Gnutella Forums

Gnutella Forums (https://www.gnutellaforums.com/)
-   Open Discussion topics (https://www.gnutellaforums.com/open-discussion-topics/)
-   -   virus files (https://www.gnutellaforums.com/open-discussion-topics/19044-virus-files.html)

fryer February 14th, 2003 04:23 AM

virus files
 
there is now a person on limewire who is on nearly every search i do the files are (fullwebinstaller.rar 1.167kb)(aV checked.zip 1.186kb)
(installer.exe 252kb) asf 378kb (the real thing mp3 378kb) (awesome mp3 378kb)
(please share!!! mp3 378kb) and mostly from location 38.144.198.150 has the trogan horse virus
YOU HAVE BEEN WARNED AND IS THERE ANY WAY TO GET THIS PRAT KICKED OFF

fryer69 February 14th, 2003 04:40 AM

part 2
 
the above post is mine forgot my user name :(
anyways i have downloaded one of the above mentioned files it has a click me first file that sets of the trojan horse virus (i used the zip file as all extracted files are scanned by norton and it just kills the file dead also i extract to a safe partition not C:) it is also the german porn dialer so 2 virus in one not bad for a total Wa***r any way the way i stopped it was to use startup manager it killed it dead so i could just delete all the relevate files

just like to say i have down loaded some fantastic stuff of limewire memturbo being one of the best :p

Julie Z February 14th, 2003 09:18 AM

Re: virus files
 
Quote:

Originally posted by fryer
there is now a person on limewire who is on nearly every search i do the files are (fullwebinstaller.rar 1.167kb)(aV checked.zip 1.186kb)
(installer.exe 252kb) asf 378kb (the real thing mp3 378kb) (awesome mp3 378kb)
(please share!!! mp3 378kb) and mostly from location 38.144.198.150 has the trogan horse virus
YOU HAVE BEEN WARNED AND IS THERE ANY WAY TO GET THIS PRAT KICKED OFF

They can't be "kicked off" as LimeWire isn't private. However, you can block them by going to Filter Hosts in your LimeWire options. Enter all the IP addresses of these files and they won't show up anymore.

fryer69 February 15th, 2003 12:26 AM

julie z
thx for that am still learning all the tricks in limewire ;)

Coast Wizard February 15th, 2003 06:55 AM

Thanks for your posting about the files containing a virus. I had been getting the same files every time a ran a search, but I never downloaded any of them because their small kb size made me suspicious that they were bogus.

After I read your posting, I entered the IP addresses in "block host" and it seems to have done the trick.

You're a good man, Charlie Brown!!!

Coast Wizard

JennyBlok February 19th, 2003 08:22 PM

if that doesn't work...
 
just filter out all the words this person uses
like (awesome!!!) or (please share!) etc.
and that should do it.

when i tried to find out the host it doesn't give me a chance so this is the only way i know how to stop it.


cheers!

irregularjoe February 19th, 2003 09:48 PM

see my post above this one. This idiot is not just on LW. I'm going to enter the address in my filter. But it would be nice if LW did something about it too. Took me 8 hours to clean out my computer from the trojans.

irregularjoe February 19th, 2003 10:00 PM

how can I see the address of this a$$hole BEFORE I download? I just did a search for Edit again and got 27 results that all seem to be from the same moron with the trojans. But how can I get the address?

irregularjoe February 19th, 2003 10:09 PM

ok. I just added the ip "38.144.198.150" to the block list. It seems to have worked. I did the same search and this time only got one result that seems legit. Thanks for that address. But my question is how can I find the address the next time one of these a$$holes does this?

Julie Z February 20th, 2003 01:09 PM

I don't know which combinations of keys to use on PC, but for Mac it's: control-click on one of the column headings (such as Name, Quality, #...) and a drop-down menu will show. Click on Location.

If anyone knows the keys for PC, please post it so others can do this.

Thanks! :D

irregularjoe February 20th, 2003 01:33 PM

thanks Julie. I use a PC. I'll try a few ctrl combinations.

Limey224 February 25th, 2003 09:11 AM

idiot tojan spreader
 
Heres the WHOIS for that IP

_____

[whois.arin.net]

OrgName: Performance Systems International Inc.
OrgID: PSI
Address: 1015 31st Street, NW
City: Washington
StateProv: DC
PostalCode: 20007
Country: US

NetRange: 38.0.0.0 - 38.255.255.255
CIDR: 38.0.0.0/8
NetName: PSINETA
NetHandle: NET-38-0-0-0-1
Parent:
NetType: Direct Allocation
NameServer: NS.PSI.NET
NameServer: NS2.PSI.NET
NameServer: NS5.PSI.NET
Comment:
RegDate: 1991-04-16
Updated: 2002-08-08

TechHandle: PSI-NISC-ARIN
TechName: PSINet, Inc.
TechPhone: +1-518-283-8860
TechEmail: hostinfo@psi.com

OrgAbuseHandle: COGEN-ARIN
OrgAbuseName: Cogent Abuse
OrgAbusePhone: +1-877-875-4311
OrgAbuseEmail: abuse@cogentco.com

OrgNOCHandle: ZC108-ARIN
OrgNOCName: Cogent Communications
OrgNOCPhone: +1-877-875-4311
OrgNOCEmail: noc@cogentco.com

OrgTechHandle: IPALL-ARIN
OrgTechName: IP Allocation
OrgTechPhone: +1-202-295-4200
OrgTechEmail: "ipalloc@cogentco.com"@nospam.com

_____

Maybe we can get the jerk kicked from his ISP...

irregularjoe February 26th, 2003 11:16 AM

everyone should forward those idiotic Nigerian "you've been selected to inherit 10 million dollars" email scams to the address of this trojan spreader!


All times are GMT -7. The time now is 02:37 PM.

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 ©2011, Crawlability, Inc.

Copyright © 2020 Gnutella Forums.
All Rights Reserved.