Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
General Security
Tag Cloud
access acer asus batch bios bsod computer crash desktop driver drivers error ethernet excel freeze gaming hard drive hardware hdmi internet laptop malware memory monitor motherboard mouse network operating system printer problem ram registry router slow software sound trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
Kernel: Intrusion

Reply  
Thread Tools
Mabusi's Avatar
Computer Specs
Junior Member with 5 posts.
 
Join Date: Jun 2008
Experience: Beginner
30-Jun-2008, 04:12 PM #1
Kernel: Intrusion
Hi

Lately something has been bothering me a bit. As soon as I play a MP3 I see a lot of activity on my Router. This seems to be quite consistent. This made me a bit suspicius so I went and checked my router ( DSL-2500U ) 's activity log. I'm getting quite a bit of the following alerts:

Kernel: Intrusion - IN = ppp_8_35_1 OUT = MAC =
SRC = 41.247.98.27 DST = 41.247.178.91 LEN .....

I'm not to sure what to make of this. Could it be farfetched to think that as soon as I play an MP3, It spews it out somewhere or am I just being a bit paranoid. Somebody did do some work on my computer a while ago and I was not present.
lotuseclat79's Avatar
Distinguished Member with 21,345 posts.
 
Join Date: Sep 2003
Location: -71.45091, 42.27841
01-Jul-2008, 10:48 AM #2
Hi Mabusi,

Welcome to TSG!

When you first connected your system together, did you change the default router admin password? This is often overlooked by many, and is a vector of attack for malware. The default admin passwords are posted on the Internet.

That is one change you should make.

After making the change, I suggest you visit the Kaspersky.com web site and let them do a full free virus scan of your system over the Internet for malware. Trendmicro.com is another full scan web site. I would certainly let both do a full scan of my system in your situation.

At the very worst case, you may need to do a full reinstallation of Vista, and hope that your BIOS chip is not compromised (in which case, you would need a new BIOS chip).

Note: Vista has good inbound firewall (software) protection, but no outbound firewall protection (by which a miscreant would "phone home" with compromising information from your system). Suggest you get ZoneAlarm Free software firewall for outbound protection. Other firewalls a also very good for outbound protection, but require payment.

-- Tom
__________________
The independence created by philosophical insight is - in my opinion - the mark of distinction
between a mere artisan or specialist and a real seeker after truth. - Einstein 1944
Imagination is more important than knowledge. - Einstein
Mabusi's Avatar
Computer Specs
Junior Member with 5 posts.
 
Join Date: Jun 2008
Experience: Beginner
01-Jul-2008, 12:11 PM #3
Intrusion
Hi

I have changed all my passwords, Router's and Computer's after the installation.

Also did a "Deep System Scan" with BitDefender just recently, but it didn't come up with any surprises.
TechOutsider's Avatar
Computer Specs
Account Disabled with 303 posts.
 
Join Date: Jun 2008
Location: Florida
Experience: Advanced
01-Jul-2008, 12:44 PM #4
It could just be an annoying neighbor.
Mabusi's Avatar
Computer Specs
Junior Member with 5 posts.
 
Join Date: Jun 2008
Experience: Beginner
01-Jul-2008, 01:08 PM #5
Hi

What about a "System Restore" to a point before I made the internet connection??

Mabusi
lotuseclat79's Avatar
Distinguished Member with 21,345 posts.
 
Join Date: Sep 2003
Location: -71.45091, 42.27841
01-Jul-2008, 02:38 PM #6
Sounds like it is worth a shot, if you are confident with System Restores.

-- Tom
Mabusi's Avatar
Computer Specs
Junior Member with 5 posts.
 
Join Date: Jun 2008
Experience: Beginner
02-Jul-2008, 03:59 PM #7
Hi

"System Restore" seems to be out of the question. I cant go that far back ( about 6 months ). Furthermore I did a scan at "Kaspersky.com" and it didn't come up with anything. Also tried "TrendMicro.com" but this site gave me a bit of a problem , maybe "Housecall" does not support Vista ?

So now maybe a OS Re-installation ? Only problem is, I did not get my
"Windows Vista Home Basic" on a CD with my system . What now?
Mabusi's Avatar
Computer Specs
Junior Member with 5 posts.
 
Join Date: Jun 2008
Experience: Beginner
02-Jul-2008, 05:57 PM #8
Hi

Looking at my router's log file I noticed something else now : The "Kernel : Intrusion ...." message I've been getting seems to come up every 10min &
18secs. Quite consistently. So I dont know wether there is any link between that and the activity on my router everytime when I play a MP3.

So instead of one problem it looks like I've got 2. There is not perhaps a way of capturing the data to see what the router is actually sending/
receiving at that point in time when I play the MP3?
lunarlander's Avatar
Computer Specs
Senior Member with 3,491 posts.
 
Join Date: Sep 2007
03-Jul-2008, 06:06 PM #9
Microsoft has a free network sniffer.

http://www.microsoft.com/downloads/d...DisplayLang=en
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 10:32 PM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.