PDA

View Full Version : Spam problem


SystemError
29-11-2003, 09:46 PM
In the last few weeks something has infected my computer which is sucking up my bandwidth. I was notified by one of the Swiftel admins that I could no longer use email because my computer was sending spam to the outgoing mail relay server. He gave me a list of virus scanners I could use to detect the problem so I checked it out, and using one of the online scanners found a VBS worm in the system. Zonealarm was still reporting a good 5-10 breaches every 3 seconds. So unfortunately, the VBS worm wasn't what was affecting the computer and using up bandwidth.

A couple of days later I did a trojan scan with another program and found a keylogger. It didn't find anything else. I tried panda activescan in safe mode (norton won't work) and it didn't find a thing. I noticed in there were multiple svchost.exe services running in the background, each with different sizes, but some people say it is quite normal to have this sort of thing.

Seeing as this system is running Server 2003 Enterprise, I thought perhaps Microsoft could have done something in the way of having safeguards against security breaches like this - bit much to hope for.

Everytime I restart, it goes fine -- for about 10 minutes. Then I notice gradual slowdowns in speed (sometimes down to 7-10K/sec) and latency everywhere is terrible (500-2000ms).
Anyway, I'm pretty much exhausted of ideas and need some advice on fixing the problem.

My monthly quota has filled up very fast because of the external bandwidth usage, and its already reached 12gb. I normally use around 4-6gb a month.
Short of formatting, does anyone have any clues?
Thanks,

- AB

mavrick5
04-12-2003, 09:20 AM
Download a product called Spybot Search and Destroy and run it. It will find and remove any spyware software that may be installed and remove it completely. I use it at work and it is very good. This may not solve your problem but it may help.

There are a couple of very good trojan killers around and I believe that Kaspersky's AV product is the best but it is a bit more expensive than others. You could also try a product that sniffs the ports to see what is happening.

Try these:

Tauscan - port scanner and checks for trojans.
Agnitum - personal firewall and port jammer.

Dirge
04-12-2003, 09:51 AM
You could also try the cleaner {trojan killer_ from www.moosoft.com. It comes with a 30 day evaluation period.