|
|
|||||||||
|
|||||||||
| |||||||||
|
|
|
| |||||||||
![]() |
|
|
«
Previous Thread
|
Next Thread
»
|
Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
#1
|
|||
|
|||
|
Computer sending out spam emails. Norton, Adaware, SpyBot will not Remove or detect.
Hi there,
I've got EXACTLY the same problem as another guy Elcho in a previous thread. My computer is sending out spam. The only way I know this is because Norton Internet Security's 2005 Resident Protection keep scanning hundreds of mails and their error/bounce messages coming up on my screen and pissing me off, slowing down my cable internet connection. The frustrating thing is nowhere on Google has there been any answer on any of the annoyance.org or similar types of sites, providing a solution, although there are many who share our problem!! I challenge anyone on this forum to come up with an answer first. I have Norton Internet Security 2005 with email scanning + an up to date Norton Antivirus with definitions from 10th of March 2005, as well as an up to date Spybot S&D, and up to date Adaware Pro SE. A Full Norton scan picks up nothing except two references to Spyware Nuker in a downloaded program files subfolder that apparently, when I navigate to it in Explorer, doesn't even exist. Spyware S&D picks up three pieces of Spyware that is SAYS it removes, but doesnt: Wind Updates (code storage database), and two code storage database references to "ISearchTech.SideFind". I've done as much research on the type of spam-virus I have as I can, and I've only found out that they embed themselves into the system somehow and include their very own SMTP engine so they operate independently of any other mail program you are running. The program, or whatever it is, detects when the internet is disconnected because it immediately stops sending mail when I disconnect the cable or block traffic with Norton. It also keeps sending hundreds of emails going right through a huge alphabetical list of addresses till it gets to the end. Then for perhaps a day or two, it wont do it again, but will start up again seemingly randomly, another day and do more spam sending. There is nothing suspicious in my msconfig that I can see either... So finally, in desperation, here is my HijackThis log... perhaps with mine you can compare it to Elcho's and make something of it???? Thanks for your help and sorry for the huge post ;-) -DJ SpeCtre Logfile of HijackThis v1.99.1 Scan saved at 6:12:13 PM, on 14/03/2005 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000) Running processes: C:\Windows\System32\smss.exe C:\Windows\system32\winlogon.exe C:\Windows\system32\services.exe C:\Windows\system32\lsass.exe C:\Windows\system32\svchost.exe C:\Windows\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccProxy.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Norton Internet Security\ISSVC.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Windows\system32\spoolsv.exe C:\Windows\System32\DRIVERS\CDANTSRV.EXE C:\Windows\System32\inetsrv\inetinfo.exe C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe C:\Windows\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Windows\System32\MsPMSPSv.exe C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\MSN Messenger\msnmsgr.exe C:\Windows\explorer.exe C:\Program Files\Norton Internet Security\ccEmFlSv.exe C:\Program Files\Hijackthis!\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nova100.com.au/clubnova R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nova100.com.au/clubnova R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nova100.com.au/clubnova R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\Windows\ybfvd.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\Windows\ybfvd.dll/sp.html#37049 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nova100.com.au/clubnova R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy1.patrick.acu.edu.au:80 O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" O4 - HKLM\..\Run: [eabconfg.cpl] "C:\Program Files\Compaq\EAB\EabServr.exe " /Start O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" O4 - HKLM\..\Run: [ATIModeChange] "Ati2mdxx.exe" O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe O4 - HKLM\..\Run: [mouseElf] C:\PROGRA~1\GENIUS~1\GNETMOUS.EXE O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [SpyBot S&D Resident Protection] C:\\Program Files\\Spybot S&D\\TeaTimer.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot S&D\TeaTimer.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra button: Search and Remove Spyware - {CDB280E8-BE43-4128-8A5A-3FCD094E2D88} - C:\Program Files\RegFreeze\rfsearchhandler.dll O9 - Extra 'Tools' menuitem: Search and Remove Spyware - {CDB280E8-BE43-4128-8A5A-3FCD094E2D88} - C:\Program Files\RegFreeze\rfsearchhandler.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.dll O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - O16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} - O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.5.0_01) - O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} - O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.5.0_01) - O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - O17 - HKLM\System\CCS\Services\Tcpip\..\{57AFBD41-9B69-4E9B-B75F-1C6735C087F6}: NameServer = 203.12.160.35,203.12.160.36 O17 - HKLM\System\CCS\Services\Tcpip\..\{5D5BBB9B-1478-4A62-95B4-6E5BA06C87C1}: NameServer = 203.12.160.35,203.12.160.36 O17 - HKLM\System\CS1\Services\Tcpip\..\{57AFBD41-9B69-4E9B-B75F-1C6735C087F6}: NameServer = 203.12.160.35,203.12.160.36 O17 - HKLM\System\CS2\Services\Tcpip\..\{57AFBD41-9B69-4E9B-B75F-1C6735C087F6}: NameServer = 203.12.160.35,203.12.160.36 O17 - HKLM\System\CS3\Services\Tcpip\..\{57AFBD41-9B69-4E9B-B75F-1C6735C087F6}: NameServer = 203.12.160.35,203.12.160.36 O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\Windows\System32\DRIVERS\CDANTSRV.EXE O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Intel File Transfer - Intel® Corporation - C:\Windows\system32\cba\xfr.exe O23 - Service: Intel PDS - Intel® Corporation - C:\Windows\system32\cba\pds.exe O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe |
|
#2
|
|||
|
|||
|
looks like i have everyone stumped so far :-P
|
|
#3
|
|||
|
|||
|
About 4 days ago, I did a Googlesearch on the files and the Registry IDs in my own HijackThis log (posted above). I found about three components of Spyware, one from WindUpdates, and two from Isearchtech, which I successfully removed. Now, whether or not these components were related to the spam problem I had, it seems that the spam has stopped sending since I had those components removed. It is a strange thing.
Now, I would like to say: Look at the number of posts I have. Look at my "belt colour". I know a fair bit about computers and spyware, but nevertheless, am a newbie. I am extremely disappointed with this forum, and so-called Dev Shed experts. Not a single reply from any of you. Thanks so much for the help. -DJ SpeCtre |
|
#4
|
|||
|
|||
|
Hi DJ SpeCtre,
I think your last post was pretty rude. There is a whole lot more infected computers out there than there is people to fix them. This forum is run by volunteers. No one gets paid here. Have a little respect. Tom
__________________
HijackThis Ad-aware Spybot Search & Destroy SpywareBlaster SpywareGuard Housecall Online A/V Scan Please read the stickys at the top of the forum before posting! |
![]() |
| Viewing: Dev Shed Forums > System Administration > Antivirus Protection > Computer sending out spam emails. Norton, Adaware, SpyBot will not Remove or detect. |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|
|
|