

bin101

    Member

  • Members
  • PipPip
  • 29 posts

Posted 28 May 2012 - 02:33 AM

Well, since I have the ESET firewall disabled and with Windows Firewall enabled, I don't think I will be getting that notification again. Hopefully no more problems...

I just wanted to know, were the steps before the cdrom check, to "removing the registry remnant and any others from my computer" mentioned by Sneakycyber??

#45 Sneakycyber

Sneakycyber

    IT Support Specialist

  • BC Advisor
  • PipPipPipPipPipPip
  • 5,007 posts
  • Gender:Male
  • Location:Ohio

Posted 28 May 2012 - 11:01 AM

Just to recap I had said the file could have been moved because of and update. Not that the drivers were out of date. Cryptodan did everything I would have done and a few that I didn't know to do. Rest assured your in great hands.

~Chad Mockensturm~
Network Infrastructure Engineer, Windows Server 2008R2
Cisco Certified Home and Small Business Networking Support





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users