Incoming ARP flood

Q: Incoming ARP flood

Hi, techguys!

I need help with the following problem. I'm on a LAN provided by my ISP, but the LAN is very hostile (when I first connected two years ago, I got hacked within something like 15 minutes). I have closed all my ports by disabling all kinds of Windows XP services (Home) and I installed Jetico Firewall, which I think is really good. I log everything, allowed and blocked traffic.

Jetico allows one to see ARP packets going out and coming in. And that's where my problem lies: Almost nothing goes out, but every second, I get about 8 ARP packets! That seems like very much. No addresses on this LAN are trusted. I have disabled NetBIOS and even uninstalled Microsoft Client from the Internet Connection.

I was wondering if there is a way to somehow regulate this traffic. I've tried blocking the packets, but the Internet connection went dead.
Isn't there a way to limit this traffic? Maybe by hardcoring the gateway's and DNS servers' MAC addresses? If yes, how do I do that?
In the command line it says that my gateway MAC is dynamic. Does that mean I have no control over this crazy stuff?
And how can I determine the MAC of my DNS servers?

I have Ethereal installed, but I have no idea whatsoever what to do with it besides watching all those packets come in. I was alarmed by the administrator of firewallleaktester[dot]com that when I registered there for the mailing list, his logs showed some specially crafted packets that 'could only be the result of a deliberate hacking attempt'. I checked my computer with all kinds of anti-this and anti-that. My computer seems to be perfectly clean.

D-Link DFE-530TX PCI Fast Ethernet Adapter (rev.C) Fast Ethernet connection with limited speed but unlimited traffic.
Windows XP SP2 (licensed and up-to-date) configured in accordance with the CIS benchmark recommendations
AMD Athlon 2004+

Paul Wynant
Moscow, Russia

A: Incoming ARP flood

im having
syn flood ,
tcp udp basedportscan
lan-side udp flood,
ip fragmented packet
how do i stop this where its comming from,
my internet become verry verry verry slow normal i can download at 7mb's now im downloading at 43 kb/s! on steam.
my connections randomly stops working
after i click on fix this connetion my pc is freeze i need to force shutdown and reboot.
can someone help me avoid and fix those problems pls

A:Syn flood lan-side udp flood etc requesting fix

If I were to make a guess as to the problem I'd say you have been infected with some malware.
What security software is installed and current?
Have you run any scans with it or any of the other available free scanners?
Keep us posted

My husband and employer both sent me an email that shows the correct date in the email time line, but Outlook shows a recieve date of April 2008.

It doesn't happen on every email, just some. We've all checked our clock dates and their correct. Talked to my Internet Service Provider and they said it was an Outlook problem.

Any ideas?


A:Incoming email randomly shows incoming date 04/08

Hi helpcook, you dont mention what version of Outlook you are running but this link is the same for most versions http://support.microsoft.com/kb/q197717/ Also check Windows control panel>date & time>time zone. Make sure all is correct.

just wondering if anyone has any information about a "TCP SYN Flood" and how I could get rid of what-ever is infecting on my computer, I am running windows XP and I am running Blackice firewall.

I un-installed norton's antivirus thinking that could be the problem but it isn't the problem is still there. I ran a scan of my computer but it pulled up no virus's.

I will post what services I have running later as I'm at work atm.

TIME: 228h 12m UPLOADED:1115.54 MB DOWNLOADED:359.81 MB from
18 May 2004 to Thursday, 17 June 2004


UDP from to local port 51106 Denied: Scan.Generic.UDP 9/2/2012 12:42:44 PM
UDP from to local port 53007 Denied: Scan.Generic.UDP 9/2/2012 12:41:36 PM
UDP from to local port 8113 Denied: Scan.Generic.UDP 9/2/2012 12:41:23 PM
UDP from to local port 50242 Denied: Scan.Generic.UDP 9/2/2012 12:41:18 PM
UDP from to local port 4067 Denied: Scan.Generic.UDP 9/2/2012 12:40:19 PM
UDP from to local port 22152 Denied: Scan.Generic.UDP 9/2/2012 12:39:17 PM
UDP from to local port 41211 Denied: Scan.Generic.UDP 9/2/2012 12:39:14 PM
UDP from to local port 9685 Denied: Scan.Generic.UDP 9/2/2012 12:38:43 PM
UDP from to local port 9482 Denied: Scan.Generic.UDP 9/2/2012 12:37:53 PM
UDP from to local port 25854 Denied: Scan.Generic.UDP 9/2/2012 12:37:15 PM
UDP from to local port 62762 Denied: Scan.Generic.UDP 9/2/2012 12:37:01 PM
UDP from to local port 23675 Denied: Scan.Generic.UDP 9/2/2012 12:36:16 PM
UDP from to local port 65491 Denied: Scan.Generic.UDP 9/2/2012 12:35:44 PM
UDP from to local port 25628 Denied: Scan.Generic.UDP 9/2/2012 12:35:14 PM
UDP from to local port 23788 Denied: Scan.Generic.UDP 9/2/2012 12:34:14 PM
UDP from to local port 59875 Denied: Scan.Generic.UDP 9/2/2012 12:33:44 PM
UDP from to local port 14495 Denied: Scan.Generic.UDP 9/2/2012 ... Read more

hi, i scanned my computer w/ mcAfee and it picked up the trojan IRC/Flood.dz and will not take it out of my computer. How can I manually remove the trojan?



Search your file for porno.exe and delete it
Search for and delete explorere.exe
Delete any of these that appear on your computer:

Run HijackThis and click Do a system scan and save a log file
Your HijackThis log will open in Notepad. Post the contents of the log here


Q: Flood

Samsung 40 gb hdd was is water for 2-3 days due to flood

no its not getting detected

i tried by changing controller card but no use
is there any way to recover data


New Member here - I have tried to solve this problem via internet search and my own uninformed efforts - without much luck.-- Hoping someone here can help me. If this isnt the right forum for this question please advise. I have had a home network with a older Belkin router serving 2 wireless PC's (family) and one wired (my main PC). Am using standard DHCP modes etc .Some time ago we started experiencing occasional strange outages on the PC's for which I had no good explanation -- IE would just quit working for no obvious reason and the PC would need to be rebooted etc to get IE browser connections. Shortly thereafter my son's PC obviously became infected ( Happy 888 plus other gremlins) - which got me seriously involved with finding out what was going wrong. I have cleaned all 3 PC's using all the usual cleaners and HJT, while keeping the wireless PC's offline. This is when I was able to catch the current problem ( I think) on my wired PC [WinXP S1A]. Whatever the problem, it has been shutting down the IE connection about once a day. After a recent shutdown I looked at the security log of the router and this is what it revealed: (xxx.xxx. my revision)

2007/05/23 12:13:09 ** TCP SYN Flooding ** <IP/TCP> ->> 76.187.xxx.xxx:46029
2007/05/23 12:14:18 ** TCP SYN Flooding ** <IP/TCP> ->>
2007/05/23 12:14:49 ** TCP SYN Flooding ** <IP/TCP> ->> 199.203... Read more

A:TCP SYN FLOOD? I need help.

My laptop (Dell Vostro 1500, XP) started freezing up yesterday and my AV began to notify me of all sorts of malware. I ran Spybot S&D in safe mode, and then again at start up - it caught a whole series of infections and supposedly fixed them. I ran it again and it detected no threats, but AV continues to note threats and there are all sorts of weird processes popping up on my task manager (odbnsy.exe, usr_.exe, etc.).

Help would be much appreciated!

Tried to run an HJT log after normal startup, but it keeps freezing up before completing. Here is an HJT log from safe mode:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:26:44 AM, on 2010-03-24
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode

Running processes:
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
c:\documents and settings\philbo\rundll32 .exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1071023
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
R1 - HKCU\Softw... Read more

A:Flood of Malware

Logfile of HijackThis v1.99.1Scan saved at 02:00:47, on 27/06/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16473)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\ZoneLabs\vsmon.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\AOL\ACS\AOLAcsd.exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exeC:\WINDOWS\system32\nvsvc32.exeC:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exeC:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exeC:\Program Files\VoyagerTest\fts.exeC:\Program Files\QuickTime\qttask.exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exeC:\WINDOWS\system32\RUNDLL32.EXEC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program Files\Common Files\AOL\1165374413\ee\AOLSoftware.exeC:\WINDOWS\SOUNDMAN.EXEC:\Program Files\Zone Labs\ZoneAlarm\zlc... Read more


Hello MickinPlymouthUK, I am SifuMike and I will be helping you. You will need to use Internet Explorer for this scan. Disable your antivirus program and go here to run BitDefender Online Scan. Click on I Agree. Avoid clicking on other links as you don't need to try out the full install at this point, just the online scanner.When the ActiveX Control has loaded, click on "Click here to scan". Please be patient, as this scan may take a few hours. It all depends on the number of files on your computer. NOTE: If you are running XP SP2, you may need to click on the Information Bar to allow the ActiveX to install and may need to repeat the BitDefender Online Scan.When BitDefender completes the scan, select the "Detected Problems" tab. Click on "Click here to export scan". Save the file as an HTML to your Desktop. Then click on the saved file and allow it to open with your browser. Go to Edit - Select All then copy/paste that log back here. Post the BitDefender log.******************Download and install AVG Anti-Spyware v7.5.After download, double click on the file to launch the install process. Choose a language, click "OK" and then click "Next".Read the "License Agreement" and click "I Agree".Accept default installation path: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5, click "Next", then click "Install".After setup completes, click "Finish" to start the ... Read more

I have a small server hosted on windows 2003 standard ed sp1 and since few days ago someone is flooding us through udp ports.

I have followed these guides




but the upd flood still goes on.

I'm using outpostfirewall to see the packets and the ip that are flooding. svchost.exe is shown as flooded through UDP 123 port
Could anyone help me to sort this out?
Thank you

A:Windows 2k3 UDP flood, help please

Do you currently have your server configured to match time with the network via NTP? If not, turn the service off and simply shut down UDP/123 at your firewall.

I've recently switched from a BT homehub (which broke [stopped giving out more that 1 bar of signal]) back to our old Belkin router (model #F5D7632-4)

I can access the internet for about 5 minutes, before I lose it and get "could not connect" type messages from my browser. After investigating further I noticed something interesting in the routers security log, A UDP flood.. I'll put the log below:
03/31/2010 17:29:33 **UDP Flood to Host**, 56853->>, 53 (from ATM1 Outbound)
03/31/2010 17:29:32 **UDP Flood to Host**, 56853->>, 53 (from ATM1 Outbound)
03/31/2010 17:29:31 **UDP Flood to Host**, 56853->>, 53 (from ATM1 Outbound)
03/31/2010 17:29:22 **SYN Flood to Host**, 50549->>, 80 (from ATM1 Outbound)
03/31/2010 17:29:05 login success
03/31/2010 17:29:00 NTP Date/Time updated.
08/01/2003 00:00:16 If(ATM1) PPP connection ok !
08/01/2003 00:00:15 ATM1 get IP:
08/01/2003 00:00:13 ATM1 start PPP
08/01/2003 00:00:13 ADSL Media Up !
08/01/2003 00:00:01 sending ACK to
There's also a SYN flood just before the others.

Anyone have a clue about why this might be happening? Am I at the receiving end of someone just having fun giving me a DDOS attack, or have I got a dodgy configuration somewhere. I've scanned my computer with AVG to no avail.

Oh, also, I can sti... Read more

A:UDP Flood attack

Comming from somewhere and have followed all steps in your sticky now what?

Logfile of HijackThis v1.99.1
Scan saved at 5:07:28 PM, on 8/1/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\Program Files\Microsoft Firewall Client 2004\FwcAgent.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft SQL Server\MSSQL$SIGMANEST\Binn\sqlservr.exe
C:\Program Files\NavNT\rtvscan.exe
C:\Program Files\Common Files\{B0A5AD2A-0711-1033-0727-051109040001}\Update.exe
C:\Documents and Settings\CWheat\Application Data\??pPatch\n?tdde.exe
C:\Program Files\Adobe\Adobe GoLive CS2\GoLive.exe
C:\Documents and Settings\CWheat\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://housecall.trendmicro.com/
... Read more

A:Flood of stuff. Pls Help

Please do two things first....relocate HijackThis.exe to it's own folder, such as at C:\HJT. Having it on the desktop will make it more difficult to locate backups should the need arise.

Once it's in it's own folder, please rename HijackThis.exe to HJT.exe, run a new scan, save that log and post it here.

Hi there. A few days ago while have problems viewing a webpage on firefox, I switched to Internet Explorer and was flooded with trojans and such. A whole load was blocked by my avast anti virus and a load of stuff was deleted by windows security. I decided to run combofix (was instructed to use it once before on this site to fix my last virus problem, updated for this use of course) hoping for a quick fix or just to see if everything was fine. Combofix detected rootkit activity and did the reboot. Problem is, at one scan stage a couple minutes in, my computer crashed with a BAD_POOL_HEADER error. This happens everytime I run it. All programs closed and anti virus off. The same thing happened when I tried to run gmer, although my computer crashes just running the .exe so I was unable to get that log.
I hope you can help, thanks for your time

DDS (Ver_10-11-05.01) - NTFSx86
Run by Paul at 4:20:58.25 on 06/11/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_15
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.3327.2485 [GMT 0:00]

AV: avast! Antivirus *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\Alwil Software\Avast5\AvastS... Read more

A:malware flood


When re-starting my windows XP, the desktop is filled with unwanted icons every time. over 2000 by now.

A:Flood of icons

It looks like something has taking over your system. Have you tried running any antiviral programs or spyware utilities like Adaware and Spybot. Another options is to download the program HiJackThis (http://www.majorgeeks.com/downloads31.html ) and post your results on the Security Forum

When re-starting my windows XP, the desktop is filled with unwanted icons every time. over 2000 by now.

A:Flood of icons

It looks like something has taking over your system. Have you tried running any antiviral programs or spyware utilities like Adaware and Spybot. Another options is to download the program HiJackThis (http://www.majorgeeks.com/downloads31.html ) and post your results on the Security Forum

Hello and I am hoping I have posted this in the correct forum. I contacted my Internet Company (Charter) and the tech told my I have some running called SYN Flood. Has anyone had a experience with is? The tech suggestion I delete my hard drive and re-install XP, although he said XP is an easy system to compromise. My question is there any anti virus application I can run to remove it. .......Thanks

A:Virus syn flood

Hello,A SYN Flood is a form of denial-of-service attack in which an attacker sends a succession of SYN requests to a target's system. There are variety of solutions to fix this,such as, solutions that involve changing the operating system's TCP/IP networking. We need to see some more about what is on here.Please go here....Preparation Guide ,do steps 6 - 9.Create a DDS log and post it in the new topic explained in step 9,which is here Virus, Trojan, Spyware, and Malware Removal Logs and not in this topic,thanks.If Gmer won't run,skip it and move on.Let me know if that went well.

Today I clicked on a link in an e-mail saying "You have a greetings card", but instead of it being from some stunning woman as I'd hoped, nothing happened except I got a Virus Alert from my AVG. (sniffle)
I ran two full scans to try to get rid of it but it won't go.
The scan tells me the virus is a "Backdoor.Flood" whatever that means, and that it's sitting in my "C:\Windows\ststem32\script.ini" file.

The test result reads -
0 files healed successfully
1 file error while healing
Moved to virus vault-0

So what shall I do now? (I'm PC-illiterate, Win XP Home)

A:How To Get Rid Of Backdoor.flood?

Install Super Antispyware. Run it in safe mode. Allow it to quarantine whatever it finds. http://www.superantispyware.com/Run the online scan for Bit Defender in normal mode. Allow it to quarantine whatever it finds.http://www.bitdefender.com/scan8/ie.html--------------------------------------------------------------------------------Post a Hijack This log in the Hijack This Forum by following the directions in the link below if the programs above have not removed ALL malware. DO NOT post the log in this forum.http://www.bleepingcomputer.com/forums/t/34773/preparation-guide-for-use-before-using-malware-removal-tools-and-requesting-help/ --------------------------------------------------------------------------------How To start Windows in Safe Modehttp://www.bleepingcomputer.com/tutorials/how-to-start-windows-in-safe-mode/

I have a slew of adware remover programs (spyboy S&D, ad-aware SE,AVG) and it's just not cutting it. im getting a fair amount of adds including the ever favorite ''your computer may contain viruses! click here to have it scanned for free!!!''...*sigh*. Any help would be GREAT.

Running processes:
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Lxdb\Ahqiruw.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Pro... Read more

A:Adware flood

I've ran McAfee multiple times and the results are always the same: it find nothing, but always warns me there's a virus, then it makes me run the scan again and again. No matter what, McAfee doesn't seem to detect the virus. I'm assuming that the virus is IRC/Flood.cd.dr because that's what it says I have. It's really weird, and I'm thinking about dumping McAfee and getting Norton.

Here's my HighjackThis file:

Logfile of HijackThis v1.99.1
Scan saved at 2:50:40 AM, on 1/8/2002
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
c:\program files\mcafee.com\agent\mcdetect.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\Program Files\Common Files\Stardock\TrayServer.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD... Read more

A:Can't find a way to get rid of IRC/Flood.cd.dr

Ok so i've been playing xbox recently and been getting disconnected from Xbox live around every 10min while nothing else has been getting disconnected...I decided to check my router security log and found loads of UDP flood attacks on my router??

Firstly why is this happening? was it my fault?

Secondly how do i stop this?

Thanks in advance,

A:My Router is being UDP flood attacked?!?

MY internet has been painfully slow of late and I managed to finally get inside the brain of my wifi router. I checked the log and noticed lots and lots of UDP Flood attack reports from many different IP addresses. Can someone tell me what this means and if it could be the reason my internet seems to be 5 times slower than usual? A

Also, is there anything I can do? I have a D-Link router.


A:UDP Flood - The problem with my interenet?

please do not dupicate threads - - closing this thread
continue here

Hi, I've recently had a computer on our network get infected with this trojan. I followed several steps posted elsewhere to remove it, but feel like the PC isn't completely repaired, as our network is rediculously slow. Any help would be much appreciated.



Please start a new thread with this description and a HijackThis 2.00.2 Log in the Malware Removal & HijackThis Logs forum here. They'll assist you in clearing any infection.

Lately my internet connection has been realy slow at some times, when I try to download stuff though my browser [Firefox] I get a maximum of 10kb/s and Ive got a 10Mbs connection.
Ive check'd my computer with NOD32 and Spybot S&D, nothing found.
So I check'd my router event-log and I see there's a lot of tcp syn flood stuff, and yes its all comming from my computer [].
I dont know if they have anything to do with each other.

Can anyone help me?

Router Event-Log:

01:08:31 (since last boot)IDS dos parser : tcp syn flood (1 of 1) : 0048 TCP 10973->80 [S.....] seq 1007159808 win 16384

01:08:11 (since last boot)FIREWALL icmp check (1 of 1): Protocol: ICMP Src ip: Dst ip: Type: Destination Unreachable Code: Port Unreacheable

01:06:21 (since last boot)IDS dos parser : tcp syn flood (1 of 1) : 0048 TCP 10973->80 [S.....] seq 1007159808 win 16384

01:06:18 (since last boot)FIREWALL icmp check (1 of 2): Protocol: ICMP Src ip: Dst ip: Type: Destination Unreachable Code: Port Unreacheable

01:05:13 (since last boot)FIREWALL icmp check (1 of 2): Protocol: ICMP Src ip: Dst ip: Type: Destination Unreachable Code: Host Unreacheable

01:04:12 (since last boot)IDS dos parser : tcp syn flood (1 of 1) : 0048 TCP 10973->80 [S.....] seq 1007159808 win 16384

01:02:01 (since l... Read more

A:Slow internet, tcp syn flood?

you might want to try a rootkit revealer:

Read other 1 answers

good day

my windows 7 x64 laptop is logging over 1300 event id 7036 on boot in a span of less than 30 seconds. It encompasses many different services all starting and stopping very rapidly. there used to be less than 100 of these after using the system for a whole day. the computer browser service seems the most frequent, and I have seen it start and stop 24 times in 1 second according to the logs. there are no errors in the logs.

has anyone experienced this? any idea what has caused this?

thanks in advance

A:event id 7036 flood

Here is another link from microsoft technet website.The poster has the same problem as you are encountering.
Windows 7 Home Premium - services keep stopping and re-starting - eventually lose all network connectivity and access to most system services

Let us know how it goes

Read other 9 answers

Hello, I seem to have something a trojan called ... trojan.flood that my AVG antispyware 7.5 keeps finding, but cant get rid of. I have also found a strange entry on my hijack this log to... fir.exe & fixweb.exe? I tried looking it up, but found nothing. I'd appreciate any help thanks so much!

Running processes:
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\PoivY.com\PoivY\PoivY.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrob... Read more

MY internet has been painfully slow of late and I managed to finally get inside the brain of my wifi router. I checked the log and noticed lots and lots of UDP Flood attack reports from many different IP addresses. Can someone tell me what this means and if it could be the reason my internet seems to be 5 times slower than usual? A

Also, is there anything I can do? I have a D-Link router.


A:UDP Flood - The problem with my interenet?

Hello and please please help me:
I just runned AVG and it detected 13 infections. I have a PC running with Microsoft XP. Please help me with this.
The result of AVG says it has found infected files in "DC21.exe" in the following folder:



This is my Hijack Log, please help me with this...

Logfile of HijackThis v1.99.1
Scan saved at 23:40:21, on 19/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Alias\Maya7.0\docs\wrapper.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Alias\Maya7.0\docs\jre\bin\java.exe
C:\WIN... Read more

A:Help against virus: Backdoor flood

Apologies for any delay in replying, but we have been rather busy lately, and, of course, all our helpers are volunteers.

Since it has been a few days since you first posted, please follow these instructions if you still need assistance.

Download Deckard's System Scanner (DSS) to your Desktop . Note: You must be logged onto an account with administrator privileges.Close all applications and windows.
Double-click on dss.exe to run it, and follow the prompts.
When the scan is complete, two text files will open - minimised > extra.txt and maximised > main.txt.
Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt back in this thread (do not attach it).
Please attach extra.txt to your post.

To attach a file to a new post, simplyClick the[Manage Attachments] button under Additional Options > Attach Files on the post composition page, and
copy and paste the following into the "Upload File from your Computer" box:C:\Deckard\System Scanner\extra.txt

Click Upload.

I will monitor this thread for your reply.

Thank you for your patience.

I'm a Vista & PC newbie, as well as a newbie to this forum. Sorry in advance for such a long post.

I have a Sony Vaio NG31S, with Vista Home Premium & Service Pack 1. When my free Norton trial expired, I read reviews and bought Shield Deluxe, which seems to work well except for regularly saying that a mal-ware scan has not been carried out for (e.g.) 40 days when one has actually just been carried out.

Now the PC has gone crazy, with a constant barrage of Windows error messages piling up faster than I can delete them. Meanwhile, programmes won't load.

At first, the normal desktop was visible, I was able to set up an Administrator account and thanks to this forum try some possible solutions, such as 'restore' - but none have worked.

I had recently added updates from Apple for iTunes & Quicktime and suspected they may have conflicts, so I un-installed them - no change.

The most common error message is: 'Windows Problem Reporting has stopped working', but there are many others, such as 'Task Scheduler Engine' and many more landing on top of each other and all saying that various features have stopped working. These include System Restore, so I can't follow recommendations to carry out a restore.

I shut down last night and went to have another go tonight - this time, after signing in as Administrator again, I can only get a black screen with the Windows error messages coming thick & fast.

The Vaio came with Vista pre-loaded and no support disks. I... Read more

A:Flood of error messages

I would run Hard Drive Diags and Windows Memeory Diag

Also, I would get rid of and a refund (personal opinion) of Shield Deluxe.
I have seen this in the past, and I think it was the root cause of issues. But uncertain as it was a long time ago.

You should find out what manufacturer HDD you have and run those (ie: Western Digital, Seagate, Maxtor etc. [Toshiba Drives do not have diags available at all])

When you run the mem diag, after it starts hit "t" on the keyboard to run the advanced diags and let them run for no less than 4 to 6 hours.

Read other 9 answers

Okay so my computer has 50 mps download speed. However the frequency and network utilization is always maxed out. Also, i get pop-ups for poker and green cards USAGC. How do i fix this??? Logfile of Trend Micro HijackThis v2.0.4Scan saved at 7:11:04 PM, on 6/6/2013Platform: Windows 7 SP1 (WinNT 6.00.3505)MSIE: Internet Explorer v9.00 (9.00.8112.16448)Boot mode: Normal Running processes:C:\Users\DM Gray\AppData\Local\Akamai\netsession_win.exeC:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeC:\Program Files (x86)\hp\Digital Imaging\bin\hpqtra08.exeC:\Users\DM Gray\AppData\Local\Akamai\netsession_win.exeC:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exeC:\Program Files (x86)\hp\HP Software Update\hpwuschd2.exeC:\Program Files (x86)\PowerISO\PWRISOVM.EXEC:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exeC:\Program Files (x86)\Common Files\Java\Java Update\jusched.exec:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exeC:\Users\DM Gray\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exeC:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exeC:\Users\DM Gray\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\DM Gray\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\DM Gray\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\DM Gray\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\DM Gray\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\DM Gray\AppData\L... Read more

A:USAGC Pop-Up and internet flood

I would like assistance with this problem rather than having to send it into an IT

Read other 3 answers

Hi, I've recently have noticed sluggish internet speeds. I decided to take a look at our router's activity and here is what I've found.

Is someone outside the network trying to flood and knock out our network? Or could it be coming from inside the network?

Belkin Wireless Router (G)

Devices Connected to Network:
WinVista Machine (Wired)
WinVista Machine (Wireless)
Ubuntu 9.10 Machine (Wireless)
Netendo Wii

From looking at the logs, what do you guys think?

01/01/2010 19:14:37 **UDP Flood Stop** (from PPPoE1 Inbound)
01/01/2010 19:14:37 **UDP flood**, 24086->>, 46349 (from PPPoE1 Inbound)
01/01/2010 19:14:36 **UDP flood**, 16776->>, 46349 (from PPPoE1 Inbound)
01/01/2010 19:14:36 **UDP flood**, 33837->>, 46349 (from PPPoE1 Inbound)
01/01/2010 19:14:35 **UDP flood**, 37193->>, 46349 (from PPPoE1 Inbound)
01/01/2010 19:14:35 **UDP flood**, 59963->>, 57890 (from PPPoE1 Inbound)
01/01/2010 19:14:34 **UDP flood**, 13181->>, 46349 (from PPPoE1 Inbound)
01/01/2010 19:14:33 **UDP flood**, 24528->>, 46349 (from PPPoE1 Inbound)
01/01/2010 19:14:33 **UDP flood**, 19327->>, 46349 (from PPPoE1 Inbound)
01/01/2010 19:14:33 **UDP flood**, 58339->>, 57908 (from PPPoE1 Inbound)
01/01... Read more

A:UDP Flood? Is someone spamming our network?

Read other 6 answers

Hello and thanks in advance for the help:My Pc is infected with Backdoor.Flood. I have ran AVG several times but it was able to detect it only the first time. Nevertheless, Panda Activescan gives the following information:Incident Status Location Adware:Adware/SaveNow Not disinfected C:\Program Files\DAEMON Tools\SetupDTSB.exe Adware:Adware/SaveNow Not disinfected C:\Program Files\DaemonTools_WhenUSave_Installer\DaemonTools_WhenUSave_Installer.exe Spyware:Cookie/Tribalfusion Not disinfected C:\RECYCLER\S-1-5-21-130597653... Read more

A:Infected With Backdoor.flood

Read other 1 answers

I've used Malwarebytes', SpyBOT and Avira for detections, but I guess there is still a rootkit or worm hidden.

DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_26
Run by Carlos at 8:10:44 on 2011-06-30
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.55.1046.18.2038.928 [GMT 1:00]
AV: AntiVir Desktop *Enabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AntiVir Desktop *Enabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
============== Running Processes ===============
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:... Read more

A:Getting (UDP and SYN) flood on wireless router.

Please make sure to carefully read any instruction that I give you. Attention to detail is important! Since I cannot see or directly interact with your computer I am dependent on you to "be my eyes" and provide as much information as you can regarding the current state of your computer.
If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
In Windows Vista and Windows 7, all tools need to be started by right clicking and selecting Run as Administrator&#... Read more

Read other 16 answers

Hi, Hope Someone can Help Me With Thiis One...Im Not The Brightest Bulb In The House when it comes To Computers.. But Im Trying to Learn, Im Stuck On E-mails.. I Receive Them With Full Headers And Just Like The People Who Send Them To Me, I Dont Know how To Remove Them,Would Like Just My Address To Show (Like It Should) When I Forward To Other Friends...Dont Want to Be Promoteing Spam For Other People.. I Know I Hate Opening Anything From Someone I Dont know who Got My Name Of A Forwarded E-mail... Can You Help Me? I Have Yahoo For My Mail, And In My Tools Cut Coppy And Paste Are shown in faded color. Tried Hilighting and Deleteing To No Avail.. Tryed Right Clicking,, Got Nothing?? Dont know What Else To Do.. If You Can help me With This It Would be Appreciated... And Please in Detail, Not Very Tec Minded Here... Thanks So Much

A:Lost In a Flood of Headers

Read other 9 answers

Can someone explain what a "detected syn flood attack" means?
lately I've noticed my broadband connection has slowed to a point where it is slower than dialup,pages take longer to load
and downloads are 1 or 2kbs or sometimes less than 1kbs when i should normally get around 30kbs
I downloaded a program called NNAgent and in the alerts it mentioned detected syn flood attack,is this a symptom of some malware on my computer or is the problem coming from my isp?
I'm using a WAG54Gv.3 wireless modem on windows xp

A:Solved: SYN flood attack


usually not malware, but an attacker on the internet flooding your IP address with syn packets, otherwise known as a denial of service attack, contact your isp about it.

If you suspect malware download MBAM, manually update it after install and do a scan of your system, it is free.


Free version has to be updated occasionally, and has to be done manually by you, and will only scan when you tell it to, the paid version has automatic updates and active protection.


Read other 3 answers

....this is day three, since I started getting around 500 emails day from that microsoft patch, critical update, returned mail, etc. email virus.

I have OE set to not let in attachments, but the emails still come in.

It still seems to be averaging around 1 email every 3 mins. I have now set OE to NOT check for new messages, so I can click on SEND/RECEIVE and download them all at once.

For awhile I was finding the sender's email and sending back a short note, like "your computer is sending a virus, just letting you know in case you weren't aware". I figured what good does it do to just delete them, if the people don't know it's happening?

I'm also getting around 20 every few hours in my Yahoo mail, but this fills it up overquota, and stops more from coming in, till I delete and empty it all and it starts over again.

I thought, by now it would have stopped, or the servers (mine is Earthlink) would have set up some kind of filter or something.

Is there any "best" way to deal with this?

Should I keep downloading the emails and deleting them, or let them back up?

Same with yahoo mail, though with that I think they automatically start deleting mail if it's over quota too long, and that would allow more to come in, and I might not get something I want (email)

I don't have the virus, and don't think I'll get it, with OE not letting in attachments and my AVG virus scan running, checking all mail.

Just not sure ... Read more

Read other 7 answers


recently I startd to face internet connectivity problems (web sites hardly load) then after some time I took a look at the modem log and ;I see "sync flood " or "ddos to xxx.xxx.xxx.xxx" (If you wish I can look at the log one more time and post the exact log here)... I scanned by virus programs, trojan remover etc. and I am using AVG 8 + PCTools Firewall.....

I can not solve this problem -- is there any way to handle thiss issue and delete the program / virus that makes the ddos attck?...

Read other answers

I just ran a virus scan under PC Tools Antivirus and here are my results.

PC Tools AntiVirus Activity Report
Generated on: 5/19/2008 4:59:41 PM

Scan Information:

Object Name Status Action Infection Date and Time

C:\WINDOWS\system32\oiib\exit.exe Infected Quarantined trojan: Trojan.Cloner.L 5/19/2008 5:28:42 PM

C:\WINDOWS\system32\oiib\x.q Infected Quarantined mutant: IRC.Flood.CJ 5/19/2008 5:28:47 PM

C:\WINDOWS\system32\cl Infected Quarantined mutant: IRC.Flood.CJ 5/19/2008 5:28:49 PM

C:\WINDOWS\system32\d Infected Quarantined mutant: Backdoor.IRC.Kelebek.O 5/19/2008 5:28:50 PM

C:\WINDOWS\system32\d.dll Infected Quarantined trojan: Trojan.DuckIRC.F 5/19/2008 5:28:51 PM

C:\WINDOWS\system32\col\jt1 Infected Quarantined mutant: IRC.Flood.CJ 5/19/2008 5:28:52 PM

C:\WINDOWS\system32\col\jt3 Infected Quarantined mutant: IRC.Flood.CJ 5/19/2008 5:28:53 PM

C:\WINDOWS\system32\col\win.dll Infected Quarantined trojan: Trojan.DuckIRC.F 5/19/2008 5:28:54 PM

C:\WINDOWS\system32\j44444m\b Infected Quarantined mutant: IRC.Flood.CJ 5/19/2008 5:28:55 PM

... Read more

Read other answers

Hello,  I keep getting the following error message: A corrected hardware error has occurred. Component: PCI Express Root Port Error Source: Advanced Error Reporting (PCI Express) Busevice:Function: 0x0:0x1C:0x5 Vendor IDevice ID: 0x8086:0xA115 Class Code: 0x30400  The details view of this entry contains further information. My Model: HP Pavilion Gaming 15 - ak000nh  It always happens after system start and I got thousands of entries. As I know I'm using the latest BIOS version F.71 which is not available on the download section anymore, neither this nor newer version. I'm using the latest drivers installed by HP Assistant, and I tried to update all of them induvidualy too. I also tried to reinstall the system and reset the BIOS to defaults including security settings. There was no effect I'm getting the message continuosly. Is there any solution? Is there any update that can help? I saw a few same post here with same models, if this a known issue I would like to know the exact way to solve this issue. Thank You

A:WHEA-Logger flood - Event ID 17

Its a hardware issue, software or drivers may not fix it, is it under Warranty? You can try reinstalling all the chipset drives found at link below.  http://support.hp.com/us-en/drivers/selfservice/HP-Pavilion-Gaming-15-ak000-Notebook/8610971/model/8...

Hi I'm new here so hope I'm posting in right forum. Correct me if I'm not.

I have 3 laptops an Ipad 2 and an Xbox which use a Belkin wireless router to connect to the outside world. My main PC is hardwired to router and so is my Humax HD TV Box.

The problem is we all keep losing connection together. It's almost become an hourly occurence. Sometimes more often and its driving us mad.

Whenever we lose connection the wireless is still showing as connected via the login and all the lights are lit on thr router?

The router is a Belkin F5d7634-4 model.

All items are MAC address filtered. Security is set at WPA WPA2 Encryption Type AES and there is a password to use the router.

I've noticed when we all lose connection that the following is a typical security report from the router but I haven't the foggiest what its telling me. Is the info below the source of our trouble and if it is what's the likely cause please anyone?

07/28/2012 18:49:55 login success
07/28/2012 18:49:37 logout
07/28/2012 18:49:18 Duplicate user login from
07/28/2012 18:49:17 Duplicate user login from
07/28/2012 18:49:01 sending ACK to
07/28/2012 18:44:37 login success
07/28/2012 18:36:04 **UDP Flood Stop** (from ATM1 Outbound)
07/28/2012 18:36:02 **SYN Flood**, 49361->>, 80 (from ATM1 Outbound)
07/28/2012 18:36:02 **SYN Flood**, 52478-&... Read more

A:Intermittent Internet Loss - SYN FLOOD?

My Belkin Wireless N Router has been recently showing UDP Floods constantly coming from random IPs and random ports, and targeting only one of my computers. Here is the log from the router so far:Firewall Log06/15/2010 10:36:15 **UDP Flood to Host**, 35168->>, 9305 (from WAN Inbound)06/15/2010 09:23:21 **UDP flood**, 11407->>, 9424 (from WAN Inbound)06/15/2010 09:23:21 **UDP Flood Stop** (from WAN Inbound)06/15/2010 09:23:21 **UDP flood**, 8080->>, 9305 (from WAN Inbound)06/15/2010 09:23:21 **UDP flood**, 22887->>, 9305 (from WAN Inbound)06/15/2010 09:23:21 **UDP flood**, 16707->>, 9305 (from WAN Inbound)06/15/2010 09:23:21 **UDP flood**, 22303->>, 9305 (from WAN Inbound)06/15/2010 09:23:20 **UDP flood**, 19505->>, 9305 (from WAN Inbound)06/15/2010 09:23:20 **UDP flood**, 10772->>, 9305 (from WAN Inbound)06/15/2010 09:23:20 **UDP flood**, 32768->>, 9305 (from WAN Inbound)06/15/2010 09:23:20 **UDP flood**, 15072->>, 9305 (from WAN Inbound)06/15/2010 09:23:20 **UDP flood**, 33006->>, 9305 (from WAN Inbound)06/15/2010 09:23:19 **UDP flood**, 1483->>, 9305 (from WAN Inbound)06/15/2010 09:23:19 **UDP fl... Read more

A:Router showing UDP Flood from WAN Inbound

Read other 2 answers

In my Hijackthis log below, you'll see a flood of entries like "O18 - Protocol: bw-0s". What are they? My Gateway WinXPPro desktop (750MB RAM) starts and runs just fine, and I'm willing to leave them alone, but they sure do look weird. Clue: The desktop is a gift from a friend and although he had deleted a lot of his files, he did not do a full re-install of XPPro. Maybe some old stuff got left on. (By the way, the keyboard and mouse are also the original Gateway.) And if you see anything else wrong, feel free to flame.Logfile of Trend Micro HijackThis v2.0.2Scan saved at 10:57:20 PM, on 12/22/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16574)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\System32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Ahead\InCD\InCDsrv.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\Program Files\Alwil Software\Avast4\aswUpdSv.exeC:\Program Files\Alwil Software\Avast4\ashServ.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Commo... Read more

A:Flood Of O18 - Protocol: Bw-0s Startup Entries

Read other 1 answers

Has anyone heard of a virus that sends multiple copies of an email? I sent an email to a friend via "hotmail" and now, she is getting multiple copies of it. She's already received over 100 copies, and they keep coming - like every 15 minutes.

I got an automatic notice from the hotmail "postmaster" saying that my email was "delayed" and would be sent later!
So, possibly there is a bug in the hotmail side of it.
I've written to the hotmail people, but no response so far.

Does anyone know anything about this problem, or have any suggestions?

A:Virus? - Got email flood on Hotmail

I'm running Windows Vista, and my system has been fairly stable for the last few months. I got a pile of strange bugs all popping up at the same time today, and I'm stumped-

1)Windows explorer crashes periodically, especially when opening items in the control panel. The "system" "programs" tabs refuse to open at all.
2)Some applications are reporting that my CPU does not meet minimum spec, saying it has a speed of 0.0 GHz.
3)Sophos antivirus refuses to start entirely, making a virus scan difficult
4)Itunes library was reported as damaged
5)Audio does not work for some applications.

32-bit Vista
Dual Core AMD 2.41 GHz Processor
2 GB ram
Geforce 8600 GT graphics card

HJT log attached

A:Sudden flood of problems with vista

Read other 1 answers

my computer is on a network with a zywall router/fw. The internet was stopping from time to time and i checked the routers logs and saw flooding for lan to wan that was stopping when i disconnect my computer from the network so it's me causing the problem.
I run malware bytes antimalware but found nothing.
What should i do next?
PS i'll post logs from hijack this, gmer and dds as soon as i have access to that pc again.

A:Computer flood router-firewall

AVG has spotted this Trojan, and I have isolated it in the vault, but I am unable to remove it, can some one please advise ?.


A:Solved: Trojan IRC Backdoor Flood.

