Scrivo qui perchè da tre giorni la rete internet a casa mia è praticamente inutilizzabile a quanto pare per via di svariati attacchi DoS.
Per farvi un'idea vi posto il log del router di martedi:
> Sun, 2002-09-08 14:00:20 - LCP is allowed to come up.
> Sun, 2002-09-08 14:00:23 - PAP authentication success
> Sun, 2002-09-08 14:00:26 - Send out NTP request to time-g.netgear.com
> Tue, 2012-06-19 11:37:21 - Receive NTP Reply from time-g.netgear.com
> Tue, 2012-06-19 11:36:55 - Router start up
> Tue, 2012-06-19 13:11:38 - UDP Packet - Source:96.6.40.7,3478 Destination:79.6.33.147,54662 - [DOS]
> Tue, 2012-06-19 13:11:39 - UDP Packet - Source:217.212.238.143,3478 Destination:79.6.33.147,54662 - [DOS]
> Tue, 2012-06-19 13:11:39 - UDP Packet - Source:146.82.184.12,3478 Destination:79.6.33.147,54662 - [DOS]
> Tue, 2012-06-19 13:11:39 - UDP Packet - Source:217.212.238.143,3478 Destination:79.6.33.147,54662 - [DOS]
> Tue, 2012-06-19 13:11:39 - UDP Packet - Source:146.82.184.12,3478 Destination:79.6.33.147,54662 - [DOS]
> Tue, 2012-06-19 13:11:39 - UDP Packet - Source:217.212.238.143,3478 Destination:79.6.33.147,54662 - [DOS]
> Tue, 2012-06-19 13:11:40 - UDP Packet - Source:96.6.40.7,3478 Destination:79.6.33.147,54662 - [DOS]
> Tue, 2012-06-19 13:11:40 - UDP Packet - Source:146.82.184.12,3478 Destination:79.6.33.147,54662 - [DOS]
> Tue, 2012-06-19 13:11:40 - UDP Packet - Source:96.6.40.7,3478 Destination:79.6.33.147,54662 - [DOS]
> Tue, 2012-06-19 13:11:40 - UDP Packet - Source:217.212.238.143,3478 Destination:79.6.33.147,54662 - [DOS]
> Tue, 2012-06-19 13:11:40 - UDP Packet - Source:146.82.184.12,3478 Destination:79.6.33.147,54662 - [DOS]
> Tue, 2012-06-19 13:11:41 - UDP Packet - Source:217.212.238.143,3478 Destination:79.6.33.147,54662 - [DOS]
> Tue, 2012-06-19 13:11:41 - UDP Packet - Source:146.82.184.12,3478 Destination:79.6.33.147,54662 - [DOS]
> Tue, 2012-06-19 13:11:41 - UDP Packet - Source:217.212.238.143,3478 Destination:79.6.33.147,54662 - [DOS]
> Tue, 2012-06-19 13:11:41 - UDP Packet - Source:96.6.40.7,3478 Destination:79.6.33.147,54662 - [DOS]
> Tue, 2012-06-19 13:11:42 - UDP Packet - Source:146.82.184.12,3478 Destination:79.6.33.147,54662 - [DOS]
> Tue, 2012-06-19 13:11:42 - UDP Packet - Source:96.6.40.7,3478 Destination:79.6.33.147,54662 - [DOS]
> Tue, 2012-06-19 13:11:42 - UDP Packet - Source:217.212.238.143,3478 Destination:79.6.33.147,54662 - [DOS]
> Tue, 2012-06-19 13:11:42 - UDP Packet - Source:146.82.184.12,3478 Destination:79.6.33.147,54662 - [DOS]
> Tue, 2012-06-19 13:11:42 - UDP Packet - Source:217.212.238.143,3478 Destination:79.6.33.147,54662 - [DOS]
> Tue, 2012-06-19 13:11:43 - UDP Packet - Source:146.82.184.12,3478 Destination:79.6.33.147,54662 - [DOS]
> Tue, 2012-06-19 13:11:43 - UDP Packet - Source:217.212.238.143,3478 Destination:79.6.33.147,54662 - [DOS]
> Tue, 2012-06-19 13:11:43 - UDP Packet - Source:96.6.40.7,3478 Destination:79.6.33.147,54662 - [DOS]
> Tue, 2012-06-19 17:45:38 - UDP Packet - Source:96.6.40.7,3478 Destination:79.6.33.147,60353 - [DOS]
> Tue, 2012-06-19 17:46:09 - UDP Packet - Source:96.6.40.7,3478 Destination:79.6.33.147,56212 - [DOS]
> Tue, 2012-06-19 17:46:10 - UDP Packet - Source:217.212.238.143,3478 Destination:79.6.33.147,56212 - [DOS]
> Tue, 2012-06-19 17:46:10 - UDP Packet - Source:146.82.184.12,3478 Destination:79.6.33.147,56212 - [DOS]
> Tue, 2012-06-19 17:46:10 - UDP Packet - Source:217.212.238.143,3478 Destination:79.6.33.147,56212 - [DOS]
> Tue, 2012-06-19 17:46:10 - UDP Packet - Source:146.82.184.12,3478 Destination:79.6.33.147,56212 - [DOS]
> Tue, 2012-06-19 17:46:10 - UDP Packet - Source:217.212.238.143,3478 Destination:79.6.33.147,56212 - [DOS]
> Tue, 2012-06-19 17:46:11 - UDP Packet - Source:146.82.184.12,3478 Destination:79.6.33.147,56212 - [DOS]
> Tue, 2012-06-19 17:46:11 - UDP Packet - Source:217.212.238.143,3478 Destination:79.6.33.147,56212 - [DOS]
> Tue, 2012-06-19 17:46:11 - UDP Packet - Source:96.6.40.7,3478 Destination:79.6.33.147,56212 - [DOS]
> Tue, 2012-06-19 17:46:11 - UDP Packet - Source:146.82.184.12,3478 Destination:79.6.33.147,56212 - [DOS]
> Tue, 2012-06-19 17:46:11 - UDP Packet - Source:96.6.40.7,3478 Destination:79.6.33.147,56212 - [DOS]
> Tue, 2012-06-19 17:46:12 - UDP Packet - Source:217.212.238.143,3478 Destination:79.6.33.147,56212 - [DOS]
> Tue, 2012-06-19 17:46:12 - UDP Packet - Source:146.82.184.12,3478 Destination:79.6.33.147,56212 - [DOS]
> Tue, 2012-06-19 17:46:12 - UDP Packet - Source:96.6.40.7,3478 Destination:79.6.33.147,56212 - [DOS]
> Tue, 2012-06-19 17:46:12 - UDP Packet - Source:146.82.184.12,3478 Destination:79.6.33.147,56212 - [DOS]
> Tue, 2012-06-19 17:46:12 - UDP Packet - Source:217.212.238.143,3478 Destination:79.6.33.147,56212 - [DOS]
> Tue, 2012-06-19 17:46:12 - UDP Packet - Source:96.6.40.7,3478 Destination:79.6.33.147,56212 - [DOS]
> Tue, 2012-06-19 17:46:13 - UDP Packet - Source:217.212.238.143,3478 Destination:79.6.33.147,56212 - [DOS]
> Tue, 2012-06-19 17:46:13 - UDP Packet - Source:146.82.184.12,3478 Destination:79.6.33.147,56212 - [DOS]
> Tue, 2012-06-19 17:46:13 - UDP Packet - Source:96.6.40.7,3478 Destination:79.6.33.147,56212 - [DOS]
> Tue, 2012-06-19 17:46:13 - UDP Packet - Source:146.82.184.12,3478 Destination:79.6.33.147,56212 - [DOS]
> Tue, 2012-06-19 17:46:14 - UDP Packet - Source:217.212.238.143,3478 Destination:79.6.33.147,56212 - [DOS]
> Tue, 2012-06-19 17:46:14 - UDP Packet - Source:96.6.40.7,3478 Destination:79.6.33.147,56212 - [DOS]
> Tue, 2012-06-19 21:32:54 - Administrator login successful - IP:192.168.0.4
> Tue, 2012-06-19 21:38:09 - Administrator login successful - IP:192.168.0.4
Ho cercato gli indirizzi in questione e ho scoperto che molti, se non tutti, passano per i server dell'Akamai, in america, qualcuno pure ad Amsterdam.
La cosa va avanti da 3 giorni e io non riesco nemmeno a vedermi un video di 2 minuti (si 2 non mi sono sbagliato a scrivere) su youtube, ne ho leggermente piene le pelotas...
Premetto che ho gia passato il pc con Avira, MSE, MbAm, tool di rimozione rootkit di Kaspersky, tool di rimozione rootkit di Avast e ComboFix.
Tutto quello che di malevolo c'era è stato eliminato, sempre se qualcosa vi era davvero.
Se qualcuno ha qualche consiglio costruttivo e utile lo prego di farsi avanti perchè qui non so più dove sbattere la testa, inoltre il router dopo il log che vi ho postato non ha più rilevato niente,
ma la rete continua a cadere ugualmente.
PS: So bene che attacchi di tipo DoS non possono essere fermati definitivamente, quindi cerco un metodo per almeno limitarli al minimo.