My computer is sending spam

Hi,

It seems to me (looking at the Avast Internet Mail scanner) that my PC is being used to send spam.

Is there a way I can find the process that is doing it and remove it?

Failing this is there a way I can request Avast only send mail from specified email accounts? This would at least prevent the spam from being sent.

TIA

Kevin

You appear to have an undetected trojan spambot on your system avast doesn’t have the function to block for specific accounts, it is quite possible it isn’t even using your email proram to send the email.

I would suggest that you put this in the Viruses and Worms Forum, but a forum search in that forum is sure to bring up similar topics as it is one that if frequently encountered.

I suggest that you schedule a boot time scanning with avast. Start avast! > Right click the skin > Schedule a boot-time scanning. Select for scanning archives. Boot.
Also, it will be good if you download, install, update and run other trojan remover tools: a-squared and/or Free AVG Antispyware (trojan removers). Some users recommend SUPERantispyware or Spyware Terminator.

Hey Guys,

Thanks for your help.

I followed your suggestions (ran the boot check and tried a few other products).

They didn’t seem to find anything but the problem seems to have gone away.

Thanks again,

Kevin

If you still detecting any strange behavior or even you’re sure you’re not clean, maybe it will be good to test your machine with anti-rootkit applications. I suggest AVG, Panda and/or F-Secure BlackLight.

Also, if you still detecting strange behaviors or you want to be sure you’re clean, maybe making a HijackThis log to post here and, specially, scan and submit to on-line analysis the RunScanner log would help to identify the problem and the solution.

Hey Guys,

Thanks for your help.

I think running the rootkit programs has worked (one was found and removed).

It is a little hard to tell as the emails are sent intermittently (sometimes 0 a day, and sometimes more).

It has been now been several days and no emails have been sent.

Thanks again,

Kevin

After all, it will be good to be sure, that you:

  1. Disable System Restore on Windows ME or Windows XP. System Restore cannot be disabled on Windows 9x and it’s not available in Windows 2k. After boot you can enable System Restore again.

  2. Clean your temporary files. You can use [ur=http://www.stevengould.org/downloads/cleanup/]CleanUp[/url] or the Windows Advanced Care features for that.

  3. Schedule a boot time scanning with avast. Start avast! > Right click the skin > Schedule a boot-time scanning. Select for scanning archives. Boot. Other option is scanning in SafeMode (repeatedly press F8 while booting).

  4. It will be good if you download, install, update and run other trojan remover tools: a-squared and/or Free AVG Antispyware (trojan removers). Some users recommend SUPERantispyware or Spyware Terminator.

  5. Use the immunization of SpywareBlaster or, which is better, the Windows Advanced Care features of spyware/adware cleaning and removal.

I will do that.

I sort of understand the allure of writing a virus that can’t be detected (sort of like hacking) but I wonder if they worry about the troubles they put people through.

I suspect not :).

Thanks again,

Kevin

The allure is money, sending out the spam in the hope that some fool will think, ‘oh I really need that, insert product of choice here.’ Instead of ‘never’ buy anything from unsolicited email (just delete spam), if no one bought then it wouldn’t be worth doing.