What worries me is that I removed the infection on Monday - but got the isp message today stating the spam had occurred yesterday (Wednesday) via a trojan.
These are in the OTL moved folder and aren’t active. When your cleanup was confirmed and you reported your system was OK (after a day or so) you should have received information on removing the tools used in the cleanup.
I also believe the purpose of the _OTL moved folder is to send samples to avast if they weren’t detected by avast.
So did you report your system was working normally and did you get information on removing the tools used ?
Did anyone suggests sending these samples in the _OTL moved folder to avast ?
This really should have been in your original topic on the cleanup as all of that information would have been there.
ISPs are pretty dumb (and slow at times) when it comes to spam, how they know that spam occurred via a trojan is beyond me as they aren’t monitoring your system. That is speculation on their part in my speculative opinion ;D
It is easy to fake a from email address in an email and this results in emails being bounced back to the fake email address. If your prior infection included sending spam then I would say that you should have changed your email password. Trojans sending spam, generally don’t use your email client but their own SMTP program, they are also using an email account/server that has been hacked or allows forwarding.
Set your Mail Shield Sensitivity to High Heuristics.
What is suspicious is that I used a VPN account yesterday for the first time since the original infection last weekend - the spam report came from the VPN provider today. Sort of suggests the infection was still active yesterday??