Detected DNS query of malicious domain

Hi,

I’m new to this so please bear with me! thx, rubotted tells me I have a bot & log file says Detected DNS query of malicious domain. I was in Thunderbird email at the time, so since then I have run Housecall as it advised, TrendMicro Pro 2009 free trial, Avast Home Edition 4.8, Spybot, & Hijackthis all to no avail. I also uninstalled rubotted and reinstalled because the first version didn’t give me a logfile and everytime I ran it it came up green meaning no bots but then popup said bot found. After reinstall though it gave logfile and says I have bot.

I had to uninstall Avast to put on TrendMicro and have since reinstalled Avast and am running yet again! I do have to say Avast is great and I’m sticking with it! Anyway please HELP, I’m extremely frustrated and thinking I probably don’t have a bot but what if I do!!!
Thanks,
nanajana

Hi nanajana,

Reported a similar find, what I consider as a FP here: http://forum.avast.com/index.php?topic=40131.0

polonus

P.S. Have now installed BotHunter for XP to be sure and analyze the situation:
BotHunter is a passive network monitoring tool designed to recognize the communication patterns of malware-infected computers within your network perimeter. Using an advanced infection-dialog-based event correlation engine (patent pending), BotHunter represents the most in-depth network-based malware infection diagnosis system available today.

* Windows XP Distribution v1.0.2 (Official Release) - 14 November 2008

BotHunter-Win32-v1.0.2.exe, (MD5 = 30aa9d81bab1709be2b61e428461666b)

Download from Mirror Sites: [SRI], [EmergingThreats], [DShield]

http://www.cyber-ta.org/downloads/BotHunter-Win32-v1.0.2.exe
http://www.emergingthreats.net/bothunter/BotHunter-Win32-v1.0.2.exe

Windows XP: this self-installing Win32 executable will install all necessary supporting packages

pol

Hi polonus,

I am running Vista, I will go to website to see if they have a download for Vista.

thx
nanajana