For the last week or so I have noticed intermittent HTML droppoffs, and while not actively researching until today, I have been wondering.
Today I get into my router settings to reboot it, and glance at the logs while I am in there:
Code: Select all
[LAN access from remote] from 99.232.132.62:53916 to 192.168.1.201:57509, Tuesday, October 11,2011 12:21:00
[LAN access from remote] from 90.204.52.250:59466 to 192.168.1.201:57509, Tuesday, October 11,2011 12:21:00
[LAN access from remote] from 184.161.235.77:21196 to 192.168.1.201:57509, Tuesday, October 11,2011 12:20:44
[LAN access from remote] from 187.160.70.51:52832 to 192.168.1.201:57509, Tuesday, October 11,2011 12:20:12
[LAN access from remote] from 67.63.97.73:62899 to 192.168.1.201:57509, Tuesday, October 11,2011 12:20:01
[LAN access from remote] from 71.92.198.65:57102 to 192.168.1.201:57509, Tuesday, October 11,2011 12:19:55
[LAN access from remote] from 131.104.250.225:55798 to 192.168.1.201:57509, Tuesday, October 11,2011 12:19:44
[LAN access from remote] from 142.217.25.117:56836 to 192.168.1.201:57509, Tuesday, October 11,2011 12:19:41
[LAN access from remote] from 68.62.52.30:64009 to 192.168.1.201:57509, Tuesday, October 11,2011 12:19:30
[LAN access from remote] from 201.167.45.144:61819 to 192.168.1.201:57509, Tuesday, October 11,2011 12:19:10
[LAN access from remote] from 83.2.50.49:2430 to 192.168.1.201:57509, Tuesday, October 11,2011 12:19:07
[LAN access from remote] from 71.232.60.250:52078 to 192.168.1.201:57509, Tuesday, October 11,2011 12:18:55
[LAN access from remote] from 78.232.73.123:56752 to 192.168.1.201:57509, Tuesday, October 11,2011 12:18:21
[LAN access from remote] from 97.90.200.89:54106 to 192.168.1.201:57509, Tuesday, October 11,2011 12:18:16
[LAN access from remote] from 71.227.162.16:23260 to 192.168.1.201:57509, Tuesday, October 11,2011 12:18:03
[LAN access from remote] from 24.6.118.29:57851 to 192.168.1.201:57509, Tuesday, October 11,2011 12:17:18
[LAN access from remote] from 76.22.223.34:52215 to 192.168.1.201:57509, Tuesday, October 11,2011 12:16:28
[LAN access from remote] from 71.204.243.59:60373 to 192.168.1.201:57509, Tuesday, October 11,2011 12:16:27
[LAN access from remote] from 76.121.146.97:53431 to 192.168.1.201:57509, Tuesday, October 11,2011 12:16:26
[LAN access from remote] from 86.97.131.81:54262 to 192.168.1.201:57509, Tuesday, October 11,2011 12:16:09
[LAN access from remote] from 79.166.151.15:53120 to 192.168.1.201:57509, Tuesday, October 11,2011 12:16:08
[LAN access from remote] from 27.32.186.17:51858 to 192.168.1.201:57509, Tuesday, October 11,2011 12:15:47
[LAN access from remote] from 72.50.70.211:51030 to 192.168.1.201:57509, Tuesday, October 11,2011 12:15:29
[LAN access from remote] from 124.122.180.226:2031 to 192.168.1.201:57509, Tuesday, October 11,2011 12:14:52
.201 is my main system, the one I am typing on, now. The only reference to port 57509 was a reference in the UPnP settings, that port was directed right at this PC.
I never set up anything to point at this PC in the router, so I don't know what that is.
Does this look like an infection, and did I fix it by disabling UPnP on the router? So far the logs show none of that activity for the last 10 minutes, since I disabled it.[/color]
Edited By GORDON on 1318351497