How to notify an infected broadband user

  • Thread starter Thread starter Beauregard T. Shagnasty
  • Start date Start date
Hmm. You may be right. I discovered that *my* Windows Messenger was
disabled (well, I knew that 'cause I didn't want the spam popups). So
I re-enabled it, sent a message to the guy's IP, and got the response:

"The message was successfully sent to nn.nn.nn.nn"

So ... we'll see. Thanks, guys.

I'm willing to use one of my machines as "goat" for a experiment, if
you want. I can bypass my wireless router and connect my ethernet
adapter directly to my DSL modem. We would agree on a day and time
frame, and that morning I would send you via email my current IP#
(it's dynamic).

If you want to play, let me know. My email addy is artsown at epix
dot net

Art

http://home.epix.net/~artnpeg
 
Art said:
I'm willing to use one of my machines as "goat" for a experiment,
if you want. I can bypass my wireless router and connect my
ethernet adapter directly to my DSL modem. We would agree on a day
and time frame, and that morning I would send you via email my
current IP# (it's dynamic).

If you want to play, let me know. My email addy is artsown at epix
dot net

Thanks for that, Art. If I don't get a response to my net send in a
day or so, I'll take you up on it. My message gave him my email
address and requested that he respond. I was polite. <g>

Doesn't matter; he already has my address somewhere on his computer,
probably from my web site. I did just get another worm from him about
20 minutes ago.

(Figgs, looking forward to the number, just in case.)
 
Thanks for that, Art. If I don't get a response to my net send in a
day or so, I'll take you up on it. My message gave him my email
address and requested that he respond. I was polite. <g>

Doesn't matter; he already has my address somewhere on his computer,
probably from my web site. I did just get another worm from him about
20 minutes ago.

Have you considered going to the media? Little bit of bad publicity goes
along way.
 
Heather said:
I wrote Elayne and asked her to find an 800 number......and if not, just the
local one. Hopefully she will return from the beach and let me know. I
will fire it off to you as soon as I get it.
Hi Shaggy.....

Just phoned Elayne and all she has is the tech support number on her bill,
which is a local one. Also one for Customer Service, but that won't do you
much good.

1-604-629-3000 is the Tech Support number and they probably will be able to
give you a number for Abuse. I know it is like pulling teeth with Rogers as
well, trying to get that sort of thing....and I usually go thru one of the
techies.

Good luck.....if you get really stuck, E. says that she could call and see
what she can find out. She literally just signed with them about 3 days
ago, so hasn't had to use their services yet. (G)

Cheers.....Heather
 
Heather said:
Hi Shaggy.....
Hey!

Just phoned Elayne and all she has is the tech support number on
her bill, which is a local one. Also one for Customer Service, but
that won't do you much good.

1-604-629-3000 is the Tech Support number and they probably will be
able to give you a number for Abuse. I know it is like pulling
teeth with Rogers as well, trying to get that sort of thing....and
I usually go thru one of the techies.

Good luck.....if you get really stuck, E. says that she could call
and see what she can find out. She literally just signed with them
about 3 days ago, so hasn't had to use their services yet. (G)

Thanks for the number. I'll keep that in reserve if the messaging
doesn't work. Cheers.
 
Me not Figgs but ...

I don't know if you have to be in Canada for these:
1-888-472-2222
1-866-730-2040

FWIW: Some numbers can be had here
http://www.shaw-cable.com/contact.htm
JS equired - I can't tell what they are.

Yo....good work. Now all he has to do is figure out which city the guy
lives in!! Which I am sure he already has. I will send that page to Elayne
so that she has it for reference.....she is in Vancouver, btw.

Cheers....Heather
 
I'm getting about one to two dozen Worm.Mytob.T-2 infected messages
daily from a clueless Shaw cable subscriber who has my web site email
address on his computer. This has been going on for over a week. All I
know is the IP address, which has been constant.


What AV program are you using that picks them all up? You have good and
bad news there. The bad news is the jerk who sends the viruses and the
good news is that you're AV program picks them up. Doesn't your
broadband provider have a virus checker that cleans the mail before you
receive it (or are you not using their e-mail service). Many will inform
the subscriber that an e-mail was deleted because it contained a virus.
 
Moe said:
What AV program are you using that picks them all up? You have
good and bad news there. The bad news is the jerk who sends the
viruses and the good news is that you're AV program picks them up.
Doesn't your broadband provider have a virus checker that cleans
the mail before you receive it (or are you not using their e-mail
service). Many will inform the subscriber that an e-mail was
deleted because it contained a virus.

The jerk's computer is sending them to a contact address of one of my
web sites, which he apparently visited as I have had no contact with
anyone in western Canada.

The emails are being relayed through my web host, whose AV (says
ClamAV) is stripping off the attachment and adding the message about
which virus it is: Worm.Mytob.T-2

The virus itself isn't a problem for me; I know how to recognize them.
It's the couple dozen of them every day that is so annoying. Got three
more in the last hour.
 
Beauregard T. Shagnasty said:
Will try those later.


If I knew what city he was in ... <g> a traceroute ends at:
s0106000c4120a3f7.cg.shawcable.net whatever that is...

WAG?? Probably Calgary. (Alberta, Canada). Home of the famous Calgary
Stampede!! You guys will have to learn some Canadian geography. (VBG)
Also has a suburb named after me......well, a great uncle really. Make that
the *trivial pursuit* comment of the evening.

Cheers.....Heather
 
Heather - 03.07.2005 06:59 :

Heather, could you please explain to me why/how the correct SIG of
Beauregard T. Shagnasty (-- ) nevertheless shines up in your reposts?
Normally his SIG (dashdashspace) should'nt be "> -quoted" within you
repost, IMHO. Your OE-configuration?

THX for clarification.
 
<snip>|
| .....Home of the famous Calgary Stampede!! You guys will have to
| learn some Canadian geography. (VBG)

Same goes for the new US Ambassador to the Great White, eh! ;-) He
went to the Bush school of geography.

Chas.
 
Heather said:
WAG?? Probably Calgary. (Alberta, Canada).

So, I thought that .cg. was either Calgary or Coast Guard ...
Home of the famous Calgary Stampede!! You guys will have to learn
some Canadian geography. (VBG) Also has a suburb named after
me......well, a great uncle really. Make that the *trivial
pursuit* comment of the evening.

Oh, I know a fair bit about CDN geography, having been to almost all
of your provinces a time or three...

Just one more Worm from the guy this morning, at 6:15 UDT.
 
If I knew what city he was in ... <g> a traceroute ends at:
s0106000c4120a3f7.cg.shawcable.net whatever that is...

Thanks, J.
You're welcome.

if s0106000c4120a3f7.cg.shawcable.net == 68.147.95.22
then it's Calgary, Alberta (w/ 94% certainty).

J
 
Back
Top