paulvernon63 Posted October 17, 2012 Posted October 17, 2012 My Server 2003 machine appears to be having it's network card DNS address set to 8.8.8.8 and 8.8.4.4. I know that's google dns but I haven't set the card's dns to that; we use SEGfL / RMs forwarders, 62.171.198.104 and 105. Is it possible that a virus / malware infection could be causing this? Can I monitor this in event viewer; what would be the event ID? Regards, Paul Vernon.
Geoff Posted October 17, 2012 Posted October 17, 2012 That's a symptom of the TDSS Rootkit. TDL4 – Top Bot - Securelist
sonofsanta Posted October 17, 2012 Posted October 17, 2012 hack hack hack, check your firewall ports & close them down, check your security logs, assume that server has been compromised.
Gibson335 Posted October 17, 2012 Posted October 17, 2012 Yes, and I hate to say it, but change your admin password - or at least give it strong consideration.
andydis Posted October 17, 2012 Posted October 17, 2012 lots of malware does this too, check for the normal : startup entrys you do not recognize, unusual services, you could try tea timer from spybot to find out what changes the setting. check your local users passwords
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now