firewall warning?

ammer

Beta member
Messages
3
Eset giving me DNS cache poisoning attack.And 2 days ago i found by Svchost Process Analyzer program "Time network" and "System drive" viruses and reformatted my computer.But after this i found by Svchost Process Analyzer
23w3bir.jpg
worm "Monitor time" and "Task time" virus.I need to know how do work the "Monitor" and "Task time" processes.The name of these viruses are very similar.Is it hack?

[FONT=&quot]ESET beta 5 firewall warnings[/FONT]


[FONT=&quot]<?xml version="1.0" encoding="utf-8" ?>[/FONT]
[FONT=&quot]-[/FONT][FONT=&quot] <ESET>[/FONT]
[FONT=&quot]-[/FONT][FONT=&quot] <LOG>[/FONT]
[FONT=&quot]-[/FONT][FONT=&quot] <RECORD>[/FONT]
[FONT=&quot]-[/FONT][FONT=&quot] <COLUMN NAME="Time">[/FONT]
[FONT=&quot] <DATE>8/9/2011</DATE> [/FONT]
[FONT=&quot] <TIME>4:32:14 PM</TIME> [/FONT]
[FONT=&quot] </COLUMN>[/FONT]
[FONT=&quot] <COLUMN NAME="Event">Detected DNS cache poisoning attack</COLUMN> [/FONT]
[FONT=&quot] <COLUMN NAME="Source">192.168.0.1:53</COLUMN> [/FONT]
[FONT=&quot] <COLUMN NAME="Target">192.168.0.37:3586</COLUMN> [/FONT]
[FONT=&quot] <COLUMN NAME="Protocol">UDP</COLUMN> [/FONT]
[FONT=&quot] <COLUMN NAME="Rule/worm name" /> [/FONT]
[FONT=&quot] <COLUMN NAME="Application" /> [/FONT]
[FONT=&quot] <COLUMN NAME="User" /> [/FONT]
[FONT=&quot] </RECORD>[/FONT]
[FONT=&quot]-[/FONT][FONT=&quot] <RECORD>[/FONT]
[FONT=&quot]-[/FONT][FONT=&quot] <COLUMN NAME="Time">[/FONT]
[FONT=&quot] <DATE>8/9/2011</DATE> [/FONT]
[FONT=&quot] <TIME>4:31:59 PM</TIME> [/FONT]
[FONT=&quot] </COLUMN>[/FONT]
[FONT=&quot] <COLUMN NAME="Event">Detected DNS cache poisoning attack</COLUMN> [/FONT]
[FONT=&quot] <COLUMN NAME="Source">192.168.0.1:53</COLUMN> [/FONT]
[FONT=&quot] <COLUMN NAME="Target">192.168.0.37:3586</COLUMN> [/FONT]
[FONT=&quot] <COLUMN NAME="Protocol">UDP</COLUMN> [/FONT]
[FONT=&quot] <COLUMN NAME="Rule/worm name" /> [/FONT]
[FONT=&quot] <COLUMN NAME="Application" /> [/FONT]
[FONT=&quot] <COLUMN NAME="User" /> [/FONT]
[FONT=&quot] </RECORD>[/FONT]
[FONT=&quot]-[/FONT][FONT=&quot] <RECORD>[/FONT]
[FONT=&quot]-[/FONT][FONT=&quot] <COLUMN NAME="Time">[/FONT]
[FONT=&quot] <DATE>8/9/2011</DATE> [/FONT]
[FONT=&quot] <TIME>4:29:14 PM</TIME> [/FONT]
[FONT=&quot] </COLUMN>[/FONT]
[FONT=&quot] <COLUMN NAME="Event">Detected DNS cache poisoning attack</COLUMN> [/FONT]
[FONT=&quot] <COLUMN NAME="Source">192.168.0.1:53</COLUMN> [/FONT]
[FONT=&quot] <COLUMN NAME="Target">192.168.0.37:3586</COLUMN> [/FONT]
[FONT=&quot] <COLUMN NAME="Protocol">UDP</COLUMN> [/FONT]
[FONT=&quot] <COLUMN NAME="Rule/worm name" /> [/FONT]
[FONT=&quot] <COLUMN NAME="Application" /> [/FONT]
[FONT=&quot] <COLUMN NAME="User" /> [/FONT]
[FONT=&quot] </RECORD>[/FONT]
[FONT=&quot]-[/FONT][FONT=&quot] <RECORD>[/FONT]
[FONT=&quot]-[/FONT][FONT=&quot] <COLUMN NAME="Time">[/FONT]
[FONT=&quot] <DATE>8/9/2011</DATE> [/FONT]
[FONT=&quot] <TIME>4:24:47 PM</TIME> [/FONT]
[FONT=&quot] </COLUMN>[/FONT]
[FONT=&quot] <COLUMN NAME="Event">Detected DNS cache poisoning attack</COLUMN> [/FONT]
[FONT=&quot] <COLUMN NAME="Source">192.168.0.1:53</COLUMN> [/FONT]
[FONT=&quot] <COLUMN NAME="Target">192.168.0.37:3586</COLUMN> [/FONT]
[FONT=&quot] <COLUMN NAME="Protocol">UDP</COLUMN> [/FONT]
[FONT=&quot] <COLUMN NAME="Rule/worm name" /> [/FONT]
[FONT=&quot] <COLUMN NAME="Application" /> [/FONT]
[FONT=&quot] <COLUMN NAME="User" /> [/FONT]
[FONT=&quot] </RECORD>[/FONT]
[FONT=&quot] </LOG>[/FONT]
[FONT=&quot] </ESET>[/FONT]




23w3bir.jpg
 
From just looking at the log, it seems someone within the that router/network is trying to gain access to something on your computer. I wouldn't call it exactly posioning your computer yet because it is not nailing your computer every half with a different port. Maybe that computer that has the 192.168.1.53 address has a spam or maybe you just have a piece of software on it that is trying to just communicate. You will need to provide more details on this so we can help.
 
Ok, it's home wired internet with one PC without router.I found some info from internet, the IP 192.168 is Windows XP domain-mshome.net.Few days ago in my Control Panel/Network connections appeared any Internet gateway which connecting from another PC:

1231vfq.jpg
 
Sounds like you never cleaned your PC from the viruses....Boot your PC in safe mode and run your antivirus program to clean your PC... once done run it in normal mode and do another scan for viruses and this hopefully should fix your problem.

I doubt your PC is hacked.
 
Back
Top Bottom