A
Andrew Bell
Hi,
I have a windows XP Pro system. I think a virus or
something has gotten in some how. This is what is
happening. Whenever I try and browse to one of the
popular search engine web sites such as google it take me
to some cPanel site.
Some how something has gotten in and poisoned my clients
DNS cache.
I've tried flushdns cache no joy all the false info is
still listed there. There is a sample of the cache
below. They all point to the 207.44.220.30 IP. I've
made sure that the hosts and lmhost files haven't been
altered. Gone through the registry looking for rouge
programs at start up. What other means do programs have
at editing the cache, also how can I edit the cache.
Anybody seen this before, if so how did you remove it?
C:\ >ipconfig /displaydns
Windows IP Configuration
www.lycos.de
----------------------------------------
Record Name . . . . . : www.lycos.de
Record Type . . . . . : 1
Time To Live . . . . : 581890
Data Length . . . . . : 4
Section . . . . . . . : Answer
A (Host) Record . . . : 207.44.220.30
search.msn.co.kr
----------------------------------------
Record Name . . . . . : search.msn.co.kr
Record Type . . . . . : 1
Time To Live . . . . : 581890
Data Length . . . . . : 4
Section . . . . . . . : Answer
A (Host) Record . . . : 207.44.220.30
I have a windows XP Pro system. I think a virus or
something has gotten in some how. This is what is
happening. Whenever I try and browse to one of the
popular search engine web sites such as google it take me
to some cPanel site.
Some how something has gotten in and poisoned my clients
DNS cache.
I've tried flushdns cache no joy all the false info is
still listed there. There is a sample of the cache
below. They all point to the 207.44.220.30 IP. I've
made sure that the hosts and lmhost files haven't been
altered. Gone through the registry looking for rouge
programs at start up. What other means do programs have
at editing the cache, also how can I edit the cache.
Anybody seen this before, if so how did you remove it?
C:\ >ipconfig /displaydns
Windows IP Configuration
www.lycos.de
----------------------------------------
Record Name . . . . . : www.lycos.de
Record Type . . . . . : 1
Time To Live . . . . : 581890
Data Length . . . . . : 4
Section . . . . . . . : Answer
A (Host) Record . . . : 207.44.220.30
search.msn.co.kr
----------------------------------------
Record Name . . . . . : search.msn.co.kr
Record Type . . . . . : 1
Time To Live . . . . : 581890
Data Length . . . . . : 4
Section . . . . . . . : Answer
A (Host) Record . . . : 207.44.220.30