Re: Can't stop a Zombie EMailer



Block the said ports from the firewall as an option

"JP" <JP@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:D01A399C-59E6-4B0E-B133-6072EA7A2082@xxxxxxxxxxxxxxxx
I am assuming I am on the right Group.
I have discovered a Zombie Emailer running on XP Home.
It is sending enough email to bring down the LAN. Using CurrPorts
(cports.exe) I can watch it connect to an IP address on port 80 (probably
picking up the day's email) then connect to another IP Address (close to the
first one) on Port 25.

After a few seconds, all hell breaks loose, and the computer starts spewing
email at a great rate...stopped by pulling the Network cable.
I have watched this, in CurrPorts, and in Process Explorer from
Sysinternals, and it appears to be running from Services.exe PID 688, but
from where after that is the real question.
I have used 3 different Virus Scanners, and 2 different Rootkit finders.
Nothing.

I further checked it with HiJackThis, and with Autoruns. Seems that it is
not something that normally shows up as an "evil doer". I am not sure if
they have hijacked a service, or just what.
Any suggestions.

.



Relevant Pages

  • Re: Cant stop a Zombie EMailer
    ... Also try superantispyware. ... I have discovered a Zombie Emailer running on XP Home. ... I have watched this, in CurrPorts, and in Process Explorer from ... I further checked it with HiJackThis, ...
    (microsoft.public.security.virus)
  • Re: Default FTP Site (Stopped)
    ... I used Currports and first stopped the process then deleted it. ... accessed FTP and bingo it works fine now on port 21. ... the FTP publishing service and IIS was started which they were. ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: Default FTP Site (Stopped)
    ... Bernard Cheah ... I used Currports and first stopped the process then deleted it. ... accessed FTP and bingo it works fine now on port 21. ... the FTP publishing service and IIS was started which they were. ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: AdAware, SpyBot S &D, etc. + leave PC connected to Internet
    ... run hiJackThis! ... > what's running - it's more detailed than Task Manager. ... I don't see areason why Port 80 should be ... There is no OPEN ports anymore when I scan after I uninstalled Sygate ...
    (comp.security.firewalls)
  • Re: TCP socket question
    ... There is also TCPView, ActivePorts and Currports that give port and application using port information, which all of the solutions are free. ... to display netstat's help and shows the parms that can be used and the information returned by using those parms. ...
    (microsoft.public.dotnet.languages.csharp)