Results 1 to 11 of 11

Thread: Ah, the good ol' ISP problems

  1. #1
    Mr. Boardburner
    Join Date
    Jun 2005
    Location
    the Netherlands
    Posts
    5,340

    Ah, the good ol' ISP problems

    I woke up this morning and noticed I was disconnected from the net by my ISP. They told me too look in my mailbox for more details. This is what they sent me:

    Official warning for distributing wormviruses by ip xxx.xxx.xxx.xxx
    Dear customer,

    In response to complaints we recieved, we have temporarily disabled your internet service. We noticed your IP to be distributing wormviruses over the internet. Logs this, traffic that, blah blah blah.

    You will have to remove the worm by downloading a virusscanner. Blah blah blah.

    We also suggest using a firewall. Blah blah blah.

    If we notice you are still distributing wormviruses in 24 hours, we will have to take action by disabling your service until you have solved your (notice that word) problems. Blah blah blah.


    Sincerely,
    Telfort Internet Abuse

    So I sent them this reply:

    Dear Sir/Madam,

    This email was in my mailbox when I woke up. Of course I did a virus scan on all of my machines, but none of them were infected. I use McAfee 8.5 Corporate with the latest updates installed.
    I would like to know why I got this email. Is it possible that you send me the log files in question so I can examine them myself? I run various distributed computing programs, a webserver and a gameserver. It could be that one of these programs is causing trouble.
    If you cannot confirm the source of the problem, I will consider this email illegitimate. I am willing to 'limit' my internet usage, but I would like to know the source of the problem, for I cannot take action otherwise. I am looking forward to a response.

    Have a nice day,
    Martijn Kruit

    N.B.
    Wormviruses do not exist. It is either a worm or a virus, not both. Worms do not need files to distribute themselves, unlike virusses. Also, worms mostly infect networks, whereas viruses infect software.
    Could MJ12 be the source of the problem? I mean, it is constantly downloading various IPs, then sending data back to a server?
    Last edited by Martijn; 05-22-2008 at 06:07 AM.
    Main rig:
    CPU: I7 920C0 @ 3.6Ghz (180*20)
    Mobo: DFI UT X58 T3eH8
    RAM: 12GB OCZ DDR3-1600 Platinum
    GPU/LCD: GeForce GTX280 + GeForce 8600GTS (Quad LCDs)
    Intel X25-M G2 80GB, 12TB storage
    PSU/Case: Corsair AX850, Silverstone TJ07

  2. #2
    I am Xtreme
    Join Date
    Sep 2007
    Location
    New Jersey, U.S.
    Posts
    2,329
    I'd wait for Movieman to respond since he's the expert, but MJ12 should be completely passive - i.e., no "distribution". Either the 'complaints' are bogus or you've been hacked and your machine is being used as a sporge zombie or something similar. I would call them and try to get to level 2 tech support. Then you can find out what protocols are being used - email, telnet, etc - to do the distribution. That should help narrow down the possibilities. But if you have a decent firewall, I don't see how this could happen.

    The only other thing I can think of is that whoever is sending out this crap is spoofing their ip address and using yours instead, but it would be nice to think that the ISP would have checked and eliminated this possibility before shutting you down.

    Good luck.

  3. #3
    Mr. Boardburner
    Join Date
    Jun 2005
    Location
    the Netherlands
    Posts
    5,340
    Yeah, I got this in return from them:

    Event Date Time, Destination IP, IP Protocol, Target Port, Issue Description, Source Port, Event Count
    EventRecord: 17 May 2008 11:26:52, 70.96.x.x, 6, 445, Sasser/Agobot/GenericBot, 25297, 1
    EventRecord: 17 May 2008 11:26:40, 70.96.x.x, 6, 445, Sasser/Agobot/GenericBot, 25894, 1
    EventRecord: 17 May 2008 11:26:29, 70.96.x.x, 6, 445, Sasser/Agobot/GenericBot, 25577, 1
    EventRecord: 17 May 2008 11:26:04, 70.96.x.x, 6, 445, Sasser/Agobot/GenericBot, 24782, 1
    EventRecord: 17 May 2008 11:24:33, 70.96.x.x, 6, 445, Sasser/Agobot/GenericBot, 21757, 1
    And a lot more, but it definitely means it's not MJ12. Also, they specifically noted that they didn't give a damn about what I did with my internet, which is good .

    Oh well, I've blocked the port and I should be good to go now.
    Main rig:
    CPU: I7 920C0 @ 3.6Ghz (180*20)
    Mobo: DFI UT X58 T3eH8
    RAM: 12GB OCZ DDR3-1600 Platinum
    GPU/LCD: GeForce GTX280 + GeForce 8600GTS (Quad LCDs)
    Intel X25-M G2 80GB, 12TB storage
    PSU/Case: Corsair AX850, Silverstone TJ07

  4. #4
    I am Xtreme
    Join Date
    Sep 2007
    Location
    New Jersey, U.S.
    Posts
    2,329
    According to wikipedia - http://en.wikipedia.org/wiki/List_of...P_port_numbers - port 445 can be either
    445/TCP Microsoft-DS Active Directory, Windows shares
    445/UDP Microsoft-DS SMB file sharing
    So it looks like the malware is targeting filesharing apps.

    I don't know if blocking ports is going to help. Sounds like you still might have an infection. Hopefully some security guys will chime in.

  5. #5
    Xtreme Guru
    Join Date
    Jan 2005
    Location
    waukegan
    Posts
    3,607
    damn ... makes me want to unshare my drive for the network ...
    mobo: strix b350f
    gpu: rx580 1366/2000
    cpu: ryzen 1700 @ 3.8ghz
    ram: 32 gb gskill 2400 @ 3000
    psu: coarsair 1kw
    hdd's: samsung 500gb ssd 1tb & 3tb hdd

  6. #6
    V3 Xeons coming soon!
    Join Date
    Nov 2005
    Location
    New Hampshire
    Posts
    36,363
    This is a new one on me.
    I run MJ12 and do between 3.5-6 million urls a day and no AV on the machines as it slows them down.
    Yea, I know,AV, but we can argue that till the cows come home.
    Crunch with us, the XS WCG team
    The XS WCG team needs your support.
    A good project with good goals.
    Come join us,get that warm fuzzy feeling that you've done something good for mankind.

    Quote Originally Posted by Frisch View Post
    If you have lost faith in humanity, then hold a newborn in your hands.

  7. #7
    Registered User
    Join Date
    Mar 2006
    Location
    Livingston, Scotland
    Posts
    635
    I occasionally get grief from one particular domain, .RU. Always flags up dodgy virii, trojans etc for some weird ass domain names.

    Bar that, never had any issues.
    < MB / CPU > Asus X99 Pro / Intel Core i7 5820K
    < MEM / GFX >Corsair Vengeance 16GB DDR4 / EVGA GeForce GTX 780 Ti SC ACX
    < PSU / HSF > OCZ Z-Series 1000W / Phanteks 140PE
    < CASE / OS > Phanteks Enthoo Primo / Windows 7 Home Premium x64
    < STORAGE > Samsung 840 EVO 120GB - Samsung 840 250GB - 2 x Seagate Barracuda 3TB - Intel Intel X25-M 80GB

  8. #8
    Mr. Boardburner
    Join Date
    Jun 2005
    Location
    the Netherlands
    Posts
    5,340
    I've updated all my firwalls again, haven't had any issues since. MJ12 is also going pretty well. I've got it capped at either 800k URLs/20GB since I'll also do some downloading right now.
    Main rig:
    CPU: I7 920C0 @ 3.6Ghz (180*20)
    Mobo: DFI UT X58 T3eH8
    RAM: 12GB OCZ DDR3-1600 Platinum
    GPU/LCD: GeForce GTX280 + GeForce 8600GTS (Quad LCDs)
    Intel X25-M G2 80GB, 12TB storage
    PSU/Case: Corsair AX850, Silverstone TJ07

  9. #9
    Xtreme Enthusiast
    Join Date
    May 2007
    Posts
    649
    Quote Originally Posted by Martijn View Post
    I've updated all my firwalls again, haven't had any issues since. MJ12 is also going pretty well. I've got it capped at either 800k URLs/20GB since I'll also do some downloading right now.
    Good to hear you're back in the game! Come join us in this Friday's MJ12 beatdown

  10. #10
    Mr. Boardburner
    Join Date
    Jun 2005
    Location
    the Netherlands
    Posts
    5,340
    Quote Originally Posted by DeadlyFire View Post
    Good to hear you're back in the game! Come join us in this Friday's MJ12 beatdown
    Overtaking Team Norway : 107.93 Days

    I don't get it?
    Main rig:
    CPU: I7 920C0 @ 3.6Ghz (180*20)
    Mobo: DFI UT X58 T3eH8
    RAM: 12GB OCZ DDR3-1600 Platinum
    GPU/LCD: GeForce GTX280 + GeForce 8600GTS (Quad LCDs)
    Intel X25-M G2 80GB, 12TB storage
    PSU/Case: Corsair AX850, Silverstone TJ07

  11. #11
    It is
    Join Date
    Feb 2005
    Location
    Copenhagen Denmark
    Posts
    2,214
    It's calculated from the last seven days overall gain , divided with seven, on Free-DC's stats. Meaning, the last seven days, there hasn't been a big daily difference. Therefore you will get those big changes, when a new day starts.
    Last edited by Frisch; 05-28-2008 at 05:27 AM.
    ~Opinion about Dogs~~~~~~~Hug~~~~~~~~
    ~~~~
    ________________________________________________

Bookmarks

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •