Any help is appreciated.

DigitalCancer

Diamond Member
Apr 6, 2004
3,726
0
76
Ok...heres the deal, i have 3 computers on my network. All running XP Pro.

I got THIS screen awhile back and i fixed it by just unplugging the modem for a bit. Well, it came back a 2nd time, i done the same thing to fix it. Then the 3rd time (all this over a course of months) and it didn't come back. I had to call tech support, which let me know that i was QUARANTINED!

So..she (christy) gives me a 3 week grace period, if problem still exists, then i'm banned from internet.
I believe my bro-in-law's comp to be the culprit and we put a firewall on it and all that good stuff, close all the open ports he had and...its fixed.

I call this christy chick again after running for a week, and she says its fine, no activity, i tell her to call me if anything comes up and she says 'ok'. <-- this was a few days ago.

Well, last night around 9p, the net went out. Resetting did not help, i was yet again QUARANTINED! So i call (still haven't gotten hold of her and its 10am, something about a meeting. BUT...my net just now came back on, out of nowhere.

What good programs are out there to see if i have actually been invaded somewhere?? I've ran netstat /d to check open ports, i have nothing useful. Last time the bro-in-law comp had tons of smtp ports open so i believe it was his comp that was doing the spamming. PLEASE help me out here, if i don't get it fixed, i lose the internet. =/
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
If you have a router, which I figure you do since you have three computers, then you might want to lock all non-essential ports and then look at its logs to see what it's blocking. It might be good to initially block all ports except 53 (DNS) and 80 (standard HTTP) so you can look for port 25 (SMTP email), in case one of your systems is a spam bot. The logs should help you nail down which computer is being bad.

Also, scan the computers with some rootkit-detection tools. Panda and F-Secure have easy-to-use ones. And scan them with good antivirus software after maxing out all the detection settings.

Also, if you have a wireless setup, make sure it's secured with at least WEP or preferably WPA or WPA2 encyrption, so neighbors can't connect to it and get you in trouble with their spam-bots.
 

DigitalCancer

Diamond Member
Apr 6, 2004
3,726
0
76
wow...i checked the log with my router...i know that the last malware used port 17112 right? (lady told me) When i checked the logs...i get:

Source IP Destination Port Number
221.12.113.242 1026
221.209.110.7 1027
221.209.110.7 1026
60.12.166.2 1027
60.12.192.38 1026
60.12.192.38 1027
218.27.148.74 1026
201.170.36.119 17788
221.208.208.91 1027
221.208.208.91 1026
76.182.222.124 51810
60.12.166.198 1026
201.170.36.119 17788
202.97.238.202 1027
221.12.113.247 1027
221.12.113.247 1026
202.97.238.201 1027
201.170.36.119 17788
60.11.125.51 1026
221.208.208.99 1027
81.105.235.198 48092
221.12.113.238 1026
221.12.113.238 1027

So...my question is..how do i find out which computer (theres only 3) that the 201.170.36.119 belongs to???
 

Medea

Golden Member
Dec 5, 2000
1,606
0
0
So...my question is..how do i find out which computer (theres only 3) that the 201.170.36.119 belongs to???

red-corp-201.170.36.119.telnor.net (201.170.36.119)

201.170.0.0 - 201.170.127.255
Telefonos del Noroeste S.A. de C.V.
Pio Pico, 2101,
22000 - Tijuana - BC
Mexico
Brazil
+52 664 6332215 []
Created on 27-10-2006
Last updated on 27-10-2006

Operacion Internet TELNOR
rone@TELNOR.COM
Pio Pico, 1525,
22000 - Tijuana - BC
Mexico
Brazil
+52 664 6332215 []
Created on 09-12-2002
Last updated on 11-04-2006


 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Originally posted by: DigitalCancer
wow...i checked the log with my router...i know that the last malware used port 17112 right? (lady told me) When i checked the logs...i get:

Source IP Destination Port Number
221.12.113.242 1026
221.209.110.7 1027
221.209.110.7 1026
60.12.166.2 1027
60.12.192.38 1026
60.12.192.38 1027
218.27.148.74 1026
201.170.36.119 17788
221.208.208.91 1027
221.208.208.91 1026
76.182.222.124 51810
60.12.166.198 1026
201.170.36.119 17788
202.97.238.202 1027
221.12.113.247 1027
221.12.113.247 1026
202.97.238.201 1027
201.170.36.119 17788
60.11.125.51 1026
221.208.208.99 1027
81.105.235.198 48092
221.12.113.238 1026
221.12.113.238 1027

So...my question is..how do i find out which computer (theres only 3) that the 201.170.36.119 belongs to???
Easy. Hook up one computer at a time and watch the logs.

 

engineereeyore

Platinum Member
Jul 23, 2005
2,070
0
0
Originally posted by: mechBgon
Originally posted by: DigitalCancer
wow...i checked the log with my router...i know that the last malware used port 17112 right? (lady told me) When i checked the logs...i get:

Source IP Destination Port Number
221.12.113.242 1026
221.209.110.7 1027
221.209.110.7 1026
60.12.166.2 1027
60.12.192.38 1026
60.12.192.38 1027
218.27.148.74 1026
201.170.36.119 17788
221.208.208.91 1027
221.208.208.91 1026
76.182.222.124 51810
60.12.166.198 1026
201.170.36.119 17788
202.97.238.202 1027
221.12.113.247 1027
221.12.113.247 1026
202.97.238.201 1027
201.170.36.119 17788
60.11.125.51 1026
221.208.208.99 1027
81.105.235.198 48092
221.12.113.238 1026
221.12.113.238 1027

So...my question is..how do i find out which computer (theres only 3) that the 201.170.36.119 belongs to???
Easy. Hook up one computer at a time and watch the logs.

Good idea. To make sure you get plenty of hits in your log, you may wish to restart the computer and open the web browser on the the computer. Any type of spyware or viruses will typically do a lot of communicating and port establishment when the computer initially starts. However, if it's as bad as you say, you should be able to see plenty of traffic without needing to restart.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |