Home arrow Forum arrow General arrow Chit Chat arrow To: ThreadMaster
To: ThreadMaster
November 22, 2008, 09:21:49 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
 
   Home   Help Search Login Register  
Pages: [1] 2
  Print  
Author Topic: To: ThreadMaster  (Read 10216 times)
0 Members and 1 Guest are viewing this topic.
dsantamassino
Experienced Member
****
Offline Offline

Posts: 122


View Profile
« on: March 02, 2004, 07:50:40 PM »

Hey man. Feel free to edit the subject if u have too or if u think the IP address is for Security procetion u can edit the topic and block it out. I\'m going to copy my whole e-mail below. I have a Blasterworm virus. EDIT: I forgot to mention something. I get this virus even when re-installing a fresh copy of Win XP Pro.



Hi Derek

 

Thank you for the attachments, I can confirm that the trace is complete however I cannot confirm the target you are tracing to verify accuracy as the input has not been included. Are you tracing an IP address (ie n.n.n.n format) or a domain name (ie www.Huh?.Huh Format). I can double check if you would like further confirmation, just email me the target you used and I will further verify if that will help you.

 

MORE WORRYINGLY: Unfortunately you have the blaster worm virus on your system; this may explain why you have been asking about whether the trace is complete as this will cause excessive activity in the table. In the table below on port 135 (marked in red) you will see msblast.exe is communicating. You need to immediately firewall that port (135) and use some virus software to remove the virus. I recommend Symantec but otherwise any major Virus product will work.

-------------------------------------------------------------------------------

From: Derek  
Sent: 01 March 2004 14:16
To:
Subject: Re:

 

Hi,

 

I\'m sending an attachment with 3 of them. Will you tell me from what you see did my trace finish?

----- Original Message -----

From:

To:

Sent: Monday, March 01, 2004 4:22 PM

Subject: RE:

 

Hi Derek,

 

Sorry for the delay, unfortunately we lost power to the house this evening and I had to take my family out for a meal. I think they bribed the power supply company!!

 

Anyway, the answer to your question is no, unlike VisualRoute CallerIP tracks the destination instantly and tells you the location immediately. As soon as you see the cross-hairs the location has been verified. The table at the bottom is really providing a new capability. It is tracking connections to your system in real-time (this is done continuously), the purpose being to alert you to when someone connects to you from the outside. The version you have is beta 5 which cannot distinguish outbound connections (ie you browsing to say yahoo.com) from in bound connections (ie a hacker attacking your system). Basically the table updates as soon as a connection inbound or outbound is established by your computer and it is up to you to know if the connection is good or suspect. CallerIP lets you click on the line item in the table CallerIP will look-up and validate the connecting address. Version beta 6 will be out in the next 24 hours, this version will highlight inbound versus outbound connections. I will send a copy when it passes Quality Assurance.

 

I hope this helps, let me know if not.

 

Best wishes

 

Julian

 


--------------------------------------------------------------------------------

From: Derek
Sent: 01 March 2004 11:43
To:
Subject:

 

Hi,

 

When i see the numbers in the yellow table moving does that mean my trace is done? Or how do i tell if my trace is done?
Logged

My milkshake is better than yours.
PostMaster
Guest
« Reply #1 on: March 02, 2004, 07:59:55 PM »

Derek Did you do a Virus scan?

You can do a free one here, it does this for you:

http://housecall.trendmicro.com/

To me I don\'t think it worked/ the trace.
Logged
dsantamassino
Experienced Member
****
Offline Offline

Posts: 122


View Profile
« Reply #2 on: March 05, 2004, 05:54:27 PM »

Jay,

I remeber some time ago about a month ago. I did a Low Level Format to format my drive at the lowest possible which most people don\'t recommend. I believe it went through every sector on my drive and then i made my partitions using fdisk and formatted them and then re-installed Windows XP Pro and still had the virus. I still do now. That low level should of took care of it. I guess it didn\'t work. Thanx TM..
Logged

My milkshake is better than yours.
PostMaster
Guest
« Reply #3 on: March 05, 2004, 06:18:42 PM »

Quote
Jay,

I remeber some time ago about a month ago. I did a Low Level Format to format my drive at the lowest possible which most people don\'t recommend. I believe it went through every sector on my drive and then i made my partitions using fdisk and formatted them and then re-installed Windows XP Pro and still had the virus. I still do now. That low level should of took care of it. I guess it didn\'t work. Thanx TM..


You sure you didn\'t just do a full scan disk,  You still didn\'t get this Blaster worm fixed?  

If you have reformated the drive then this should have taken care of this, now if you have two partitions and you only formated one and not both then you could still have the virus because of this.  If you like to take care of this once in for all..

Just go ahead and do a full format and delete both partitions and only have one next time and right after this up date your windows with all the patches they now have to provent this, before downloading and browsing the web.

You also have to remember, you can visit certain web site that would cause this, like ? sites or ware sites..  all right from your explorer allowing it to come in.  

Hope you work this out and get it fixed..  and if so please let us know how you did it.

TM
Logged
dsantamassino
Experienced Member
****
Offline Offline

Posts: 122


View Profile
« Reply #4 on: March 05, 2004, 06:43:03 PM »

Like i said it\'s been about a month since i did that low level and that took about 12 hours straight and no it didn\'t take care of it so why would it be fixed if i do a normal format using one of the Windows discs?? When a low level completely formats the whole entire drive just like it came from the factory and that didn\'t fix it but that was about a month ago. And yes i still have the blaster worm virus. When i re-install windows i get the message something about the RPC and restarts my computer when i connect to the internet and not only that but the Blaster worm is no longer active and i still have it. Hope this helps.
Logged

My milkshake is better than yours.
PostMaster
Guest
« Reply #5 on: March 05, 2004, 07:03:11 PM »

Quote
By \"dsantamassino\"
Like i said it\'s been about a month since i did that low level and that took about 12 hours straight and no it didn\'t take care of it so why would it be fixed if i do a normal format using one of the Windows discs??


Because of the Restore feature in XP, it\'s saved info, what affects you now will even doing a system restore a month ago date. Do a full clean sweep, just doing a system format will not do it, you need to wipe the hard drive clean, I think your lucky, some worms can kill your hard drive and leave it impossible to do anything or even start up windows at all.

Quote
When a low level completely formats the whole entire drive just like it came from the factory and that didn\'t fix it but that was about a month ago.


Hmmm do you have a compac?  Or HP or something else.  Did your system come with window XP Pro?

Quote
And yes i still have the blaster worm virus. When i re-install windows i get the message something about the RPC and restarts my computer when i connect to the internet and not only that but the Blaster worm is no longer active and i still have it. Hope this helps.

http://support.microsoft.com/default.aspx?scid=kb;en-us;811576&Product=winxp

&

http://support.microsoft.com/default.aspx?scid=kb;en-us;329080&Product=winxp

About this RPC.  Ok so the Blaster worm is no longer active,  Then your good.  It\'s not causing any more problems.  Did you do a full windows update yet, if not go ahead and do so for your pretection with holes that patches are now out for.

TM
Logged
dsantamassino
Experienced Member
****
Offline Offline

Posts: 122


View Profile
« Reply #6 on: March 05, 2004, 07:09:35 PM »

Quote
Hmmm do you have a compac?  Or HP or something else.  Did your system come with window XP Pro?


I have Cmpaq. No it didn\'t come with Pro. It came with Home version. I like Pro better because home automatically puts it on my C: drive and formats and partitions it for me that\'s why i\'m not using home. What version and what OS r u using?? Thanx..
Logged

My milkshake is better than yours.
PostMaster
Guest
« Reply #7 on: March 05, 2004, 07:22:48 PM »

Quote
I have Cmpaq. No it didn\'t come with Pro. It came with Home version. I like Pro better because home automatically puts it on my C: drive and formats and partitions it for me that\'s why i\'m not using home. What version and what OS r u using?? Thanx..


I have XP Pro Media center and Xp home..  I have other computers but are put away, one has ME, the other If I remember XP home as well.

I always use a firewall and aways keep my virus program up to date, I\'m lucky I havn\'t gotten any viruses now going on 4 years or more.
TM
Logged
afonic
Guest
« Reply #8 on: March 05, 2004, 07:36:54 PM »

If you have an anti-virus and you update it regulary and also if you don\'t open attachments from people you don\'t know, you will never have a virus.

Derek, low level format is a process that is being done in there special situations as bad sectors. Do not do it again without reason. A format /q c: is enough!
Logged
dsantamassino
Experienced Member
****
Offline Offline

Posts: 122


View Profile
« Reply #9 on: March 05, 2004, 07:37:44 PM »

Quote
Quote
I have Cmpaq. No it didn\'t come with Pro. It came with Home version. I like Pro better because home automatically puts it on my C: drive and formats and partitions it for me that\'s why i\'m not using home. What version and what OS r u using?? Thanx..


I have XP Pro Media center and Xp home..  I have other computers but are put away, one has ME, the other If I remember XP home as well.

I always use a firewall and aways keep my virus program up to date, I\'m lucky I havn\'t gotten any viruses now going on 4 years or more.
TM


That\'s cool. I never want viruses..

P.S. thanx for the edit whoever did it. I couldn\'t make a quote like that but i did tried my best to do it. Thanx again!!
Logged

My milkshake is better than yours.
PostMaster
Guest
« Reply #10 on: March 05, 2004, 07:55:27 PM »

Quote
That\'s cool. I never want viruses..

P.S. thanx for the edit whoever did it. I couldn\'t make a quote like that but i did tried my best to do it. Thanx again!!


You can learn here, just to many quotes over your one reply within the quotes.  You can learn here how to use them.
http://dvd-guides.com/forum/faq.php?mode=bbcode
Logged
dsantamassino
Experienced Member
****
Offline Offline

Posts: 122


View Profile
« Reply #11 on: March 05, 2004, 07:58:53 PM »

I was reading it about quotes and it looks way too confusing. I still don\'t understand how to do it. Should i make another topic about it??
Logged

My milkshake is better than yours.
dsantamassino
Experienced Member
****
Offline Offline

Posts: 122


View Profile
« Reply #12 on: March 05, 2004, 08:01:52 PM »

Quote
If you have an anti-virus and you update it regulary and also if you don\'t open attachments from people you don\'t know, you will never have a virus.

Derek, low level format is a process that is being done in there special situations as bad sectors. Do not do it again without reason. A format /q c: is enough!


Ok man i won\'t do it again..
Logged

My milkshake is better than yours.
PostMaster
Guest
« Reply #13 on: March 05, 2004, 08:16:26 PM »

Quote

I was reading it about quotes and it looks way too confusing. I still don\'t understand how to do it. Should i make another topic about it??[//quote]

Ok I\'m replying to you and make it so you can see, if you look at the last quote I have added two // which you would only need one

If you do it just like this it will look like this, remember not to use two // just one.
Quote
I was reading it about quotes and it looks way too confusing. I still don\'t understand how to do it. Should i make another topic about it??
Logged
dsantamassino
Experienced Member
****
Offline Offline

Posts: 122


View Profile
« Reply #14 on: March 05, 2004, 08:18:49 PM »

I still don\'t understand it at all.
Logged

My milkshake is better than yours.
Pages: [1] 2
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC Valid XHTML 1.0! Valid CSS!
Page created in 0.129 seconds with 17 queries.