CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 949
Comments: 28
block bottom
spacer spacer

Caution....Shadowserver

 
Post new topic   Reply to topic       All -> FavForums -> Catch All - Guests [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Jud68

Corporal
Corporal


Joined: May 23, 2005
Posts: 61
Location: USA

PostPosted: Sat Mar 22, 2008 9:54 pm    Post subject: Caution....Shadowserver
Reply with quote

Hi,

Why and I getting this Caution alert:

"Welcome to CastleCops®. In cooperation with Shadowserver Foundation, your IP address [207.69.137.29] matches our records for possible malicious activity observed on the Internet around 2008-03-22 03:34:09 UTC. Please follow our Malware Removal and Prevention procedures. Questions/Comments?"

This is not my IP address. I am on Earthlink dialup and get a different IP address every time I log on, and it always starts with 4.xxx.xxx.x(x).

My computer is clean. I just scanned it this morning with Spybot, a2, and Norton scanned last night. I also use Spywareblaster, and just did a HijackThis and nothing appears out of the ordinary there. CWShredder finds nothing.

Thanks,
Judy

Back to top
View users profile Send private message
Cudni

Special Response Team


Joined: Dec 10, 2002
Posts: 3683
Location: Et In Arcadia ego
MIRT MVP SRT

PostPosted: Sat Mar 22, 2008 10:37 pm    Post subject:
Reply with quote

see
CastleCops Link/postlite214359-.html

but as you checked your comp, nothing to worry about

Cudni


_________________
Hecho en Mexico
Back to top
View users profile Send private message Visit posters website
Jud68

Corporal
Corporal


Joined: May 23, 2005
Posts: 61
Location: USA

PostPosted: Sat Mar 22, 2008 10:59 pm    Post subject:
Reply with quote

Thanks Cudni. I did find that link earlier trying to find out what this was about. So I guess I just get an "Caution..." every time I visit the site even though its not my IP. Sad

Thanks for your reply.

Judy

Back to top
View users profile Send private message
mrrockford

News Admin
News Admin
AVPE Host
AVPE Host

Joined: Apr 24, 2004
Posts: 2996

Forums Admin MVP Premium Team F@H

PostPosted: Sun Mar 23, 2008 1:14 am    Post subject:
Reply with quote

Howdy,

As you are on dial-up your IP will change quite often. The IP you used to post the previous 2 posts had come up on the list.

If you use FireFox you might want to check out the ShowMyIP ext.


_________________
"Anyone who considers protocol unimportant has never dealt with a cat."

L. Long
Back to top
View users profile Send private message Visit posters website
Jud68

Corporal
Corporal


Joined: May 23, 2005
Posts: 61
Location: USA

PostPosted: Sun Mar 23, 2008 1:42 am    Post subject:
Reply with quote

Hi,

Yes, I know my IP changes on dialup, everytime I connect thru my ISP. (Instead of "logon" in my original post, I guess I should have said dialup and connect thru my ISP.) But it is never 207.xxx.xxx.xxx. It is always a 4.xxx.xxx.x(xx). I use IE6, XP Home SP2. I can see my IP just by hovering my mouse over what Earthlink calls the "Task Panel", which is part of their software. This time the "Caution...." does not show up, and it didn't on my last post. It just showed up last night when I visited, and the first time today before I posted.

So when Shadowserver detects the IP 207.xxx.xxx.xxx, it is not my computer per se. Somehow it is Earthlink's IP it is detecting. It is the 207.xxx.xxx.xxx IP in the list, and not my 4.xxx.xxx.x(xx) computer. Do I understand that correctly. Because I am 99.99% positive my computer is clean. (Even though I do not understand two IP addresses. Question )

Thanks for your help,
Judy

Back to top
View users profile Send private message
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Sun Mar 23, 2008 1:46 am    Post subject:
Reply with quote

What does CastleCops Link/modules.php?name=Reveal_IP say? Does it show the 207 IP?


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
Jud68

Corporal
Corporal


Joined: May 23, 2005
Posts: 61
Location: USA

PostPosted: Sun Mar 23, 2008 1:49 am    Post subject:
Reply with quote

It says:
Your real IP: 4.x.x.x
Your browser: MSIE
Your Operating System: Windows

It does not show and 207.

Edit: Thanks for the x's someone. I was just going to change that.



Last edited by Jud68 on Sun Mar 23, 2008 1:55 am, edited 1 time in total
Back to top
View users profile Send private message
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Sun Mar 23, 2008 1:52 am    Post subject:
Reply with quote

OK I see it, its a proxy. I'll try to adjust the script.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Sun Mar 23, 2008 1:55 am    Post subject:
Reply with quote

Script now modified, is the Caution alert still there?

Back to top
View users profile Send private message Send email Visit posters website
Jud68

Corporal
Corporal


Joined: May 23, 2005
Posts: 61
Location: USA

PostPosted: Sun Mar 23, 2008 2:00 am    Post subject:
Reply with quote

No the Caution is not there. It was not there when I came back to the site to read Cudni's reply to me. Only last night and today durng my first post. The 207 is not showing using you IP link either. Just the 4.

Back to top
View users profile Send private message
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Sun Mar 23, 2008 2:03 am    Post subject:
Reply with quote

OK. Thanks for the thread, I've improved the code on our end.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
Jud68

Corporal
Corporal


Joined: May 23, 2005
Posts: 61
Location: USA

PostPosted: Sun Mar 23, 2008 2:11 am    Post subject:
Reply with quote

Thank you for your help. Very Happy

Glad this helped you too. Very Happy

Judy

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Catch All - Guests All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer