Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 





Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Networking Forum > Security and Firewalls
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read

Security and Firewalls Protecting you against unwanted people and programs

Reply
 
Thread Tools
Old 09-23-2007, 02:01 PM   #1 (permalink)
Registered User
 
Overclocked Doc's Avatar
 
Join Date: Nov 2004
Posts: 204
OS: 2000/XP Pro


[SOLVED] Possible denial of service attack?

Not sure if this is where I should post this, but it appears to be close.

Is it possible I am expieriencing a "denial of service attack" on one of my machines on my home network?
The machine in questions appears to be sending out large packet amounts to 5 similar IPs all at one. The packet amounts are all the same amount. When this happens, no other machine on my network can access the net until the one in question is removed.

Checking the Ips, I noted on one day, they appeared to be directed to Russia. On another day they appeared to be directed to North America at what appears to be a legitimate business (paynet.no).

I have run virus and spyware scans using multiple software and even scanned the hard drive from another machine. I am quite well versed in dealing with a lot of this stuff but, this appears to have gotten the better of me. I really don't want to reformatt if possible, simply because of the time involved to reinstall all the 80 Gbs worth of software.

Does this scenario ring a bell with anyone?
Overclocked Doc is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 09-24-2007, 07:15 AM   #2 (permalink)
Manager, Networking Forums
 
johnwill's Avatar
 
Join Date: Sep 2002
Location: S.E. Pennsylvania, US
Posts: 31,468
OS: XP-Pro, Vista, Linux


Blog Entries: 1
Re: Possible "denial of service attack"?

Actually, this is not a DOS, which would be lots of traffic coming in. You appear to have malware that has taken over the machine and is using it for some purpose. Most likely, it's sending massive amounts of SPAM to us.

You are clearly infected, so I suggest...

Please follow this HJT Log 5 Step Process to post a HijackThis log in the HijackThis Log Help forum here.
__________________
If TSF has helped you, Tell us about it! or Donate to help keep the site up!

Microsoft MVP - Windows Desktop Experience
johnwill is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 09-26-2007, 01:30 PM   #3 (permalink)
Registered User
 
Overclocked Doc's Avatar
 
Join Date: Nov 2004
Posts: 204
OS: 2000/XP Pro


Re: Possible "denial of service attack"?

Thanks for your reply!

Yes I had my facts off slightly. I was infact expieriencing high volumes of traffic "outbpound" and not "inbound" as I had previously thought.

In reading several well written articles posted on the net, my symptoms closely matched that of a "zombie attack pc". I spoke to a friend who works as an internet security analyst and explained all the details.

He offered some insight on how to detemine what was happening in part by defining the ports being used to transfer information. Here's part of his reply back to me:

"I am familiar with botnets, zombies and Denial Of Service attacks.
A common scenario is that PCs that have been 'zombied' communicate with IRC servers to receive and carry out their orders.

In simple terms, the person in control sends out a command to an IRC channel "attack ip address x.x.x.x"
The infected PC's receives the command via IRC and carries out the order (send as much junk to that IP address as quick as possible).
A common port range for IRC is 6660-6669TCP so you may see your computer trying to connect out to the Internet on any of these ports if you have been zombied."

I have since remedied the problem although I inadvertanly deleted a few files containing info that would of helped me to better understand "what happened".
Overclocked Doc is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 09-27-2007, 08:03 AM   #4 (permalink)
Manager, Networking Forums
 
johnwill's Avatar
 
Join Date: Sep 2002
Location: S.E. Pennsylvania, US
Posts: 31,468
OS: XP-Pro, Vista, Linux


Blog Entries: 1
Re: Possible "denial of service attack"?

So, the issue is resolved?
__________________
If TSF has helped you, Tell us about it! or Donate to help keep the site up!

Microsoft MVP - Windows Desktop Experience
johnwill is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 09-27-2007, 01:38 PM   #5 (permalink)
Registered User
 
Overclocked Doc's Avatar
 
Join Date: Nov 2004
Posts: 204
OS: 2000/XP Pro


Re: Possible "denial of service attack"?

Yes it is thanks.
Overclocked Doc is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -7. The time now is 11:21 AM.



Copyright 2001 - 2008, Tech Support Forum

Search Engine Friendly URLs by vBSEO

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82