There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
 
Tag Cloud
access audio avg avg 8 bios blue screen boot bsod computer connection cpu crash css dell desktop dma driver drivers dvd email error excel explorer firefox firefox 3 freeze gimp graphics hard drive hardware hijackthis hjt install internet internet explorer itunes keyboard laptop macro malware monitor motherboard network networking outlook outlook 2003 outlook 2007 outlook express pio problem problems router seo server slow sound sp3 spyware trojan usb video virtumonde virus vista vundo windows windows vista windows xp winxp wireless
General Security
Search
Search in:
 
Advanced Search
Tech Support Guy Forums > Security & Malware Removal > General Security >
Kernel: Intrusion


HELLO AND WELCOME! Before you can post your question, you'll have to register -- it's completely free! Click here to join today! We highly recommend that you print a copy of our Guide for New Members. Enjoy!

 
Thread Tools
Mabusi's Avatar
Computer Specs
Junior Member with 5 posts.
 
Join Date: Jun 2008
Experience: Beginner
30-Jun-2008, 03:12 PM #1
Kernel: Intrusion
Hi

Lately something has been bothering me a bit. As soon as I play a MP3 I see a lot of activity on my Router. This seems to be quite consistent. This made me a bit suspicius so I went and checked my router ( DSL-2500U ) 's activity log. I'm getting quite a bit of the following alerts:

Kernel: Intrusion - IN = ppp_8_35_1 OUT = MAC =
SRC = 41.247.98.27 DST = 41.247.178.91 LEN .....

I'm not to sure what to make of this. Could it be farfetched to think that as soon as I play an MP3, It spews it out somewhere or am I just being a bit paranoid. Somebody did do some work on my computer a while ago and I was not present.
lotuseclat79's Avatar
Distinguished Member with 10,037 posts.
 
Join Date: Sep 2003
Location: -71.45091, 42.27841
01-Jul-2008, 09:48 AM #2
Hi Mabusi,

Welcome to TSG!

When you first connected your system together, did you change the default router admin password? This is often overlooked by many, and is a vector of attack for malware. The default admin passwords are posted on the Internet.

That is one change you should make.

After making the change, I suggest you visit the Kaspersky.com web site and let them do a full free virus scan of your system over the Internet for malware. Trendmicro.com is another full scan web site. I would certainly let both do a full scan of my system in your situation.

At the very worst case, you may need to do a full reinstallation of Vista, and hope that your BIOS chip is not compromised (in which case, you would need a new BIOS chip).

Note: Vista has good inbound firewall (software) protection, but no outbound firewall protection (by which a miscreant would "phone home" with compromising information from your system). Suggest you get ZoneAlarm Free software firewall for outbound protection. Other firewalls a also very good for outbound protection, but require payment.

-- Tom
__________________
The independence created by philosophical insight is - in my opinion - the mark of distinction between a mere artisan or specialist and a real seeker after truth. - Einstein wrote in 1944.

Some say knowledge is power, I say knowledge without action is powerless. - lotuseclat79

Don't confuse action with movement. - Hemingway to Gardner

Imagination is more important than knowledge. - Einstein
Mabusi's Avatar
Computer Specs
Junior Member with 5 posts.
 
Join Date: Jun 2008
Experience: Beginner
01-Jul-2008, 11:11 AM #3
Intrusion
Hi

I have changed all my passwords, Router's and Computer's after the installation.

Also did a "Deep System Scan" with BitDefender just recently, but it didn't come up with any surprises.
TechOutsider's Avatar
Computer Specs
Account Disabled with 303 posts.
 
Join Date: Jun 2008
Location: Florida
Experience: Advanced
01-Jul-2008, 11:44 AM #4
It could just be an annoying neighbor.
Mabusi's Avatar
Computer Specs
Junior Member with 5 posts.
 
Join Date: Jun 2008
Experience: Beginner
01-Jul-2008, 12:08 PM #5
Hi

What about a "System Restore" to a point before I made the internet connection??

Mabusi
lotuseclat79's Avatar
Distinguished Member with 10,037 posts.
 
Join Date: Sep 2003
Location: -71.45091, 42.27841
01-Jul-2008, 01:38 PM #6
Sounds like it is worth a shot, if you are confident with System Restores.

-- Tom
Mabusi's Avatar
Computer Specs
Junior Member with 5 posts.
 
Join Date: Jun 2008
Experience: Beginner
02-Jul-2008, 02:59 PM #7
Hi

"System Restore" seems to be out of the question. I cant go that far back ( about 6 months ). Furthermore I did a scan at "Kaspersky.com" and it didn't come up with anything. Also tried "TrendMicro.com" but this site gave me a bit of a problem , maybe "Housecall" does not support Vista ?

So now maybe a OS Re-installation ? Only problem is, I did not get my
"Windows Vista Home Basic" on a CD with my system . What now?
Mabusi's Avatar
Computer Specs
Junior Member with 5 posts.
 
Join Date: Jun 2008
Experience: Beginner
02-Jul-2008, 04:57 PM #8
Hi

Looking at my router's log file I noticed something else now : The "Kernel : Intrusion ...." message I've been getting seems to come up every 10min &
18secs. Quite consistently. So I dont know wether there is any link between that and the activity on my router everytime when I play a MP3.

So instead of one problem it looks like I've got 2. There is not perhaps a way of capturing the data to see what the router is actually sending/
receiving at that point in time when I play the MP3?
lunarlander's Avatar
Computer Specs
Senior Member with 463 posts.
 
Join Date: Feb 2008
03-Jul-2008, 05:06 PM #9
Microsoft has a free network sniffer.

http://www.microsoft.com/downloads/d...DisplayLang=en
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are Off
Refbacks are Off

You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 07:16 AM.
Copyright © 1996 - 2008 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Powered by Cermak Technologies, Inc.