you have a suspicious message...?

hi everyone

latelly, a lot of boxes from avast av are appearing with the message, …suspicious message, there are too many emails sent at the same time, followed by e-mail adresses and subjects that i don’t know at all. there are only 2 selection boxes that i can choose, continue or don’t send.

could any of you please give an hint on this one? is this a virus? is this something departing from my computer to another? tranferin of information? i’m totally lost with this matter, don’t really know ehat it is or what to do.

thanks in advance

(sorry for my poor english, i hope i’ve made myself clear)

What is your Operating System and email program ?

This is the heuristics of the email scanner at work.

It would appear that your system is infected with a spambot sending out emails without your knowledge. So the correct answer is don’t send. Unless it is you sending bulk male for a legitimate purpose, which I doubt.

As a result of this have you had any Timeout messages, if so the information contained in it can help to track down the culprit.

Do you have a firewall (please don’t say XP’s firewall, which doesn’t provide outbound protection) ? this should stop unauthorised outbound internet access.

Hi david

thanks for your fast response

this computer uses win 2000, without any email program. we check the email directly in the mail’s server, such as hotmail or yahoo.

I’ve run avast and it recognised a trojan virus, which was moved to chest. i can’t really remember the name of the virus, because my mum deleted it. it was mns or msn"something".exe. sorry for the lack of data.

i also used the avast virus removal tool, but it didn’t detected anything. i really can’t tell how a spambot in the system, sending those mails and avast didn’t found it. i get the warnings of the outgoing mails, but i can’t find the file or program responsable for it!

suddenly appear several boxes with warnings messages, but all only with the subject and a destination, not much more. next time i see one of those, i’ll try to post the message here, surely it can help.

I’ve always answered don’t send, but it’s disturbing, once in a while, while you’re working, to have a boom of warning messages allover your screen, not to mention the eventual privacy violation.

i saved this one for last…but it isn’t the best…Do you have a firewall ? nop…but i use only the XP one in my laptop. can you give some information about a decent firewall?suggestions? which one do you use? does avast provide one?

thks a lot again

It doesn’t have to have an email program many spambot and mass mailers come with their own means of sending emails, that is why it is important to have a girewall that can stop unauthorised outbound connections.

Info on infections, etc. are in the avast! Log Viewer and if win2k has an event viewer (like XP) also there.

avast is essentially an anti-virus program that also picks other malware. However, one specialised tool is unlikely to catch everything. The removal tool won’t detect anything that the main program doesn’t, after it is a specialised tool to remove certain worm infection (the list is on the site).

Without a firewall you are playing russian roulette with an automatic, it is an essential part of your security. Zone Alarn free is fine, has areasonably friendly user interface. The one I use is Outpost Pro, a paid for version and not I would say an easy first firewall.

I suggest you also download one of these Ewido if it is OK with win2k, otherwise A-squared Ewido Security Suite If using winXP. or a-Squared free if using win98/ME.

If you haven’t already got this software (freeware), download, install, update and run it.

  1. Ad-Aware
  2. Spybot Search and Destroy
  3. Spywareblaster Don’t install this until you are clean.

Also useful as a diagnostic tool to see what is running on your system - Download HiJackThis.zip - HJT Information HiJackThis Tutorial 1 or HiJackThis Tutorial 2
For an on-line analysis - HiJackThis Log file - On-line Analysis OR HiJackThis Log file - On-line Analysis 2
Ignore any 023 reference to avast processes, this is a hiccup in the HJT 1.99.1 (especially missing file entry for avast), if you need any help with any of the analysis let us know.
OR - Post your hijackthis-Log here for a diagnosis: tomcoyote.org/hjt