This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

ISP says we have a trojan sending mail out.

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hullo

We have 4 XP computers here behinds a Linux Smooth Wall firewall. Each has Trend Penicillin and Zonealarm.

We have broadband and our ISP and server supplier says we are sending spam, hundreds a day.

We are also said to have my doom.M here as well.

I have had mutiple searches and taken the drives out to do scans on another computer so the disk OS in not running but we cant find any tojans, viruses ( virii) or the like.

Today only my machine has been running and we have had another spam warning and others.

THIS

We have detected that your email account has been used to send a large amount of unsolicited commercial e-mail messages during this week.
Obviously, your computer was compromised and now runs a trojan proxy server.

Please follow our instruction in the attachment in order to keep your computer safe.

AND THIS

At Sat Dec 2 11:03:12 2006 the virus scanner said:
ClamAV Module: message.txt .pif was infected: Worm.Mydoom.M
MailScanner: Very long filenames are good signs of attacks against Microsoft e-mail packages (message.txt .pif)

AND THIS

The original e-mail attachment "Document.scr"
was believed to be infected by a virus and has been replaced by this warning
message.

If you wish to receive a copy of the *infected* attachment, please
e-mail helpdesk and include the whole of this message
in your request. Alternatively, you can call them, with
the contents of this message to hand when you call.

At Sat Dec 2 07:38:34 2006 the virus scanner said:
ClamAV Module: Document.scr was infected: Worm.Mydoom.M
MailScanner: Windows Screensavers are often used to hide viruses (Document.scr)

HERE IS OUR LOG.

Logfile of HijackThis v1.99.1
Scan saved at 2:25:30 p.m., on 2/12/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\mfsyncsv.exe
C:\WINDOWS\System32\mgabg.exe
C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PCCTLCOM.EXE
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TMPROXY.EXE
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\EXPLORER.EXE
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunThreatEngine.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TMPFW.EXE
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunProtectionServer.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
C:\WINDOWS\System32\mrfshl.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRAM FILES\GOOGLE\GOOGLE DESKTOP SEARCH\GOOGLEDESKTOPINDEX.EXE
C:\WINDOWS\SYSTEM32\ZONELABS\VSMON.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\PROGRAM FILES\BENIGN\B9.EXE
C:\Program Files\ScanSoft\NaturallySpeaking\Program\natspeak.exe
C:\PROGRAM FILES\MAILWASHER PRO\MAILWASHER.EXE
C:\Program Files\shortkey\SHORTKEY.EXE
C:\Program Files\Winm8\Winm8.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\Qualcomm\Eudora\Eudora.exe
C:\WINDOWS\System32\msiexec.exe
C:\Documents and Settings\Anthony Lealand\Desktop\HIJACK AND LOG\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://update.zonelabs.com/downloadrequest…eqId=1236196209
O1 - Hosts: 127.98.9.2 mail.firework.co.nz.b9
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunServer] C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe"
O4 - HKLM\..\Run: [MirrorFolderShell] C:\WINDOWS\System32\mrfshl.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [Skype] "C:\PROGRAM FILES\SKYPE\PHONE\SKYPE.EXE" /nosplash /minimized
O4 - HKCU\..\Run: [b9] C:\PROGRAM FILES\BENIGN\B9.EXE /minimize
O4 - HKCU\..\Run: [Startup Manager] C:\Documents and Settings\Anthony Lealand\Application Data\Systweak\ASO 2\smstartUp manager.exe
O4 - Startup: Dragon NaturallySpeaking.lnk = C:\Program Files\ScanSoft\NaturallySpeaking\Program\natspeak.exe
O4 - Startup: MailWasherPro.lnk = C:\Program Files\MailWasher Pro\MailWasher.exe
O4 - Startup: ShortKeys 2000.lnk = C:\Program Files\shortkey\SHORTKEY.EXE
O4 - Startup: Winm8.lnk = C:\Program Files\Winm8\Winm8.exe
O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.dll
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRAM FILES\SKYPE\Plugin Manager\Skype4COM.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: MirrorFolder auto-synchronization service (mfsyncsv) - Techsoft Pvt. Ltd. - C:\WINDOWS\System32\mfsyncsv.exe
O23 - Service: MGABGEXE - Matrox Graphics Inc. - C:\WINDOWS\System32\mgabg.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


Kind Regards
Anthony Lealand

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI