The Unofficial Karoo User Forums
May 24, 2012, 02:00:43 pm *
Welcome, Guest. Please login or register.

Login with username, password and session length
News:
 
   Home   Chat Help Search Calendar Login Register  
Pages: [1]
  Print  
Author Topic: Spam Mail  (Read 1395 times)
KromaZone
Tech Support
**
Posts: 38


View Profile
« on: November 06, 2008, 08:46:37 am »

Found out yesterday i had my internet cut off because my computer was sending out spam mail without me even knowing. They said that it started sending out this shit last saturday and have only just cut me off yesterday....couldnt they have got in touch with with and told me over the phone? I told em i had no idea that my computer was doing this and basicly they said if it happends another two times i will be cut off for good Huh? So im the victim in both cases...what a load of shit. Anyone else had this problem and how to deal with it.
Logged
Fastethernet
Administrator
Engineer
*****
Broadband Provider: Karoo
Posts: 231


Don't make me angry.....


View Profile
« Reply #1 on: November 06, 2008, 09:14:53 am »

<rant>Once again Krapoo customer service is abysmal at best.</rant>

Right then, sounds like you have some sort of virus/trojan/root kit on your system. Do you have any anti virus? Do you have a software firewall? if the answer to either of those questions is no grab a copy of this http://files.avast.com/iavs4pro/setupeng.exe and or this http://www.sunbeltsoftware.com/Home-Home-Office/Sunbelt-Personal-Firewall/.

Right now it's time to root out what is sending all that spam mail, grab this http://www.trendsecure.com/portal/en-US/_download/HiJackThis.zip this http://download.sysinternals.com/Files/ProcessExplorer.zip and this http://download.sysinternals.com/Files/TcpView.zip.

Hijackthis will produce a log file of all the services running and programs that run during boot up, feel free to post the log file if you'd like someone to offer some further help.

Process Explorer will display a real time list of all processes running at any time, think of it as task manager on steroids. Try and look for processes using way too much CPU.

TCPview will display in real time all the network connections each program is making, you are looking for services/programs which are making connections to other hosts on ports TCP 25,110,143,465,585,993,995, mainly it will be port 25.

Once you have located the process sending mail then use hijackthis log file to find out how it's getting run in the boot up sequence. Then you should be able to remove that entry and stop the malware from being reloaded onto your computer when you next reboot.

I would probably google the file names of the malicious program and try and find out which virus/trojan was causing all these problems, then try and find a removal guide.

Get your important data backed up right away and if the above fails or sounds like too much work just re-install your OS.
Logged
KromaZone
Tech Support
**
Posts: 38


View Profile
« Reply #2 on: November 07, 2008, 07:39:43 pm »

Thanks for all that info m8, but i took the easy way out and re-installed my op system...gonna re-install all the programs then ghost the driver just in case i get another one.....bloody hate re-installing all the programs i need.
Logged
Fastethernet
Administrator
Engineer
*****
Broadband Provider: Karoo
Posts: 231


Don't make me angry.....


View Profile
« Reply #3 on: November 07, 2008, 09:00:22 pm »

Hi KromaZone,

I don't blame you weeding out the virus/trojan would have been quite a task. Can I offer one other piece of advise, maybe try using http://en.wikipedia.org/wiki/NLite to slipstream service packs and drivers onto you Windows XP installation disk, it's saved me hours of copying driver back and forth  Wink
Logged
The Dominator
Administrator
Director
*****
Broadband Provider: Karoo - Pro 1
Posts: 528



View Profile
« Reply #4 on: November 07, 2008, 10:57:27 pm »

wow - someone else using nlite....
careful there, that's sysadmin work!!!!

If you keep it up i will be forced to inform the authorities, we can't have comms specialist doing sysadmin stuff....

 Kiss

 Tongue

though i would also look at this..
http://driverpacks.net/DriverPacks/

Logged

The Dominator....
And the following is what i want to acheive -


This is what Kcom give me:
KromaZone
Tech Support
**
Posts: 38


View Profile
« Reply #5 on: November 09, 2008, 11:15:15 am »

Thanks for the advice guys...will check em out.
Logged
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.13 | SMF © 2006-2011, Simple Machines LLC Valid XHTML 1.0! Valid CSS!