Antivirus Protection
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationAntivirus Protection

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old March 16th, 2005, 05:29 PM
DJ SpeCtre DJ SpeCtre is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2005
Posts: 10 DJ SpeCtre User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 2 h 35 m 24 sec
Reputation Power: 0
Computer sending out spam emails. Norton, Adaware, SpyBot will not Remove or detect.

Hi there,
I've got EXACTLY the same problem as another guy Elcho in a previous thread. My computer is sending out spam. The only way I know this is because Norton Internet Security's 2005 Resident Protection keep scanning hundreds of mails and their error/bounce messages coming up on my screen and pissing me off, slowing down my cable internet connection.

The frustrating thing is nowhere on Google has there been any answer on any of the annoyance.org or similar types of sites, providing a solution, although there are many who share our problem!! I challenge anyone on this forum to come up with an answer first.

I have Norton Internet Security 2005 with email scanning + an up to date Norton Antivirus with definitions from 10th of March 2005, as well as an up to date Spybot S&D, and up to date Adaware Pro SE. A Full Norton scan picks up nothing except two references to Spyware Nuker in a downloaded program files subfolder that apparently, when I navigate to it in Explorer, doesn't even exist. Spyware S&D picks up three pieces of Spyware that is SAYS it removes, but doesnt: Wind Updates (code storage database), and two code storage database references to "ISearchTech.SideFind".

I've done as much research on the type of spam-virus I have as I can, and I've only found out that they embed themselves into the system somehow and include their very own SMTP engine so they operate independently of any other mail program you are running. The program, or whatever it is, detects when the internet is disconnected because it immediately stops sending mail when I disconnect the cable or block traffic with Norton. It also keeps sending hundreds of emails going right through a huge alphabetical list of addresses till it gets to the end. Then for perhaps a day or two, it wont do it again, but will start up again seemingly randomly, another day and do more spam sending. There is nothing suspicious in my msconfig that I can see either...
So finally, in desperation, here is my HijackThis log... perhaps with mine you can compare it to Elcho's and make something of it????

Thanks for your help and sorry for the huge post ;-)
-DJ SpeCtre




Logfile of HijackThis v1.99.1
Scan saved at 6:12:13 PM, on 14/03/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Windows\system32\spoolsv.exe
C:\Windows\System32\DRIVERS\CDANTSRV.EXE
C:\Windows\System32\inetsrv\inetinfo.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Windows\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Windows\System32\MsPMSPSv.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Windows\explorer.exe
C:\Program Files\Norton Internet Security\ccEmFlSv.exe
C:\Program Files\Hijackthis!\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nova100.com.au/clubnova
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nova100.com.au/clubnova
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nova100.com.au/clubnova
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\Windows\ybfvd.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\Windows\ybfvd.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nova100.com.au/clubnova
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy1.patrick.acu.edu.au:80
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] "C:\Program Files\Compaq\EAB\EabServr.exe " /Start
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [ATIModeChange] "Ati2mdxx.exe"
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [mouseElf] C:\PROGRA~1\GENIUS~1\GNETMOUS.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SpyBot S&D Resident Protection] C:\\Program Files\\Spybot S&D\\TeaTimer.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot S&D\TeaTimer.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Search and Remove Spyware - {CDB280E8-BE43-4128-8A5A-3FCD094E2D88} - C:\Program Files\RegFreeze\rfsearchhandler.dll
O9 - Extra 'Tools' menuitem: Search and Remove Spyware - {CDB280E8-BE43-4128-8A5A-3FCD094E2D88} - C:\Program Files\RegFreeze\rfsearchhandler.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.dll
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
O16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} -
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.5.0_01) -
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} -
O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.5.0_01) -
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{57AFBD41-9B69-4E9B-B75F-1C6735C087F6}: NameServer = 203.12.160.35,203.12.160.36
O17 - HKLM\System\CCS\Services\Tcpip\..\{5D5BBB9B-1478-4A62-95B4-6E5BA06C87C1}: NameServer = 203.12.160.35,203.12.160.36
O17 - HKLM\System\CS1\Services\Tcpip\..\{57AFBD41-9B69-4E9B-B75F-1C6735C087F6}: NameServer = 203.12.160.35,203.12.160.36
O17 - HKLM\System\CS2\Services\Tcpip\..\{57AFBD41-9B69-4E9B-B75F-1C6735C087F6}: NameServer = 203.12.160.35,203.12.160.36
O17 - HKLM\System\CS3\Services\Tcpip\..\{57AFBD41-9B69-4E9B-B75F-1C6735C087F6}: NameServer = 203.12.160.35,203.12.160.36
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\Windows\System32\DRIVERS\CDANTSRV.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Intel File Transfer - Intel® Corporation - C:\Windows\system32\cba\xfr.exe
O23 - Service: Intel PDS - Intel® Corporation - C:\Windows\system32\cba\pds.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Reply With Quote
  #2  
Old March 17th, 2005, 09:48 PM
DJ SpeCtre DJ SpeCtre is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2005
Posts: 10 DJ SpeCtre User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 2 h 35 m 24 sec
Reputation Power: 0
looks like i have everyone stumped so far :-P

Reply With Quote
  #3  
Old March 21st, 2005, 02:21 AM
DJ SpeCtre DJ SpeCtre is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2005
Posts: 10 DJ SpeCtre User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 2 h 35 m 24 sec
Reputation Power: 0
About 4 days ago, I did a Googlesearch on the files and the Registry IDs in my own HijackThis log (posted above). I found about three components of Spyware, one from WindUpdates, and two from Isearchtech, which I successfully removed. Now, whether or not these components were related to the spam problem I had, it seems that the spam has stopped sending since I had those components removed. It is a strange thing.

Now, I would like to say: Look at the number of posts I have. Look at my "belt colour". I know a fair bit about computers and spyware, but nevertheless, am a newbie. I am extremely disappointed with this forum, and so-called Dev Shed experts. Not a single reply from any of you. Thanks so much for the help.

-DJ SpeCtre

Reply With Quote
  #4  
Old March 22nd, 2005, 07:51 AM
Tom Myboy Tom Myboy is offline
Contributing User
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Aug 2003
Posts: 2,491 Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 3 Days 20 h 13 m 41 sec
Reputation Power: 13
Hi DJ SpeCtre,

I think your last post was pretty rude. There is a whole lot more infected computers out there than there is people to fix them.

This forum is run by volunteers. No one gets paid here. Have a little respect.

Tom
__________________
HijackThis
Ad-aware
Spybot Search & Destroy
SpywareBlaster
SpywareGuard
Housecall Online A/V Scan

Please read the stickys at the top of the forum before posting!

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationAntivirus Protection > Computer sending out spam emails. Norton, Adaware, SpyBot will not Remove or detect.


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 6 hosted by Hostway