JessicaJoy Posted March 23, 2011 Share Posted March 23, 2011 HG | Grizzly cannot access the website without a Proxy. Here is the conversation. I hope someone can help. Wednesday, March 23, 2011 12:11 AM - HG | GRIZZLY: I have not been able to get on the website since Sunday night and on Sunday it was ruff. When I type http://www.hellsgamers.com I get sent top Google, so i click on one of the links and nothing happens. i can get on any other site I frequent, so I'm wondering where the problem is or if you have heard of sucj a problem. if not, could you direct me to who, thanks Grizz. 12:12 AM - HG | JessicaJoy: try searching hellsgamers in google 12:12 AM - HG | JessicaJoy: and click on the link 12:13 AM - HG | GRIZZLY: This is what I get 12:13 AM - HG | GRIZZLY: Internet Explorer cannot display the webpage 12:13 AM - HG | JessicaJoy: Hold on 12:13 AM - HG | JessicaJoy: http://www.proxywebsite.org/ 12:14 AM - HG | JessicaJoy: go there 12:14 AM - HG | JessicaJoy: and type in hellsgamers.com 12:14 AM - HG | JessicaJoy: see if you can get to it through a proxy 12:14 AM - HG | GRIZZLY: I clicked on dianose problem and said problem found 12:15 AM - HG | GRIZZLY: Your computer appears to be correctly configured, but the device or resource is not responding 12:15 AM - HG | GRIZZLY: trying proxy thing now 12:15 AM - HG | JessicaJoy: If you can get to it through there, then post on the forums 12:17 AM - HG | GRIZZLY: I can see the front page, home page. i clicked on forum link and it sent me here 12:17 AM - HG | GRIZZLY: http://www.strap-ongym.com/ 12:17 AM - HG | JessicaJoy: lawl 12:17 AM - HG | JessicaJoy: is it saying something? 12:17 AM - HG | GRIZZLY: I need to excercise? 12:17 AM - HG | JessicaJoy: Haha 12:17 AM - HG | JessicaJoy: jk M3 12:17 AM - HG | JessicaJoy: <3* 12:18 AM - HG | GRIZZLY: the home page does not have an option to log in either 12:18 AM - HG | JessicaJoy: humm ...let me see ..I will post something for you. 12:21 AM - HG | GRIZZLY: I will say I banned a guy for one hour on Sunday from D2DM. He was having a bitch fest with BirdFlu, this was going on for more than an hour. i took a vote on who to ban, he lost. He was threatening BirdFlu he was going to hack his steam account or computer I don't know but I'm begining to wonder if he has something to do with this. He requested to be in my friends list but is now gone. his steam name was recon-ward. Quote Link to comment Share on other sites More sharing options...
Homer Posted March 23, 2011 Share Posted March 23, 2011 He should be unbanned now. Ask him why his computer is spamming the website on port 500 Time: Sun Mar 20 18:46:44 2011 -0400 IP: 74.199.xx.xx (US/United States/d199-74-xx-xx.try.wideopenwest.com) Hits: 11 Blocked: Temporary Block Sample of block hits: Mar 20 18:42:10 master kernel: Firewall: *UDP_IN Blocked* IN=eth0 OUT= MAC=00:22:15:d6:xx:xx:xx:xx:xx:xx:62:80:08:00 SRC=74.199.xx.xx DST=66.225.231.6 LEN=364 TOS=0x00 PREC=0x00 TTL=116 ID=9103 PROTO=UDP SPT=500 DPT=500 LEN=344 He will get banned again if this continues.. Quote Link to comment Share on other sites More sharing options...
Homer Posted March 23, 2011 Share Posted March 23, 2011 Grizzly you might have a trojan. http://www.computing.net/answers/security/port-5000-/6198.html Quote Link to comment Share on other sites More sharing options...
JessicaJoy Posted March 23, 2011 Author Share Posted March 23, 2011 I will make sure to let him know. Thanks very much Homer! Quote Link to comment Share on other sites More sharing options...
JessicaJoy Posted March 23, 2011 Author Share Posted March 23, 2011 Grizzly was unbanned for a short time, but then was banned again. He doesn't know what is going on. He messaged me to see if I could get a hold of Terry to see if he can help. He also wanted me to post in this thread again. If you guys have any help for him, please message him on steam. He doesn't know what to do. 2:13 PM - HG | GRIZZLY: maybe someone knows what this is. 2:13 PM - HG | GRIZZLY: http://zhost.hellsgamers.com/u/yb/log.png 2:14 PM - HG | JessicaJoy: I will post it in the thread Quote Link to comment Share on other sites More sharing options...
GRIZZLY Posted March 23, 2011 Share Posted March 23, 2011 I deleted that file in that picture and I'm back. Jessica, thank you for taking the time to help me (again, again...) much appreciated. Quote Link to comment Share on other sites More sharing options...
enigma# Posted March 23, 2011 Share Posted March 23, 2011 (edited) hey grizz you can make sure it is not sending anything through that port http://www.grc.com/port_500.htm there's a button called "Probe this Port", click it It should be either Closed or Stealthed. let us know if the results of that too Edited March 23, 2011 by enigma# opps port 500 not 5000 Quote Link to comment Share on other sites More sharing options...
GRIZZLY Posted March 23, 2011 Share Posted March 23, 2011 ShieldsUP! Internet Port Vulnerability Profiling by Steve Gibson, Gibson Research Corporation. Probing Your Port 500 The GRC server is attempting to establish a TCP connection to Port 500 of your computer located at Internet at IP address 74.199.33.198: Port Status Protocol and Application 500 Stealth isakmp Internet Security Association and Key Management Protocol (ISAKMP) This is the 1st time I can remember installing or running a virus program on my computer. Question, is it possible the steam name I mentioned above could have sent this file? (I'm doubting it) Quote Link to comment Share on other sites More sharing options...
enigma# Posted March 24, 2011 Share Posted March 24, 2011 Looks okay, if you want to double check go to Start -> run -> Type in "cmd.exe" (without the quotes) type in the Command Prompt netstat -an check that none of them have line that say something like this TCP xxxx.xxxx.xxxx.xxxx:500 xxxx.xxxx.xxxx.xxxx:n LISTENING TCP xxxx.xxxx.xxxx.xxxx:500 xxxx.xxxx.xxxx.xxxx:n ESTABLISHED TCP xxxx.xxxx.xxxx.xxxx:500 xxxx.xxxx.xxxx.xxxx:n TIME_WAIT n = any port xxxx = ip address other than 0.0.0.0 or [..] Quote Link to comment Share on other sites More sharing options...
GRIZZLY Posted March 26, 2011 Share Posted March 26, 2011 They all look like that to me. Your x's blocking out the nunbers? Quote Link to comment Share on other sites More sharing options...
enigma# Posted March 26, 2011 Share Posted March 26, 2011 lol yeah the xs are supposed to be numbers if you can take a screenshot I can look at that for you honestly if the trojan has been removed you should be okay Quote Link to comment Share on other sites More sharing options...
Narwhals Posted March 26, 2011 Share Posted March 26, 2011 Well it's good to have you back Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.