Hello,
We just got back, and went online... only to discover that nothing was working. After checking with the network diagnostics tool I found that the DNS Server was down. After a few minutes stuff started working again. However, they are reactivating at different times for different computers for the same websites (Yahoo is now working on one computer...). I was wondering if anyone can tell me if this could be a virus... I do have the router logs here.
System log:
1970-01-01 00:00:14-WAN DHCP Client Connected IP 72.133.53.11
2010-02-16 16:37:26-192.168.2.13 logout
2010-02-16 16:37:32-192.168.2.13 login
2010-02-16 18:50:25-192.168.2.13 logout
2010-02-16 18:50:32-192.168.2.13 login
2010-02-18 17:39:54-192.168.2.13 logout
2010-02-18 17:39:59-192.168.2.13 login
2010-02-18 17:41:19-WAN DHCP Client Connected IP 72.133.53.11
DoS log:
2010-02-18 10:24:02 [TCP Stealth FIN Port Scan] (TCP) WAN to LAN 66.135.202.211:80->72.133.53.11:33667 [Drop]
2010-02-18 10:24:02 [TCP SYN Flood] (TCP) LAN to WAN 192.168.2.13:56250->66.135.200.11:80 [Drop]
2010-02-18 10:24:02 [HOST Attack: TCP SYN Flood] (TCP) LAN to WAN 192.168.2.13:56252->98.27.88.96:80 [Drop]
2010-02-18 10:24:02 [HOST Attack: TCP Stealth FIN Port Scan] (TCP) LAN to WAN 192.168.2.13:56197->66.135.202.211:80 [Drop]
2010-02-18 10:24:05 [TCP SYN Flood] (TCP) WAN to LAN 66.135.200.11:80->72.133.53.11:34199 [Drop]
2010-02-18 10:24:28 [TCP SYN Flood] (TCP) WAN to LAN 198.104.150.202:80->72.133.53.11:33554 [Drop]
2010-02-18 10:24:30 [TCP Stealth FIN Port Scan] (TCP) WAN to LAN 74.125.113.95:80->72.133.53.11:33137 [Drop]
2010-02-18 10:24:34 [UDP Flood] (UDP) LAN to WAN 192.168.2.2:56668->192.168.2.1:53 [Drop]
2010-02-18 10:24:40 [TCP Stealth FIN Port Scan] (TCP) LAN to WAN 192.168.2.13:56504->208.82.236.208:80 [Drop]
2010-02-18 10:24:42 [TCP SYN Flood] (TCP) WAN to LAN 208.82.236.208:80->72.133.53.11:32929 [Drop]
2010-02-18 10:24:42 [TCP Stealth FIN Port Scan] (TCP) WAN to LAN 208.82.236.208:80->72.133.53.11:32933 [Drop]
2010-02-18 10:26:13 [UDP Flood] (UDP) LAN to WAN 192.168.2.13:52168->192.168.2.1:53 [Drop]
2010-02-18 10:26:14 [HOST Attack: TCP Stealth FIN Port Scan] (TCP) LAN to WAN 192.168.2.13:56999->98.27.88.24:80 [Drop]
2010-02-18 10:26:14 [TCP Stealth FIN Port Scan] (TCP) WAN to LAN 74.125.115.100:80->72.133.53.11:33069 [Drop]
2010-02-18 10:34:33 [UDP Flood] (UDP) WAN to LAN 209.18.47.61:53->72.133.53.11:2054 [Drop]
2010-02-18 10:45:56 [UDP Flood] (UDP) WAN to LAN 209.18.47.62:53->72.133.53.11:2054 [Drop]
2010-02-18 10:50:49 [TCP Stealth FIN Port Scan] (TCP) WAN to LAN 76.12.31.5:80->72.133.53.11:33493 [Drop]
2010-02-18 17:44:01 [UDP Flood] (UDP) LAN to WAN 192.168.2.13:49184->192.168.2.1:53 [Drop]
2010-02-18 17:44:03 [UDP Flood] (UDP) WAN to LAN 209.18.47.61:53->72.133.53.11:2057 [Drop]
2010-02-18 17:44:04 [UDP Flood] (UDP) LAN to WAN 192.168.2.13:59925->192.168.2.1:53 [Drop]
2010-02-18 17:44:42 [TCP Stealth FIN Port Scan] (TCP) LAN to WAN 192.168.2.13:57684->208.82.236.208:80 [Drop]
2010-02-18 17:44:44 [TCP SYN Flood] (TCP) WAN to LAN 208.82.236.208:80->72.133.53.11:33300 [Drop]
2010-02-18 17:44:44 [TCP Stealth FIN Port Scan] (TCP) WAN to LAN 208.82.236.208:80->72.133.53.11:33304 [Drop]
2010-02-18 17:44:52 [TCP Stealth FIN Port Scan] (TCP) WAN to LAN 208.82.236.208:80->72.133.53.11:32872 [Drop]
2010-02-18 2010-02-18 17:44:55 [TCP Stealth FIN Port Scan] (TCP) WAN to LAN 208.82.236.208:80->72.133.53.11:33700 [Drop]
2010-02-18 17:44:55 [TCP SYN Flood] (TCP) WAN to LAN 92.61.248.118:80->72.133.53.11:33110 [Drop]
2010-02-18 17:44:55 [HOST Attack: TCP Stealth FIN Port Scan] (TCP) WAN to LAN 208.82.236.208:80->72.133.53.11:33723 [Drop]
2010-02-18 17:44:57 [TCP Stealth FIN Port Scan] (TCP) WAN to LAN 208.82.236.208:80->72.133.53.11:33483 [Drop]
2010-02-18 17:47:09 [TCP SYN Flood] (TCP) WAN to LAN 208.82.236.208:80->72.133.53.11:32915 [Drop]
New Connection log:
2010-02-18 17:56:44 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.2.13:58679->209.62.87.140:80 [Forward]
2010-02-18 17:56:45 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.2.13:58680->64.94.107.15:80 [Forward]
2010-02-18 17:56:50 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.2.13:58681->209.62.87.157:80 [Forward]
2010-02-18 17:56:50 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.2.13:58682->209.62.87.157:80 [Forward]
2010-02-18 17:56:51 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.2.13:58683->209.62.87.157:80 [Forward]
2010-02-18 17:56:52 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.2.13:58684->209.62.87.157:80 [Forward]
2010-02-18 17:56:52 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.2.13:58685->74.63.52.167:80 [Forward]
2010-02-18 17:56:52 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.2.13:58686->74.63.52.167:80 [Forward]
2010-02-18 17:56:52 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.2.13:58687->74.63.52.167:80 [Forward]
2010-02-18 17:56:52 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.2.13:58688->74.63.52.167:80 [Forward]
2010-02-18 17:56:52 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.2.13:58689->74.63.52.167:80 [Forward]
2010-02-18 17:56:52 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.2.13:58690->209.62.87.140:80 [Forward]
2010-02-18 17:56:52 [New TCP 2010-02-18 17:56:52 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.2.13:58692->209.62.87.140:80 [Forward]
2010-02-18 17:56:52 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.2.13:58693->209.62.87.140:80 [Forward]
2010-02-18 17:56:52 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.2.13:58694->209.62.87.140:80 [Forward]
2010-02-18 17:56:52 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.2.13:58695->209.62.87.140:80 [Forward]
2010-02-18 17:56:52 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.2.13:58696->208.122.28.29:80 [Forward]
2010-02-18 17:56:52 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.2.13:58697->64.94.107.15:80 [Forward]
2010-02-18 17:57:02 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.2.13:58698->198.104.150.202:80 [Forward]
2010-02-18 17:57:02 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.2.13:58699->198.104.150.202:80 [Forward]
2010-02-18 17:57:03 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.2.13:58700->74.125.115.95:80 [Forward]
2010-02-18 17:57:04 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.2.13:58701->74.125.115.95:80 [Forward]
2010-02-18 17:57:04 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.2.13:58702->74.125.115.95:80 [Forward]
2010-02-18 17:57:04 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.2.13:58703->74.125.115.95:80 [Forward]
2010-02-18 17:57:04 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.2.13:58704->74.125.115.95:80 [Forward]
2010-02-18 17:57:18 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.2.6:54233->17.149.36.221:5223 [Forward]
2010-02-18 17:57:41 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.2.13:58705->74.125.91.102:80 [Forward]
2010-02-18 17:57:52 [New TCP Outbound Flow] (TCP) LAN to WAN 192.168.2.13:58706->74.125.115.95:80 [Forward]
|