Hi all,
2 days ago, my security system ( i am running under win xp sp2 ) told me that my firewall was deactivated !!!
Iwas affraid of this weird message … 15 sec after, my firewall was working as well as the beginning. I have never opened an unknow email nor executed file received from unknow person.
Today, i saw that my avast home edition was scanning outgoing email. My email client wasn’t running and i didn’t send any email ( nor compiled a web form to send data ).
Here is a log from the avast folder :
07/21/06 12:12:17 00000D50: Started as service, Log = 1 07/21/06 12:12:17 00000D50: Build 4.7.844 07/21/06 12:12:17 00000D50: Windows XP Workstation (Service Pack 2) 07/21/06 12:12:17 00000D50: Using WinSock 2.0 07/21/06 12:12:17 00000D50: AutoRedirect settings changed 1 07/21/06 12:12:17 00000D50: POP Start settings changed: 1 07/21/06 12:12:17 00000D50: POP Default server settings changed: 127.0.0.1 110 07/21/06 12:12:17 00000D50: POP Listen settings changed: 127.0.0.1 12110 07/21/06 12:12:17 00000D50: POP RedirectPort: 110 07/21/06 12:12:17 00000D50: SMTP Start settings changed: 1 07/21/06 12:12:17 00000D50: SMTP Default server settings changed: 127.0.0.1 25 07/21/06 12:12:17 00000D50: SMTP Listen settings changed: 127.0.0.1 12025 07/21/06 12:12:17 00000D50: SMTP RedirectPort: 25 07/21/06 12:12:17 00000D50: IMAP Start settings changed: 1 07/21/06 12:12:17 00000D50: IMAP Listen settings changed: 127.0.0.1 12143 07/21/06 12:12:17 00000D50: IMAP RedirectPort: 143 07/21/06 12:12:18 00000D50: NNTP Start settings changed: 1 07/21/06 12:12:18 00000D50: NNTP Listen settings changed: 127.0.0.1 12119 07/21/06 12:12:18 00000D50: NNTP RedirectPort: 119 07/21/06 13:07:06 00000970: getnameinfo error 11004 07/21/06 13:12:31 00000FF0: --SMTP Mail is clean 07/21/06 13:12:39 00000D14: --SMTP Mail is clean 07/21/06 13:13:04 00000D2C: --SMTP Mail is clean 07/21/06 13:13:04 00000BB8: --SMTP Mail is clean 07/21/06 13:14:10 000004A8: --SMTP Mail is clean 07/21/06 13:14:16 000008FC: --SMTP Mail is clean 07/21/06 13:14:28 00000D24: --SMTP Mail is clean 07/21/06 13:14:34 00000D70: --SMTP Mail is clean 07/21/06 13:14:55 000008B4: --SMTP Mail is clean 07/21/06 13:15:14 00000508: --SMTP Mail is clean 07/21/06 13:15:16 00000D40: --SMTP Mail is clean 07/21/06 13:16:31 000007D8: --SMTP Mail is clean 07/21/06 13:16:47 00000A8C: --SMTP Mail is clean 07/21/06 13:17:22 00000120: --SMTP Mail is clean 07/21/06 13:17:32 00000FBC: --SMTP Mail is clean 07/21/06 13:17:52 00000130: --SMTP Mail is clean 07/21/06 13:18:12 00000AF8: --SMTP Mail is clean 07/21/06 13:18:28 000005F8: --SMTP Mail is clean 07/21/06 13:18:37 00000CF4: --SMTP Mail is clean 07/21/06 13:19:06 000000FC: --SMTP Mail is clean 07/21/06 13:19:08 00000C08: --SMTP Mail is clean 07/21/06 13:19:31 000004A8: --SMTP Mail is clean 07/21/06 13:20:06 00000DBC: --SMTP Mail is clean 07/21/06 13:20:07 00000AF8: --SMTP Mail is clean 07/21/06 13:20:40 0000033C: --SMTP Mail is clean 07/21/06 13:21:59 00000560: --SMTP Mail is clean 07/21/06 13:22:23 00000A48: --SMTP Mail is clean 07/21/06 13:23:26 00000704: --SMTP Mail is clean 07/21/06 13:23:29 00000E90: --SMTP Mail is clean 07/21/06 13:24:06 000002D4: --SMTP Mail is clean 07/21/06 13:24:08 00000300: --SMTP Mail is clean 07/21/06 13:24:11 00000FF4: --SMTP Mail is clean 07/21/06 13:24:34 00000FCC: --SMTP Mail is clean 07/21/06 13:24:59 0000074C: --SMTP Mail is clean 07/21/06 13:25:01 00000EE0: --SMTP Mail is clean 07/21/06 13:25:04 00000C20: --SMTP Mail is clean
As you can see, the frequency of the sending his high. The only solution i found was to unplug my network cable!
After that i launched the avast scan … and it found nothing.
What can i do now ?
Thank you