Posted 17 March 2007 - 09:48 AM
Hello well, I'm a little confused as to which information you want to me to display as apart of the log but here goes:
About every ten seconds for the 10minutes the following has been coming up:
This is from my firewall log, alert type: firewall
Rating: Medium, Date time: see above, Type: firewall, program: /, Protocol: TCP (flags s), Source IP: lots of different ones, Destination IP: My IP with a port number at the end (uTorrents port), Direction: Incoming, Action taken: Blocked, Source DNS: persons Ip with ISP name (lots of different IP's), Destination dns: our computer name.
Before that about an hour before the above the following was happening:
Four of the followings popped up:
Rating: Medium, Date: irrelevant, Type: Firewall, Protocol: UDP, Program: some were svchost.exe some were blank, Source IP: mainly different one or two re-curing, Destination IP: Some same and some different, Direction: Outgoing, Action taken: Blocked, Source DNS: Our computer name, one is uTorrent.com
This is from my firewall log, alert type: programs
For about 13m, 35 times per minute the following was logged:
Rating: Some high some medium, Type: Repeat program or Program access some repeat server program, Program: uTorrent.exe and some C:/Program Files/uTorrent/uTorrent.exe, Source IP: /, Destanation IP: lots of different ones, Direction: outgoing (connect) some outgoing (listening), action taken: some blocked some allowed, Source DNS: different IP's with theor PSP at the end of them:
Then before this pattern there was a pattern that lasted for 5 hours, several times per minute the following was logged:
Rating: High, Type: Program access, Program: svchost.exe, Source IP: Three alternating IP's, Destanation IP: /, Direction: Incoming (listen), Action taken: blocked, Source DNS: My Ip's webiste and others say ns4.on.net
One las t pattern I will display is:
This one goes for an hour and a half, being logged every two seconds:
Rating high, Type: program access, Program: avgas.exe, Source IP: /, Destnation IP: Three alternating IP's, Direction: Outgoing (connect), Action taken: Blocked, Source IP, /, Destanation SNS: some blank some ns4.on.net
Also my computer switched off while of was seeding in uTorrent again.
Thank you, help greatly appreciated.