locked
"Random" DNS Client Events Warnigs RRS feed

  • General discussion

  • Hi all ,

    I've noticed that the we get “Event ID 1014” in the Administrative Events log.

    It comes and go and it shows us unknown sporadic hostnames along with our domain suffix.

    A few examples are:

    “Name resolution for the name wqeghmrm.our.domain.suffix timed out after none of the configured DNS servers responded.”

    “Name resolution for the name mjxnekvprmmvu.our.domain.suffix timed out after none of the configured DNS servers responded.”

    I suspect, it’s some kind of spyware/Trojan, but I am not sure.  I have checked with Antivirus as well as Sysinternals process explorer

    But I  couldn’t found  any suspicious process.

    Any idea?

    Thanks,

    Sunday, July 12, 2015 5:29 AM