Router problems: internet cutting in and out DoS attack in logs

Discussion in 'Hardware' started by jkman, Sep 23, 2014.

  1. jkman

    jkman Private E-2

    Hi majorgeeks! Over the past couple of days, usually at night the internet has gone in and out intermittently for times ranging between 1 and 10 minutes. I called my ISP (time warner) and they said everything was good on their end. I checked my router logs to see what was up and found this:

    [DoS Attack: ACK Scan] from source: 65.172.31.34, port 80, Tuesday, September 23,2014 19:43:27
    [admin login] from source 192.168.1.4, Tuesday, September 23,2014 19:43:02
    [DoS Attack: ACK Scan] from source: 65.172.31.34, port 80, Tuesday, September 23,2014 19:42:23
    [DoS Attack: ACK Scan] from source: 65.172.31.33, port 80, Tuesday, September 23,2014 19:41:58
    [DoS Attack: ACK Scan] from source: 65.172.31.34, port 80, Tuesday, September 23,2014 19:40:55
    [DoS Attack: ACK Scan] from source: 31.13.74.144, port 443, Tuesday, September 23,2014 19:40:47
    [DoS Attack: ACK Scan] from source: 65.172.31.34, port 80, Tuesday, September 23,2014 19:40:23
    [DoS Attack: ACK Scan] from source: 65.172.31.33, port 80, Tuesday, September 23,2014 19:39:58
    [DoS Attack: ACK Scan] from source: 69.171.235.48, port 443, Tuesday, September 23,2014 19:39:57
    [DoS Attack: ACK Scan] from source: 74.125.225.89, port 80, Tuesday, September 23,2014 19:39:50
    [DoS Attack: ACK Scan] from source: 69.171.235.48, port 443, Tuesday, September 23,2014 19:39:50
    [DoS Attack: ACK Scan] from source: 65.172.31.34, port 80, Tuesday, September 23,2014 19:39:45
    [DoS Attack: ACK Scan] from source: 74.125.225.89, port 80, Tuesday, September 23,2014 19:39:30
    [DoS Attack: ACK Scan] from source: 65.172.31.34, port 80, Tuesday, September 23,2014 19:39:26
    [DoS Attack: ACK Scan] from source: 74.125.225.89, port 80, Tuesday, September 23,2014 19:39:20
    [DoS Attack: ACK Scan] from source: 65.172.31.34, port 80, Tuesday, September 23,2014 19:39:12
    [DoS Attack: ACK Scan] from source: 74.125.225.89, port 80, Tuesday, September 23,2014 19:39:10
    [DoS Attack: ACK Scan] from source: 23.63.227.185, port 443, Tuesday, September 23,2014 19:39:04
    [DoS Attack: ACK Scan] from source: 184.50.239.24, port 443, Tuesday, September 23,2014 19:39:01
    [DoS Attack: ACK Scan] from source: 74.125.225.89, port 80, Tuesday, September 23,2014 19:39:00
    [DoS Attack: ACK Scan] from source: 65.172.31.34, port 80, Tuesday, September 23,2014 19:38:59
    [DoS Attack: ACK Scan] from source: 65.172.31.33, port 80, Tuesday, September 23,2014 19:38:51
    [DoS Attack: ACK Scan] from source: 74.125.225.89, port 80, Tuesday, September 23,2014 19:38:50
    [DoS Attack: ACK Scan] from source: 65.172.31.34, port 80, Tuesday, September 23,2014 19:38:48
    [DHCP IP: 192.168.1.3] to MAC address d0:22:be:f2:6a:cf, Tuesday, September 23,2014 19:38:42
    [DoS Attack: ACK Scan] from source: 74.125.225.89, port 80, Tuesday, September 23,2014 19:38:41
    [DHCP IP: 192.168.1.2] to MAC address 88:c6:63:66:3b:8a, Tuesday, September 23,2014 19:38:40
    [DoS Attack: ACK Scan] from source: 65.172.31.34, port 80, Tuesday, September 23,2014 19:38:35
    [Initialized, firmware version: V1.2.3.7] Tuesday, September 23,2014 19:38:33

    These attacks aren't coming from any device on the home network because all of our IP addresses start with 192. The firmware is up to date. I'm running a motorola SB6141 modem with a netgear wnr2000 wireless router. When it cuts out, all devices wired and wireless lose connection so it's not a wireless issue. Any ideas or advice? Thanks!
     
    Last edited: Sep 24, 2014
  2. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

  3. jkman

    jkman Private E-2

    Thank you for the reply. I apologize but i'm not sure what i'm supposed to do with the given information in those links. Should I run a virus scan?
     
  4. mdonah

    mdonah Major Geek Extraordinaire

    No, plodr's links show you the results of VirusTotal scans. The IP address 65.172.31.34 shows quite a number of Conduit detections. Conduit is a browser highjacker that's included as "bundleware" with many apps downloaded from questionable sites.

    It can be removed but, it's difficult. Google "completely remove Conduit" with the quotes.
     
  5. jkman

    jkman Private E-2

    I looked around on all 3 computers that are on the network and none of them have signs of conduit programs installed on them.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds