Search the archive:
YaBB - Yet another Bulletin Board
 
   
 
Page Index Toggle Pages: 1
Send Topic Print
I had a terrible issue (Read 287 times)
Aug 20th, 2006 at 2:57pm

alrot   Offline
Colonel
Freeware Designers Above
All..

Posts: 10231
*****
 
Im not blame anyone but something "funny " has happend while I was in the multiplayer section at 2:30pm -4 gmt My HDD ini Partition section has blow ,I had un-firewallet protection in that moment but I got the antyvirus ad-aware,I lost all my files Im in my son's pc Does anybuddy know why could this happend? ??? Embarrassed Cry


EDIT:Im formatting my hdd & creating  NTFS due that ,I wish it was a hacker who do this ,I don'r bother too much after all I thing I like more my Win xp without SP2,What really worries me how fast and were Did came from,I suspect that may be lamer of is hanging on the web ,I really worrie,I didn't has active it my firewall,so I wish all info you can give me,


EDIT:
A letter to nobuddy But just in case
I an case of any from simv  member forum did it,what you did,first disconect me couple times,then destroy my partition ;ill will tell you that I also can detect their IP  config,and see If your firewall is active and do the same to you,I also knows how to use  "Net Devil" or anyother and do the same BUT this is not my nature,Im not a hacker neither a evil person I ask God to forgives you ,..........everyones know me.......

dear lord only I wish that it didn't came from here,That it simply came  from anywere else, a troyan anything else,anything,but never from people from this place,more than anything, but it was the coincidence that its giving me right now a doubt
« Last Edit: Aug 20th, 2006 at 4:13pm by alrot »  

...

Venezuela
IP Logged
 
Reply #1 - Aug 20th, 2006 at 4:12pm

Fozzer   Offline
Colonel
An elderly FS 2004 addict!
Hereford. England. EGBS.

Posts: 24861
*****
 
Very strange, ALROT....
..especially as you were quite happily flying with us at 18:30 GMT tonight, (Sunday).... Shocked...!

I doubt very much if the problem was caused by anyone here at Sim V....
....more likely a fault on your electrical supply...lightning...?

My SP1 firewall is never on, and I dont have a ROUTER, and I never have any problems in Multiplayer due to other users... Wink...!

I would check your computer hardware/software first... Wink...!

Paul...Multiplayer flying from 18:00 to 21:00 hours GMT....no problems... 8)...!
 

Dell Dimension 5000 BTX Tower. Win7 Home Edition, 32 Bit. Intel Pentium 4, dual 2.8 GHz. 2.5GB RAM, nVidia GF 9500GT 1GB. SATA 500GB + 80GB. Philips 17" LCD Monitor. Micronet ADSL Modem only. Saitek Cyborg Evo Force. FS 2004 + FSX. Briggs and Stratton Petrol Lawn Mower...Motor Bikes. Gas Cooker... and lots of musical instruments!.... ...!
Yamaha MO6,MM6,DX7,DX11,DX21,DX100,MK100,EMT10,PSR400,PSS780,Roland GW-8L v2,TR505,Casio MT-205,Korg CX3v2 dual manual,+ Leslie 760,M-Audio Prokeys88,KeyRig,Cubase,Keyfax4,Guitars,Orchestral,Baroque,Renaissance,Medieval Instruments.
IP Logged
 
Reply #2 - Aug 20th, 2006 at 4:37pm

alrot   Offline
Colonel
Freeware Designers Above
All..

Posts: 10231
*****
 
God Iam glad you show Paul you were there,I know how this thing work,I never had to my self internet like now, so I trust an I didn't activate my firewall (Im so stupid Sad.) I know because you were there,It wont repeat it again (never leave without a firewall) this is could be and advise to other fellows here,the IP the sim IP is public is easy to see by even a stranger a guy that doesn't even know what is flight simulator
Paul the hard drives has (Im sure you know a section to define partition & cluster size etc ; the INI sector)a hacker or a simple  lamber use tools to do this,Now I get it why this SP2 insist to activate antivirus and by defaul they activate you windows firewall

......Friends check and keep always activate a firewall......

Boy...That was fast the hhd make a funny noice and HDD (information,win xp etc was kill in a second)I got partition magic when I boot it NO PARTITION! Jesus Shocked I saw in many other cybers before,but you never learn until happends to you....Paul maybe you antivirus repels this Kind of   attack by not let someone to manipulate your pc from internet ,I download  a free antivirus  Roll Eyes That could be the reason Too,By the moment I can't afford a good antivirus (I ran out of money to have internet Grin well a little just to buy food and the needs)

Anyway still I like to fly in multiplayer Ill join again after I install everything Back....No problem Paul and thanks

Grin Quote:
Paul...Multiplayer flying from 18:00 to 21:00 hours GMT....no problems...
But remember take it easy on me ,when we join Ill have to use the lear45 ,I got use to this one
 

...

Venezuela
IP Logged
 
Reply #3 - Aug 20th, 2006 at 4:49pm

alrot   Offline
Colonel
Freeware Designers Above
All..

Posts: 10231
*****
 
I think I got your IP dude! 68.217.232.217 your server is bell south server u using adsl,! Ill cach you ,you have no Idea with who are u dealing with Im tracking you ,your so stupid that you did it again,I assing the same IP in my pc to see if you were so stupid to do it again,Im using BlackICE this time



EDIT:How is the weather In augusta ,Georgia pal?
« Last Edit: Aug 20th, 2006 at 8:40pm by alrot »  

...

Venezuela
IP Logged
 
Reply #4 - Aug 21st, 2006 at 8:36am

-sam-   Offline
Colonel
. .. ...
EDDM

Gender: male
Posts: 608
*****
 
Hello Alrot,

A pitty that your first multiplayer experience ended like that.
But I highly doubt that was the result of a "hack".
This sounds like a mechanical failure to me.
People flying on a FS Server cannot see your IP Adress.
And it would need a good sniffer and a big portion of luck
to find it out. Hackers usually donīt break into a system
to delete it... but to misuse it for their purpose (bottnets, spam... downloaders etc.). Nearly every Trojan Virus out there must be activated in some way. That means you have
to click on an attachement or you have to visit a manipulated website
that uses some security hole to infect your system.
In that case a firewall wonīt protect you from beeing infected. It just can stop a Trojan from sending home.

To check if someone broke into your system you should
do the following. First check if your Administrator User still has the full rights (Some Trojans/Rootkits remove certain rights from Administrator Users in an infected system)
. Open the task manager and see if you are able to close "svchost.exe" Tasks. These are system Tasks that only can be terminated by a real Administrator. This might
cause a reboot of your system.. but donīt worry.. itīs just for testing.

Next take a look into your User configuration
and look if one or more (unknown) Users were created.

Search your systems for files that were created
on that specific date (the day your HD crashed).
Just use the search function of the windows Explorer.
It has an Option to search for files created on a specific date.
If you find such a suspected file, scan it with your antivirus
or use this exellent website
http://virusscan.jotti.org/
where you can upload files that are than scanned by 15 different antivirus engines.

Check your system with anti rootkit Software like
Blacklight from F-Secure.
http://www.f-secure.com/blacklight/
or
http://www.sysinternals.com/Utilities/RootkitRevealer.html
Be carefull some copyright protection systems like "Starforce" (used by some games) use rootkits, too. Removing one of those "legal" Rootkits might cause problems with the Software using it.

You can use the Software "Hijackthis" to see if something
was changed in your Windows Registry.
http://www.merijn.org/downloads.html
This software writes out a log file. I suggest you use a
forum like
http://forum.hijackthis.de/ ; (They have an english forum, too) to post this log file. The Professionals there usually can tell you if somethingīs wrong with you Registry.

If you have the feeling there is still something going on in
your system. You can use a software like
"PIAFCTM"
http://www.zdnet.de/downloads/prg/u/x/de0DUX-wc.html
to monitor your network traffic.
But you must know. Nowadays there are hundreds.. of script kiddies scanning the internet for open systems.
So when using a software like this you will notice dozens of scans coming in from various IP Adresses. This is unfortunately called "normal" nowadays.
So you really should know wich port/pattern you have to pay attention to.

Get a good free Antivirus Software like AV
http://www.free-av.de/down/windows/antivir_workstation_win7u_de_h.exe ;
or Bitdefender
http://www.bitdefender.de/site/Main/view/Download-Free-Products.html
Keep it up to date.. and scan regular.

In general I suggest having XPAntispy installed on your system. This is actually not a protection against Viruses or
Hacker. But it closes a lot of little gaps and disables useless things.
http://xp-antispy.org/index.php?option=com_remository&func=sellang&iso=en

Striking back.. is a very bad idea !!!!!!!
(Next to the fact that we are all peacefull adults there are other good reasons)
I donīt know how you came to the IP Adress you posted before. But this is a DYNAMIC !! IP Adress. So if you attack this IP after a while, youīll probabely attack someone else who has no clue whatīs going on !! It also could be just
another infected system that does portscans without the knowledge of its owner (those Zombie PCīs).
Against a dynamic IP you have barrely a chance to do something against. If you get continous attacks from dynamic IP Adresses of a certain provider. You might have a very little chance that the provider gets active.. when contacted. But this is not very usual.

If you follow all these steps you should at least know
if youīve been hacked or not. If you really find something suspecious... Save yourself a lot of problems and reinstall the system from scratch. Itīs easy to delete suspisious
software from system, but itīs hard to say what other
security holes it might have opened..

cheers,
sam (who still doesnīt use a firewall himself  Roll Eyes )

ps.. anyway hope to see you online soon !!

 

NFo/Simviation Multiplayer Server.&&&&fs.netfrag.org:23456&&&&Stats: fs.netfrag.org&&Teamspeak: ts.netfrag.org
IP Logged
 
Reply #5 - Aug 21st, 2006 at 12:00pm

alrot   Offline
Colonel
Freeware Designers Above
All..

Posts: 10231
*****
 
Wow Thats quite work -sam- is really nice gestoure from you ,Im downloading and follow all yor advises This was a letter I send to Paul I think It Talks by it self Of how I screw it ,I feel embarazed Now ,how a dummy became a paranoic  Embarrassed..you know that when something suddenly a bad thing happend to a human this one wont never think strait ,I was about to  blame my own people ,because my own stupidity,The guilty Myself Embarrassed Embarrassed Embarrassed Embarrassed I was specting Ozzy , Fly2e,and even the Pete Itself and get a strong argue from them wich I really deserve Embarrassed Instead I receive a Paul nice advises and your Post (Thank you Sam)


Quote:
I know Paul,I took a deep breAth when I notice that it didn't came from SimV ,I post it ,It cames from an spyware an maybe was the free antivirus(ad-aware) I install ,or maybe is this D$mm SP2 ,but what Im sure it wasn't and expontaniuly ,Im very embarazed to what I said ,but was the D$mm coincidence,It happend right I was kick a the third time ..D$MM

,C'mon Grin I can get kick as many times the server wants Grin but at that moment what really really chap afraid me was Could be someone from simv? Arrrg Im so Idiot, Sad
after that I format my hdd and xp I put the same IP and reinstal fs9 quickly I put a server software who check and detect all spywares and it locations around the globe,I catch one ,thats when I wrongly post the thing of the guy of georgia,15 minutes late I realize that I have like 20 more,Im so moron ,I wish I can delete that thread Paul.....
maybe was a hacker(not from SimV),maybe was the antivirus,maybe was a virus it self (the fast ones)
But never by electricity or a mistake i made,Anyway I can erase format anytime;i just was scare that it came from simv,You know what I get to think(Jesus this also embarazing to tell you too) maybe I was banned because Im not authorize to use the ip from simv,Im became a paranoic Grin..you know that when something suddenly a bad thing happend to a human this one wont think strait ,I made a mistake Chap and Im really embarazed  Embarrassed
I behave as a child.. Embarrassed

sam I wont for any reason harm (even with a 100% sure) no one Im not violent Im very peacefull,I just wanna to show (tipycal from a child ,a 41 year old child)to the ghost in my mind of this simv Hacker  Roll Eyes that I got his address that I got the power to track him,this is a jerks behave(me),Just to scary him ,To scary no one.., a ghost  in my silly mind...Ill record your post,I think is very important advise even for other people too....
 

...

Venezuela
IP Logged
 
Reply #6 - Aug 21st, 2006 at 12:14pm

alrot   Offline
Colonel
Freeware Designers Above
All..

Posts: 10231
*****
 
This is to make fun of myself of my stupidity you gave me many good links, Don't you got a link too from a good psiquiatric,or insane center  Grin Grin Grin

Cheers
 

...

Venezuela
IP Logged
 
Reply #7 - Aug 21st, 2006 at 5:08pm

Arnimon   Offline
Colonel
Whats up Bugs?
Germany

Gender: male
Posts: 345
*****
 
Quote:
Don't you got a link too from a good psiquiatric,or insane center


I think this it not necessary anymore.You just healed yourself by "self reflection"! Wink
 

It looks like chicken,smells like chicken,tastes like chicken,but when Chuck Norris says its Beef...then damnit...its Beef!!!
IP Logged
 
Page Index Toggle Pages: 1
Send Topic Print