Solved

Weird errors in my System log (event id 1014)?

Posted on 2014-10-06
3
4,370 Views
1 Endorsement
Last Modified: 2014-10-10
I've found some 'DNS Client Events' errors in my event viewer, relating to weird websites ...

Name resolution for the name www.kocca.kr timed out after none of the configured DNS servers responded.
Name resolution for the name www.pillowsopher.com timed out after none of the configured DNS servers responded.
Name resolution for the name www.spod-central.org timed out after none of the configured DNS servers responded.

I've never consciously attempted to access those sites ... sounds spammy/trojany? But my McAfee hasn't reported anything weird ...

What's weird though too is that the DNS servers haven't responded in the first place!

Any help is appreciated
1
Comment
Question by:Xeronimo
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 28

Expert Comment

by:Dan McFadden
ID: 40363632
It is most likely that an application on your computer that tried to query these domains and the DNS client is reporting that no DNS servers responded to the query.

You can interpret that as saying no one could resolve a DNS query for records in the listed domains.

Dan
0
 

Author Comment

by:Xeronimo
ID: 40363712
Ok, so that leaves me with two questions (of a very different kind):

- which programs are making these 'calls'??
- why aren't the DNS servers constantly reachable?
0
 
LVL 28

Accepted Solution

by:
Dan McFadden earned 500 total points
ID: 40363749
#1. you will have to monitor activity of the applications on this computer to determine that.

there are some great tools for doing this in the SysInternal Suite from Microsoft.  TCPView, Process Explorer, Process Monitor, to name a few.  You could also install WireShark and monitor the computer's network traffic.

Link:  http://technet.microsoft.com/en-us/sysinternals/bb842062.aspx

#2. it is not that the DNS servers are not reachable, its that no DNS server was found that can answer a query for records under that domain.  this event is normal.  it is not an indication of a configuration failure.

If you were to use an online nslookup web site, you could see if device outside your network can get an answer for those domains.  I looked up "www.pillowsopher.com" and an online nslookup site reported that the DNS server responsible for the domain was returning an error.  Meaning that it may be an issue in that website's hosting provider.

You can also research these domains by doing a WhoIs query at a registrar.

For example, go here:  http://www.networksolutions.com/whois/index.jsp

enter the domain name, no www, and click search.

Dan
0

Featured Post

Free NetCrunch network monitor licenses!

Only on Experts-Exchange: Sign-up for a free-trial and we'll send you your permanent license!

Here is what you get: 30 Nodes | Unlimited Sensors | No Time Restrictions | Absolutely FREE!

Act now. This offer ends July 14, 2017.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Always backup Domain, SYSVOL etc.using processes according to Microsoft Best Practices. This is meant as a disaster recovery process for small environments that did not implement backup processes and did not run a secondary domain controller that ne…
Auditing domain password hashes is a commonly overlooked but critical requirement to ensuring secure passwords practices are followed. Methods exist to extract hashes directly for a live domain however this article describes a process to extract u…
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question