ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    WPAD alert

    IT Discussion
    virus alerts
    3
    7
    1.6k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JaredBuschJ
      JaredBusch
      last edited by JaredBusch

      Has anyone ever come across this before?

      https://nakedsecurity.sophos.com/2016/05/25/when-domain-names-attack-the-wpad-name-collision-vulnerability/

      I have a single machine running the Avast for Business (free verison) that suddenly start spamming alerts
      0_1489764912678_upload-c682d56b-ad77-48cd-9e42-c14f0cc99e29

      Installed Webroot and Malwarebytes trial and nothing related was found.

      Only Avast is alerting on this.

      Really do not want to mark it false positive or anything, but I really want to find an answer.

      New alerts come every 10 minutes exactly.
      0_1489765140306_upload-95f838b9-5647-4442-8744-e9b10921432e

      dafyreD 1 Reply Last reply Reply Quote 1
      • dafyreD
        dafyre @JaredBusch
        last edited by

        @JaredBusch said in WPAD alert:

        Has anyone ever come across this before?

        https://nakedsecurity.sophos.com/2016/05/25/when-domain-names-attack-the-wpad-name-collision-vulnerability/

        I have a single machine running the Avast for Business (free verison) that suddenly start spamming alerts
        0_1489764912678_upload-c682d56b-ad77-48cd-9e42-c14f0cc99e29

        Installed Webroot and Malwarebytes trial and nothing related was found.

        Only Avast is alerting on this.

        Really do not want to mark it false positive or anything, but I really want to find an answer.

        New alerts come every 10 minutes exactly.
        0_1489765140306_upload-95f838b9-5647-4442-8744-e9b10921432e

        Check for Internet Options -> Connections -> Lan settings and see if "Automatically
        detect settings" is checked.

        Also do an nslookup on wpad.net and see what IP comes back. For reference both my office machine and home systems all report 127.0.0.1 for wpad.net

        JaredBuschJ 1 Reply Last reply Reply Quote 0
        • JaredBuschJ
          JaredBusch @dafyre
          last edited by

          @dafyre said in WPAD alert:

          @JaredBusch said in WPAD alert:

          Has anyone ever come across this before?

          https://nakedsecurity.sophos.com/2016/05/25/when-domain-names-attack-the-wpad-name-collision-vulnerability/

          I have a single machine running the Avast for Business (free verison) that suddenly start spamming alerts
          0_1489764912678_upload-c682d56b-ad77-48cd-9e42-c14f0cc99e29

          Installed Webroot and Malwarebytes trial and nothing related was found.

          Only Avast is alerting on this.

          Really do not want to mark it false positive or anything, but I really want to find an answer.

          New alerts come every 10 minutes exactly.
          0_1489765140306_upload-95f838b9-5647-4442-8744-e9b10921432e

          Check for Internet Options -> Connections -> Lan settings and see if "Automatically
          detect settings" is checked.

          Also do an nslookup on wpad.net and see what IP comes back. For reference both my office machine and home systems all report 127.0.0.1 for wpad.net

          Disabled in IE but enabled in Edge. I disabled it in Edge and it still sends alerts.

          C:\Users\User>ipconfig /flushdns
          
          Windows IP Configuration
          
          Successfully flushed the DNS Resolver Cache.
          
          C:\Users\User>nslookup
          Default Server:  UnKnown
          Address:  10.254.101.1
          
          > wpad.net
          Server:  UnKnown
          Address:  10.254.101.1
          
          Non-authoritative answer:
          Name:    wpad.net.chestnut.net
          Address:  209.15.13.134
          
          >
          
          dafyreD 1 Reply Last reply Reply Quote 0
          • dafyreD
            dafyre @JaredBusch
            last edited by

            @JaredBusch said in WPAD alert:

            @dafyre said in WPAD alert:

            @JaredBusch said in WPAD alert:

            Has anyone ever come across this before?

            https://nakedsecurity.sophos.com/2016/05/25/when-domain-names-attack-the-wpad-name-collision-vulnerability/

            I have a single machine running the Avast for Business (free verison) that suddenly start spamming alerts
            0_1489764912678_upload-c682d56b-ad77-48cd-9e42-c14f0cc99e29

            Installed Webroot and Malwarebytes trial and nothing related was found.

            Only Avast is alerting on this.

            Really do not want to mark it false positive or anything, but I really want to find an answer.

            New alerts come every 10 minutes exactly.
            0_1489765140306_upload-95f838b9-5647-4442-8744-e9b10921432e

            Check for Internet Options -> Connections -> Lan settings and see if "Automatically
            detect settings" is checked.

            Also do an nslookup on wpad.net and see what IP comes back. For reference both my office machine and home systems all report 127.0.0.1 for wpad.net

            Disabled in IE but enabled in Edge. I disabled it in Edge and it still sends alerts.

            C:\Users\User>ipconfig /flushdns
            
            Windows IP Configuration
            
            Successfully flushed the DNS Resolver Cache.
            
            C:\Users\User>nslookup
            Default Server:  UnKnown
            Address:  10.254.101.1
            
            > wpad.net
            Server:  UnKnown
            Address:  10.254.101.1
            
            Non-authoritative answer:
            Name:    wpad.net.chestnut.net
            Address:  209.15.13.134
            
            >
            

            Ewww... Sounds like something is hijacking your DNS, potentially. Check from another computer and see what nslookup reports.

            JaredBuschJ 1 Reply Last reply Reply Quote 0
            • JaredBuschJ
              JaredBusch @dafyre
              last edited by JaredBusch

              @dafyre said in WPAD alert:

              Ewww... Sounds like something is hijacking your DNS, potentially. Check from another computer and see what nslookup reports.

              There are no other computers on that network normally. I will get a laptop online to test at some point tomorrow.

              For now, I added a static host mapping in the router for wpad.net and wpad.net.chestnut.net pointing to 127.0.0.1

              0_1489940897391_upload-453fd76f-e118-4dd9-afb4-13e48632180f

              1 Reply Last reply Reply Quote 0
              • JaredBuschJ
                JaredBusch
                last edited by

                Avast is the only thing on the system that catches this. I installed MBAM (trial) and Webroot after these alerts started and neither find anything.

                Anyone have another suggestion?

                I cannot believe there is nothing on the machine.

                CloudKnightC 1 Reply Last reply Reply Quote 0
                • CloudKnightC
                  CloudKnight @JaredBusch
                  last edited by

                  @JaredBusch could try hitmanpro and adwcleaner to double check..

                  1 Reply Last reply Reply Quote 0
                  • 1 / 1
                  • First post
                    Last post