DNS calls to Ukraine destinations



I have an XP Pro box on an SBS network (one SBS Premium server w/ ISA 2004,
two XP Pro clients.) The box was heavily infected by numerous viruses and
other malware on 9/11. Issues with antivirus installation resulted in its
not updating for some time, but I'm not certain just how it all got started.
Far as I can tell, none of it got to any of the other machines on the
network,

I cleaned up using various AV and anti-spyware tools (AdAware, Spybot,
Trend-Micro AV) and it seems to be healthy now, but the ISA logs show this
machine making repeated calls on DNS protocol, port 53, to two different IPs
that belong to a web hosting company in the Ukraine. I can't help but think
that this is malware in action, but can't determine what is doing it. The
ISA firewall is blocking the requests, but I'd like to know what's going on.
Any ideas on how to trace this? I can't find anything in running processes
that isn't supposed to be there. Note that these calls are being made even
when nobody is logged on to the machine. They're averaging one per second.

--
Gary S. Terhune
MS MVP Shell/User



.



Relevant Pages

  • Re: Quickbooks and ISA 2004
    ... The ISA log may be your friend here. ... transmits payroll tax payment to EFTPS. ... outside my SBS network and without the proxy configured it works. ...
    (microsoft.public.isa)
  • Quickbooks and ISA 2004
    ... I am relatively new to ISA. ... transmits payroll tax payment to EFTPS. ... outside my SBS network and without the proxy configured it works. ...
    (microsoft.public.isa)
  • Asterisk PBX and SBS Network, living together?
    ... The company I work for is going to be installing a new phone system as ... I have been looking at the Linux Trixbox ... I have sbs 2003 Prem with isa 2004 running also have a linksys ... put the Trixbox behind my isa firewall on the sbs network, ...
    (microsoft.public.windows.server.sbs)
  • Winxp pro SP2 automatic update
    ... I have an ISA 2000 Server as member server of a Domain. ... Internet access works just fine but WinXP Pro clients can't use ...
    (microsoft.public.isa.clients)
  • Re: firewall choice
    ... Don't dismiss ISA so quickly without actually doing the research. ... it may not be "certified" to work on SBS, ... ISA has quite a bit of value in an SBS network. ... misconfiguration on an SBS box, ...
    (microsoft.public.windows.server.sbs)