Trouble I think. Windows 7 Ultimate Service Pack 1 (x64) with all recommended and critical updates applied. I regularly run Malwarebytes Pro and Bitdefender 2014 is on 24x7.
Please notice the "badguy.ipaddress.in.dot.notation. IP is on another continent in a country famous for bad guy hackers, great beer and starting world wars. The IP address does not reverse to a name. The "route print" command does NOT show this added route.
The 169.254.0.0 address is explained here
. I have a static IP address though a DCHP server is running on my router/firewall. (DD-WRT v24-sp2).
Is my outgoing traffic being redirected to the bad guys IP address and I have a "man in the middle"? How can I remove the added route. I DO NOT have a known good system checkpoint. Is this an attack and should I do a scratch re-install? I am also running NetBalancer
Relevant portion of MiniToolBox.exe's Result.txt follows:
# IPv4 Configuration
pushd interface ipv4
set global icmpredirects=enabled sourceroutingbehavior=drop
add route prefix=169.254.0.0/16 interface="iftype0_0" nexthop=badguy.ipaddress.in.dot.notation metric=1 publish=Yes
add route prefix=169.254.0.0/16 interface="iftype0_0" nexthop=192.168.???.??? metric=1 publish=Yes
add route prefix=0.0.0.0/0 interface="Local Area Connection 2" nexthop=192.168.1.1 publish=Yes
set interface interface="Local Area Connection 2" forwarding=disabled advertise=disabled metric=4 siteprefixlength=0 nud=disabled routerdiscovery=disabled managedaddress=disabled otherstateful=disabled weakhostsend=disabled weakhostreceive=disabled ignoredefaultroutes=disabled advertisedrouterlifetime=0 advertisedefaultroute=disabled currenthoplimit=0 forcearpndwolpattern=disabled enabledirectedmacwolpattern=disabled
add address name="Local Area Connection* 6-QoS Packet Scheduler-0000" address=192.168.108.1 mask=255.255.255.0
add address name="Local Area Connection* 9-QoS Packet Scheduler-0000" address=192.168.23.1 mask=255.255.255.0
add address name="Local Area Connection 2" address=192.168.1.68 mask=255.255.255.0
# End of IPv4 configuration
Thanks for any help.