Hello everyone
Does anyone know how I can find out which process/service is executing a DNS query?
Background: I recently got PiHole and I noticed in the log that my PC makes the following DNS call every 2 minutes:
Apr 13 01:26:10 dnsmasq[485]: 473 192.168.1.131/59943 query[A] filecrypt.cc from 192.168.1.131
Apr 13 01:26:10 dnsmasq[485]: 473 192.168.1.131/59943 forwarded filecrypt.cc to 8.8.4.4
Apr 13 01:26:10 dnsmasq[485]: 473 192.168.1.131/59943 forwarded filecrypt.cc to 8.8.8.8.8
Apr 13 01:26:10 dnsmasq[485]: 473 192.168.1.131/59943 reply filecrypt.cc is 193.23.181.136
What I tried:
- first of all, I stopped all visible programs, services and irrelevant (user) processes):
- CMD => netstat -a -o =>
- Resource Manager + Task Manager =>
- Full scan with anti-malware bytes (no finds)
- Microsoft Network Monitor => The DNS call is logged, but without process.exe
I am really curious which service / process resolves filecrypt.cc every 2 minutes.
How could I proceed?
Kind regards
Co1m