Is my XP box affected by DDOS virus?



Hi all,

My XP (sp2) box has been exposing strange behaviors for a few weeks,
basically my browsers will work for a few minutes after reboot and then
can't connect to any website afterwards. but pinging those websites
just works fine, and DNS (UDP) also works.

I did a simple analysis with ethereal, and found out whenever I was
connecting to a website (ip: x.y.z.w), a SYN packet was forged to be
sent to another IP address 140.20.191.20, which is within DOD NIC (I
remember there is a root DNS server there), and the source ip of the
SYN packet was x.y.z.w and not mine!

Looks like something malicious was intercepting my traffic and
regenerating false SYN requests. Interestingly, only web traffic was
hijacked (TCP port 80). If I login to my company's VPN server and then
quit, the web traffic becomes normal until I reboot again, I guess it's
probably that vpn used its own network DLLs to overwrite those
defaults.

I used MS antispyware and Symantec Antivirus and did not get anything
out. Anybody here had a similar experience? and any solution?


Thank you!

Fang

.



Relevant Pages

  • Re: Another printer deleting itself.
    ... screensaver takes over the display, I then move my mouse and it's fine again. ... watched as he did all the usual stuff of reloading the the ATI Radeon driver ... I added your website to my ... Don't forget to restart it afterwards (or a reboot should start it ...
    (microsoft.public.windowsxp.print_fax)
  • RE: LSADump2 Crashing Systems
    ... > system was forced to reboot. ... > Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are ... login pages, dynamic content etc. Firewalls, SSL and locked-down servers are ...
    (Pen-Test)
  • Installing Problems
    ... MS website, but couldn't find any keys that had the ... use Netscape, I want my IE back, but it won't let me back. ... >>to be complete and reboot my computer, ...
    (microsoft.public.windows.inetexplorer.ie6.setup)
  • Re: aspnet_wp.exe sending email at project load
    ... i googled, and checked symantec, mcafee, etc. no one else seemd to have this ... nobody home at that website. ... haven't run the windows update yet. ... >> computer chose to reboot itself. ...
    (microsoft.public.dotnet.framework.aspnet)