Hi

I hope someone can help me.

I have three domains in my network environment - Network A, Network B and
Network C. Two domains are running Windows 2000 Server and the last is
Windows 2003 Server. Each domain has its own Domain Controller. Domain C
has two domain controllers. DNS is running within each domain and the Dns
server for each network is itself. Each domain communicates with the other
via a trust relationship. There is one DHCP server in the network allocating
IP addresses to the client machines running Windows XP.

My problem is as follows-
I have a 256/512Kbps wireless internet connection and I noticed that our
internet bandwidth has reduced significantly over the last couple of days. I
used Ethereal to pinpoint which machine was hogging the bandwith. Ethereal
results showed that the computer is querying www.cheaptickets.com for DNS
information along with some other wierd sites. It is one of the Domain
Controllers in Network C.

I installed Microsft Antispyware to scan the machine for spyware but nothing
was found. The Norton Virus defintions are up to date and it found no
viruses when a scan was done. When I take this machine off the network the
internet bandwidth returns to its normail behaviour. This machine is
currently running Norton, Exchange 5.5 and Print services.

What should be my next course of action to rectify this problem. The task
manager does not show any unregular behavour within the Processes nor
Performance tab.

What could be causing my problem and what should I do to rectify the issue.

PLEASE HELP.

Regards

Re: Eractic Behaviour from Win2k Server by Roger

Roger
Wed Jul 27 21:56:32 CDT 2005

You know, if some client is asking for this.cheaptickets.com, then for
that.cheaptickets.com, etc. it would be normal for your DNS server to
be making inquiries from their DNS server.
Now, this should not be to the extent that you notice network capacity
issues, but I am just wondering whether you have really pinpointed where
the capacity is being spent, rather than in what happens after DNS has
obtained the destination IP.
If it is DNS, then you really need to examine the config of your DNS
servers. Are they using root hints only for external names or have you
defined forwarders, etc.. What does the cache content look like now?
Reasonable, or is it poisoned with a number of false entries pointting to
those DNS servers? etc..

--
Roger Abell
Microsoft MVP (Windows Server System: Security)

"microsoft" <microsoft@discussions.microsoft.com> wrote in message
news:DC96C3D0-102C-4A23-A229-36133E37E316@microsoft.com...
> Hi
>
> I hope someone can help me.
>
> I have three domains in my network environment - Network A, Network B and
> Network C. Two domains are running Windows 2000 Server and the last is
> Windows 2003 Server. Each domain has its own Domain Controller. Domain C
> has two domain controllers. DNS is running within each domain and the Dns
> server for each network is itself. Each domain communicates with the
> other
> via a trust relationship. There is one DHCP server in the network
> allocating
> IP addresses to the client machines running Windows XP.
>
> My problem is as follows-
> I have a 256/512Kbps wireless internet connection and I noticed that our
> internet bandwidth has reduced significantly over the last couple of days.
> I
> used Ethereal to pinpoint which machine was hogging the bandwith.
> Ethereal
> results showed that the computer is querying www.cheaptickets.com for DNS
> information along with some other wierd sites. It is one of the Domain
> Controllers in Network C.
>
> I installed Microsft Antispyware to scan the machine for spyware but
> nothing
> was found. The Norton Virus defintions are up to date and it found no
> viruses when a scan was done. When I take this machine off the network
> the
> internet bandwidth returns to its normail behaviour. This machine is
> currently running Norton, Exchange 5.5 and Print services.
>
> What should be my next course of action to rectify this problem. The task
> manager does not show any unregular behavour within the Processes nor
> Performance tab.
>
> What could be causing my problem and what should I do to rectify the
> issue.
>
> PLEASE HELP.
>
> Regards