Hello,
well I just recieved an instant message by someone who claimed to be a member. I talk to him for a few minutes and then proceded on with things. Started playing a game online and it was really laggy. Got suspicious so I then ran a check...
went to ms-dos typed in netstat -an
came up with syn request from ip 172.xx.184.1 - 172.xx.184.254
then typed netstat -r
with 3 established ports
looked like this
foreign address
172.xx.134.54 syn sent
172.xx.134.55 syn sent
172.xx.134.56 syn sent
172.xx.134.57 syn sent
172.xx.134.58 syn sent
-berp-ci04.dial.aol.com: 13784 established
205.176.25.195: 5190 established
bombnet.p3psi.org: established
172.xx.134.116 syn sent
172.xx.134.5 syn sent
172.xx.134.6 syn sent
172.xx.134.7 syn sent
172.xx.134.8 syn sent
etc........
it seems to me that this is a scan on my port look like it was succesful. Am i correct and how do i fix and defend. Please help me out. P3psi is a virus I believe. Where can i find it if it has been executed as i am sure it will be well hidden:mad:
