 | Member with 33 posts. | | Join Date: Jan 2005 Experience: Beginner | | Solved: One and a half emails per second -help Last week my ip shut down my service and told me that I was sending out thousands of emails. I told them that they were crazy but now maybe they weren't.
I installed AVG Anti-virus 8.0 which has an email scanner. I was looking at the reports and saw the number of scanned email counting one every 3/4 of a second. I clicked off the scan on outgoing mail and the numbers stopped.
My friend, who hosts an e-mail business looked at it and said that someone is using my computer to send out bulk e-mail. He suggested that I run Trend HouseCall, which I did but it did not work. As soon as I clicked on scan , the numbers started climbing again only on the outgoing mail , of course..
Outside of just unplugging my machine , how can I make certain what is happening because I can't see anything on my task manager. And how can I stop it? I leave my machine on 24/7.
I have installed some virus checkers and I have a firewall from roadrunner and I think I have one in my Belkin router; the fact is, I don't really know what firewall I have but my internet connection shows it is firewalled.
I have three other computers on the same lan but they aren't affected, I think though that one could be.
Dieter Schmied | | Senior Member with 1,328 posts. | | | | Block outgoing port 25 on the firewall. That will stop all outgoing mail. If you use web based email like hotmail or gmail , then you don't need port 25 and you can block it to stop the email from going out.
What model is your Belkin router ? | | Distinguished Member with 4,901 posts. | | Join Date: Apr 2002 Location: Birmingham, England | | I think you would be well advised to click on the 'Report' option and ask a Moderator to move this to the Malware Removal Forum, since you appear to have a spambot.
Interesting story on this subject can be found here (particularly Lesson 4); http://isc.sans.org/diary.html?storyid=4822
__________________ Nothing matters very much, and few things matter at all.
Lord Balfour 1848-1930 | | Distinguished Member with 9,752 posts. | | Join Date: Apr 2006 Location: Pittsburgh, PA Experience: Mac Addict | | | | | Member with 33 posts. | | Join Date: Jan 2005 Experience: Beginner | | Quote:
Originally Posted by lunarlander Block outgoing port 25 on the firewall. That will stop all outgoing mail. If you use web based email like hotmail or gmail , then you don't need port 25 and you can block it to stop the email from going out.
What model is your Belkin router ? | The Belkin Router is an 80211b wireless router model # F 5d6231-4 , ver 2003.
I do have a gmail account but seldom use it. My one.net account is now owned by nuvox, which seem to be a first class company and had never given me any trouble in over ten years. | | Member with 33 posts. | | Join Date: Jan 2005 Experience: Beginner | | Quote:
Originally Posted by TOGG I think you would be well advised to click on the 'Report' option and ask a Moderator to move this to the Malware Removal Forum, since you appear to have a spambot.
Interesting story on this subject can be found here (particularly Lesson 4); http://isc.sans.org/diary.html?storyid=4822 | Yes, that was interesting, thanks.
I am one of those that haven't a clue about what he knows other than I know he is right.
I have did what ferrija1 suggested below. Is that what you have essentially suggested? | | Distinguished Member with 4,901 posts. | | Join Date: Apr 2002 Location: Birmingham, England | | Yes, the 'infection' you appear to have means that one or more of the computers on your network is constantly sending spam emails and it looks like people with programs such as Mailwasher (or their ISP's), are using the 'bounce' feature to reject them and send them back to you. That must be a very appealing thing to do if you are the victim of spam, but all it achieves is to double the traffic without bothering the people responsible for the spam because they are using malware on other peoples computers to send the stuff!. The 'Delete' option is much better for spam.
I am not qualified to comment on HJT logs so I can't be much help on that score. It would help to avoid confusion if you were to mark this thread as Solved and continue with the one ferrija1 referred to In Malware Removal. Keeping both threads going is unlikely to bring a solution any closer.
__________________ Nothing matters very much, and few things matter at all.
Lord Balfour 1848-1930 | | Member with 33 posts. | | Join Date: Jan 2005 Experience: Beginner | | I marked this as solved. I have removed the mail server from my outlook express account that I suspect is the problem and went to their webmail site and forwarded all mail to another address on another server after talking with the owner of the second server and it seems to have stopped the flow.
Mailwasher was not bouncing anything for me; I felt long ago that bouncing was a futile act with spammers. | | Distinguished Member with 4,901 posts. | | Join Date: Apr 2002 Location: Birmingham, England | | I may not have expressed myself clearly in my last post. I wasn't suggesting that you had used Mailwasher to 'bounce' anything,
I had assumed, maybe incorrectly, that the source of your returned mail was due to something similar to Mailwasher being used by people that had received spam from your infected computer(s).
You are right about the futility of bouncing though!
__________________ Nothing matters very much, and few things matter at all.
Lord Balfour 1848-1930 | | Member with 33 posts. | | Join Date: Jan 2005 Experience: Beginner |
06-Aug-2008, 06:17 PM
#10 | I really don't know what has happened. I thought there might be some kind of loop that was inadvertently closed, but that is speculation. I don't know enough about the tools that are available such as logs.
I had another computer that was just used to replace another computer on the same lan yesterday and I establish a new mail account on Outlook Express using the mail server that was suspect. I sent myself a test email and when I went to read it, a stream of emails flowed and I pulled the ethernet connector until I could stop the flow and remove the account using the roadrunner server.
It could have been something I did but for now everything seems quiet. | | Distinguished Member with 9,752 posts. | | Join Date: Apr 2006 Location: Pittsburgh, PA Experience: Mac Addict |
09-Aug-2008, 09:12 AM
#11 | I've reported you HJT thread and someone should be about to help you soon enough. |  THIS THREAD HAS EXPIRED.
Are you having the same problem?
We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.
|
Smart Search
| Find your solution! | |
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | | |  WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
| You Are Using: |
Advertisements do not imply our endorsement of that product or service.
All times are GMT -5. The time now is 09:50 PM.
Copyright © 1996 - 2009 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2009, Jelsoft Enterprises Ltd. | |
|