[DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.2], Saturday, Aug 06,2011 12:20:14
[DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.2],
Attacks happen during the evening but we work third shift so the internet isnt being used.. But on the weekends is when we are on.. and the attacks are happening as I am posting this message.
Here is a Link from when Patndoris was assisting me
http://www.bleepingcomputer.com/forums/topic408391.html
Fearing it was malware.
IF I Unplug the router i can see the IP address its coming from.
I have saved the info to my computer.
is It possible just to block their Mac address and these attacks will disappear?
Make and model of computer
Self built Intel Using Windows 7
How the computer is connected (wireless or wired)
Netgear wireless router with wpa alphanumeric encrypted password
Make and model of Router
Netgear N300 wireless WNR2000 v2
Approximate Distance From the router the PC is if its a wireless connection
less than a foot
What type of internet you have (Dsl, Cable, T-1,etc
Cable
MiniToolBox by Farbar
Ran by James (administrator) on 06-08-2011 at 18:23:37
Windows 7 Ultimate Service Pack 1 (X64)
***************************************************************************
========================= IE Proxy Settings: ==============================
Proxy is not enabled.
No Proxy Server is set.
========================= Hosts content: =================================
127.0.0.1 localhost
========================= IP Configuration: ================================
# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4
reset
set global icmpredirects=enabled
popd
# End of IPv4 configuration
Windows IP Configuration
Host Name . . . . . . . . . . . . : Nephel
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
Ethernet adapter Local Area Connection 2:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller #2
Physical Address. . . . . . . . . : 00-22-15-68-3A-97
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::b56d:8628:fb81:6b7c%12(Preferred)
IPv4 Address. . . . . . . . . . . : 192.168.1.9(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Lease Obtained. . . . . . . . . . : Saturday, August 06, 2011 4:20:38 PM
Lease Expires . . . . . . . . . . : Sunday, August 07, 2011 4:20:38 PM
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DHCPv6 IAID . . . . . . . . . . . : 352330261
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-15-0B-CA-99-00-22-15-68-3A-97
DNS Servers . . . . . . . . . . . : 192.168.1.1
NetBIOS over Tcpip. . . . . . . . : Enabled
Ethernet adapter Local Area Connection:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller
Physical Address. . . . . . . . . : 00-22-15-68-3A-96
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Server: UnKnown
Address: 192.168.1.1
Name: google.com
Addresses: 74.125.93.99
74.125.93.103
74.125.93.105
74.125.93.147
74.125.93.104
74.125.93.106
Pinging google.com [74.125.93.99] with 32 bytes of data:
Reply from 74.125.93.99: bytes=32 time=37ms TTL=49
Reply from 74.125.93.99: bytes=32 time=37ms TTL=49
Ping statistics for 74.125.93.99:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 37ms, Maximum = 37ms, Average = 37ms
Server: UnKnown
Address: 192.168.1.1
Name: yahoo.com
Addresses: 72.30.2.43
98.137.149.56
209.191.122.70
67.195.160.76
69.147.125.65
Pinging yahoo.com [69.147.125.65] with 32 bytes of data:
Reply from 69.147.125.65: bytes=32 time=31ms TTL=51
Reply from 69.147.125.65: bytes=32 time=30ms TTL=51
Ping statistics for 69.147.125.65:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 30ms, Maximum = 31ms, Average = 30ms
Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time=1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Ping statistics for 127.0.0.1:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 1ms, Average = 0ms
===========================================================================
Interface List
12...00 22 15 68 3a 97 ......Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller #2
11...00 22 15 68 3a 96 ......Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller
1...........................Software Loopback Interface 1
===========================================================================
IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.9 20
127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
192.168.1.0 255.255.255.0 On-link 192.168.1.9 276
192.168.1.9 255.255.255.255 On-link 192.168.1.9 276
192.168.1.255 255.255.255.255 On-link 192.168.1.9 276
224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 192.168.1.9 276
255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
255.255.255.255 255.255.255.255 On-link 192.168.1.9 276
===========================================================================
Persistent Routes:
None
IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
1 306 ::1/128 On-link
12 276 fe80::/64 On-link
12 276 fe80::b56d:8628:fb81:6b7c/128
On-link
1 306 ff00::/8 On-link
12 276 ff00::/8 On-link
===========================================================================
Persistent Routes:
None
========================= Event log errors: ===============================
Application errors:
==================
Error: (08/03/2011 07:05:30 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error: (07/31/2011 07:47:35 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.
The value "*" of attribute "language" in element "assemblyIdentity" is invalid.
Error: (07/31/2011 07:00:06 PM) (Source: Windows Backup) (User: )
Description: The backup did not complete because of an error writing to the backup location F:\. The error is: The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006).
Error: (07/26/2011 08:18:00 PM) (Source: Windows Backup) (User: )
Description: The backup did not complete because of an error writing to the backup location F:\. The error is: The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006).
Error: (07/23/2011 02:06:54 PM) (Source: Application Error) (User: )
Description: Faulting application name: CivilizationV_DX11.exe, version: 1.0.1.348, time stamp: 0x4e144f4e
Faulting module name: KERNELBASE.dll, version: 6.1.7601.17625, time stamp: 0x4de8781e
Exception code: 0x0000087a
Fault offset: 0x0000b9bc
Faulting process id: 0x123c
Faulting application start time: 0xCivilizationV_DX11.exe0
Faulting application path: CivilizationV_DX11.exe1
Faulting module path: CivilizationV_DX11.exe2
Report Id: CivilizationV_DX11.exe3
Error: (07/23/2011 01:05:44 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.
The value "*" of attribute "language" in element "assemblyIdentity" is invalid.
Error: (07/22/2011 03:08:16 PM) (Source: Application Error) (User: )
Description: Faulting application name: steam.exe, version: 1.0.968.628, time stamp: 0x4cda0db5
Faulting module name: ntdll.dll, version: 6.1.7601.17514, time stamp: 0x4ce7ba58
Exception code: 0xc0000005
Fault offset: 0x00038da9
Faulting process id: 0x364
Faulting application start time: 0xsteam.exe0
Faulting application path: steam.exe1
Faulting module path: steam.exe2
Report Id: steam.exe3
Error: (07/17/2011 07:00:07 PM) (Source: Windows Backup) (User: )
Description: The backup did not complete because of an error writing to the backup location F:\. The error is: The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006).
Error: (07/16/2011 06:32:31 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.
The value "*" of attribute "language" in element "assemblyIdentity" is invalid.
Error: (07/15/2011 10:39:40 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.
The value "*" of attribute "language" in element "assemblyIdentity" is invalid.
System errors:
=============
Error: (08/06/2011 05:52:37 PM) (Source: WMPNetworkSvc) (User: )
Description: WMPNetworkSvc0x80070422
Error: (08/06/2011 05:52:34 PM) (Source: WMPNetworkSvc) (User: )
Description: WMPNetworkSvc0x80070422
Error: (08/06/2011 04:23:06 PM) (Source: WMPNetworkSvc) (User: )
Description: WMPNetworkSvc0x80070422
Error: (08/06/2011 04:21:17 PM) (Source: WMPNetworkSvc) (User: )
Description: WMPNetworkSvc0x80070422
Error: (08/06/2011 04:21:11 PM) (Source: WMPNetworkSvc) (User: )
Description: WMPNetworkSvc0x80070422
Error: (08/06/2011 04:21:10 PM) (Source: WMPNetworkSvc) (User: )
Description: WMPNetworkSvc0x80070422
Error: (08/06/2011 04:20:39 PM) (Source: Service Control Manager) (User: )
Description: The MCSTRM service failed to start due to the following error:
%%2
Error: (08/06/2011 02:48:41 AM) (Source: WMPNetworkSvc) (User: )
Description: WMPNetworkSvc0x80070422
Error: (08/06/2011 02:46:43 AM) (Source: WMPNetworkSvc) (User: )
Description: WMPNetworkSvc0x80070422
Error: (08/06/2011 02:46:41 AM) (Source: WMPNetworkSvc) (User: )
Description: WMPNetworkSvc0x80070422
Microsoft Office Sessions:
=========================
Error: (08/03/2011 07:05:30 AM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe
Error: (07/31/2011 07:47:35 PM) (Source: SideBySide)(User: )
Description: assemblyIdentitylanguage*c:\program files (x86)\spybot - search & destroy\DelZip179.dllc:\program files (x86)\spybot - search & destroy\DelZip179.dll8
Error: (07/31/2011 07:00:06 PM) (Source: Windows Backup)(User: )
Description: F:\The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006)
Error: (07/26/2011 08:18:00 PM) (Source: Windows Backup)(User: )
Description: F:\The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006)
Error: (07/23/2011 02:06:54 PM) (Source: Application Error)(User: )
Description: CivilizationV_DX11.exe1.0.1.3484e144f4eKERNELBASE.dll6.1.7601.176254de8781e0000087a0000b9bc123c01cc495eb11deea6c:\program files (x86)\steam\steamapps\common\sid meier's civilization v\CivilizationV_DX11.exeC:\Windows\syswow64\KERNELBASE.dll8bc6962a-b556-11e0-9ee6-002215683a97
Error: (07/23/2011 01:05:44 PM) (Source: SideBySide)(User: )
Description: assemblyIdentitylanguage*c:\program files (x86)\spybot - search & destroy\DelZip179.dllc:\program files (x86)\spybot - search & destroy\DelZip179.dll8
Error: (07/22/2011 03:08:16 PM) (Source: Application Error)(User: )
Description: steam.exe1.0.968.6284cda0db5ntdll.dll6.1.7601.175144ce7ba58c000000500038da936401cc48a2281e1811C:\Program Files (x86)\Steam\steam.exeC:\Windows\SysWOW64\ntdll.dllf3faa326-b495-11e0-8f6c-002215683a97
Error: (07/17/2011 07:00:07 PM) (Source: Windows Backup)(User: )
Description: F:\The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006)
Error: (07/16/2011 06:32:31 PM) (Source: SideBySide)(User: )
Description: assemblyIdentitylanguage*c:\program files (x86)\spybot - search & destroy\DelZip179.dllc:\program files (x86)\spybot - search & destroy\DelZip179.dll8
Error: (07/15/2011 10:39:40 AM) (Source: SideBySide)(User: )
Description: assemblyIdentitylanguage*c:\program files (x86)\spybot - search & destroy\DelZip179.dllc:\program files (x86)\spybot - search & destroy\DelZip179.dll8
========================= Memory info: ===================================
Percentage of memory in use: 38%
Total physical RAM: 4095.12 MB
Available physical RAM: 2515.05 MB
Total Pagefile: 12093.31 MB
Available Pagefile: 10344.21 MB
Total Virtual: 4095.88 MB
Available Virtual: 3962.95 MB
========================= Partitions: =====================================
2 Drive c: () (Fixed) (Total:139.73 GB) (Free:14.8 GB) NTFS
========================= Users: ========================================
User accounts for \\NEPHEL
Administrator Guest James
UpdatusUser
== End of log ==
This post has been edited by Nephel: 06 August 2011 - 05:51 PM

Help

Back to top










