Author Topic: Some PUM DNS entries detected, anything to worry about?  (Read 3886 times)

0 Members and 1 Guest are viewing this topic.

January 31, 2016, 07:57:17 PM

JukkaG

  • Newbie

  • Offline
  • *

  • 9
  • Reputation:
    0
    • View Profile
Some PUM DNS entries detected, anything to worry about?
« on: January 31, 2016, 07:57:17 PM »
So I got some PUM DNS entries while doing regular scans (so there have been no symptoms or anything, I just scan regularly to be sure). Log attached, I guess that they are just some false positives but it still would be nice if you could comment on them just to be certain.

"registry": [
            {
                "scan_what": 1,
                "scan_how": [
                    11
                ],
                "scan_how_trigger": 11,
                "vendors": [
                    "PUM.Dns"
                ],
                "rule_name": "DNS",
                "view": 256,
                "value": "DhcpNameServer",
                "subkey": "",
                "value_old_data": "",
                "value_data": "172.20.10.1",
                "path": "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\Tcpip\\Parameters\\Interfaces\\{2f726e50-cd41-448e-81eb-c57027f22000}",
                "extra": "[X]",
                "files_status": "",
                "vtscore": -1,
                "files": [],
                "status_str": "Found",
                "status_choice": 1,
                "status_removed": 0
            },
            {
                "scan_what": 1,
                "scan_how": [
                    11
                ],
                "scan_how_trigger": 11,
                "vendors": [
                    "PUM.Dns"
                ],
                "rule_name": "DNS",
                "view": 256,
                "value": "DhcpNameServer",
                "subkey": "",
                "value_old_data": "",
                "value_data": "172.20.10.1",
                "path": "HKEY_LOCAL_MACHINE\\System\\ControlSet001\\Services\\Tcpip\\Parameters\\Interfaces\\{2f726e50-cd41-448e-81eb-c57027f22000}",
                "extra": "[X]",
                "files_status": "",
                "vtscore": -1,
                "files": [],
                "status_str": "Found",
                "status_choice": 1,
                "status_removed": 0

Reply #1February 01, 2016, 11:59:10 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: Some PUM DNS entries detected, anything to worry about?
« Reply #1 on: February 01, 2016, 11:59:10 PM »
Hi JukkaG,

These entries are legit.

Regards.