GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   My IP Changed. Spyware or Virus?? (https://gfy.com/showthread.php?t=141871)

boneprone 06-11-2003 02:45 AM

Testing My IP
 
yo

boneprone 06-11-2003 02:50 AM

WTF..

some spyware has changed my ip to

The IP Address is: 4.4.17.37. The host name is: PPPa40-City-3R7008.dialinx.net. Please click here to return to the thread.

What the fuck?
THats in the UK..

Whats going on here.

I use Verizon DSL.

Not uk dialup

funkmaster 06-11-2003 02:51 AM

donīt worry, itīs just a $25/min dialer !!

funkmaster 06-11-2003 02:52 AM

... just checked on ICQ ... your IP is in fact: <b>4.4.17.37</b>


OrgName: Genuity
OrgID: GNTY
Address: Genuity
Address: 225 Presidential Way
City: Woburn
StateProv: MA
PostalCode: 01888
Country: US

NetRange: 4.0.0.0 - 4.255.255.255
CIDR: 4.0.0.0/8
NetName: GNTY-4-0
NetHandle: NET-4-0-0-0-1
Parent:
NetType: Direct Allocation
NameServer: DNSAUTH1.SYS.GTEI.NET
NameServer: DNSAUTH2.SYS.GTEI.NET
NameServer: DNSAUTH3.SYS.GTEI.NET
Comment:
RegDate:
Updated: 2002-05-02

TechHandle: CS15-ARIN
TechName: Soulia, Cindy
TechPhone: +1-800-436-8489
TechEmail: [email protected]

OrgAbuseHandle: ABUSE23-ARIN
OrgAbuseName: Abuse
OrgAbusePhone: +1-800-436-8489
OrgAbuseEmail: [email protected]

OrgNOCHandle: NOC119-ARIN
OrgNOCName: NOC
OrgNOCPhone: +1-800-436-8489
OrgNOCEmail: [email protected]

OrgTechHandle: CS15-ARIN
OrgTechName: Soulia, Cindy
OrgTechPhone: +1-800-436-8489
OrgTechEmail: [email protected]

OrgTechHandle: ARINC4-ARIN
OrgTechName: ARIN Contact
OrgTechPhone: +1-800-436-8489
OrgTechEmail: [email protected]

# ARIN WHOIS database, last updated 2003-06-10 21:05
# Enter ? for additional hints on searching ARIN's WHOIS database.

OrgName: Genuity
OrgID: GNTY
Address: Genuity
Address: 225 Presidential Way
City: Woburn
StateProv: MA
PostalCode: 01888
Country: US
Comment:
RegDate:
Updated: 2002-12-02

AbuseHandle: ABUSE23-ARIN
AbuseName: Abuse
AbusePhone: +1-800-436-8489
AbuseEmail: [email protected]

AdminHandle: CS15-ARIN
AdminName: Soulia, Cindy
AdminPhone: +1-800-436-8489
AdminEmail: [email protected]

NOCHandle: NOC119-ARIN
NOCName: NOC
NOCPhone: +1-800-436-8489
NOCEmail: [email protected]

TechHandle: CS15-ARIN
TechName: Soulia, Cindy
TechPhone: +1-800-436-8489
TechEmail: [email protected]

TechHandle: ARINC4-ARIN
TechName: ARIN Contact
TechPhone: +1-800-436-8489
TechEmail: [email protected]

# ARIN WHOIS database, last updated 2003-06-10 21:05
# Enter ? for additional hints on searching ARIN's WHOIS database.

boneprone 06-11-2003 02:53 AM

dude, dialinx.net
what the fuck is that?

funkmaster 06-11-2003 02:55 AM

Quote:

Originally posted by boneprone
dude, dialinx.net
what the fuck is that?


Domain Name.......... dialinx.net
Creation Date........ 2003-05-06
Registration Date.... 2003-05-06
Expiry Date.......... 2004-05-06
Organisation Name.... Ultimate Search
Organisation Address. GPO Box 7862
Organisation Address.
Organisation Address. Central
Organisation Address. NA
Organisation Address. HK
Organisation Address. HONG KONG

Admin Name........... DNS Support
Admin Address........ GPO Box 7862
Admin Address........
Admin Address........ Central
Admin Address........ NA
Admin Address........ HK
Admin Address........ HONG KONG
Admin Email.......... [email protected]
Admin Phone.......... 852 2537 9677
Admin Fax............

Tech Name............ DNS Support
Tech Address......... GPO box 7862
Tech Address.........
Tech Address......... Central
Tech Address......... NA
Tech Address......... HK
Tech Address......... HONG KONG
Tech Email........... [email protected]
Tech Phone........... +1.85225379677
Tech Fax.............
Name Server.......... ns1.ultsearch.com
Name Server.......... ns2.ultsearch.com

funkmaster 06-11-2003 02:57 AM

http://www.dialinx.net/ -> looks like it expired and the guys from Ultimate Search picked it up ...

boneprone 06-11-2003 02:57 AM

I know my ip, and it has never been that!
It just switched to this after my dsl crashed, and i had to reboot.


Then norton security poped up and asked me if i wanter to allow some icq exe shit, and since it said icq i said permit.

Now my ip has changed to this shit!

boneprone 06-11-2003 03:00 AM

i dont get it!
ok heres the strange shit....
When my dsl crashed i rebooted.
when i loged back in norton security went off.
asked me if i wanted to block or permit some kind of access.
it was called something like icq.exe or something.
I thought it was weird because i had not loaded icq yet and why would icq be asking to connect if i had yet to click on it? BUt i clicked permit! and now my ip has changed!

funkmaster 06-11-2003 03:00 AM

Quote:

Originally posted by boneprone
I know my ip, and it has never been that!
It just switched to this after my dsl crashed, and i had to reboot.


Then norton security poped up and asked me if i wanter to allow some icq exe shit, and since it said icq i said permit.

Now my ip has changed to this shit!

... ahhh, donīt worry, everything is fine ... someone just hijacked your puter and probably will install some mail server shortly ... or already has ??

boneprone 06-11-2003 03:02 AM

great

Project-Shadow 06-11-2003 03:03 AM

Call your isp... thats why i love cable..

funkmaster 06-11-2003 03:04 AM

Iīd do a system recovery from yesterdays setting and reboot ... if this doesnīt work Iīd use my latest backup (if you donīt have any: www.danz.com -> retrospect is a great tool)

... if all the above fails -> reinstall

Machete_ 06-11-2003 03:22 AM

All internet connections with a dynamic IP adress can change the IP when you reboot the router/cablemodem

No panic - exept if you ORDERED a fixed IP adress

Vlad PL 06-11-2003 04:11 AM

format C: :Graucho

Vlad PL 06-11-2003 04:13 AM

hehe you propably got dynamic IP , or it`s just your gateway , trojans or any other software CAN'T change your real IP :) , best solution , call your ISP , good luck.:winkwink:

Vlad PL 06-11-2003 04:19 AM

hmm I didn't paid attention about icq thingy , should be your 1025 port , or it`s real ICQ request or you got NetSpy or Maverick?s Matrix or even RemoteStorm trojan :( congrats comrad , use Anti-Trojan 5.5.42 , get firewall (in case you don`t have one) and disable the damn 5000 port (http://grc.com/unpnp/unpnp.htm) :thumbsup

Mr.Fiction 06-11-2003 04:28 AM

Your computer is now a zombie for some 11 year old kid in Hong Kong. Have fun!

goBigtime 06-11-2003 04:44 AM

icq.exe lcq.exe

Icq.exe ^ Lcq.exe

I wonder if it was Lcq.exe

Reak 06-11-2003 05:00 AM

reboot your Pc probely some1 use your IP to make a Fraude

A friend of mine had it before.. its real shit

bigdog 06-11-2003 05:24 AM

hey here you go http://www.apple.com/switch

Herb Kornfield 06-11-2003 05:27 AM

its all about the cable modem


All times are GMT -7. The time now is 04:00 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123