Computing.Net > Forums > Security and Virus > virus/trojan self mailer

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

virus/trojan self mailer

Reply to Message Icon

Original Message
Name: Iceberg_Slim
Date: April 24, 2004 at 23:07:30 Pacific
Subject: virus/trojan self mailer
OS: XP PRO
CPU/Ram: amd 2100/512
Comment:

before i begin i will tell u what i have

latest versions and updates of

norton antivirus 2004
ad-aware
cwshredder
bazooka spyware scanner
browser hijack blaster

im not runnig MSjava, im using sunjava in IE browser.

a self running SMTP mass mailer virus/trojan has attacted itsself to svchost.exe and continally emails itself to random email servers such as aol and earthlink and att and yadda yadda(determined this from netstat in command line). only way i caught this was that i have norton set to scan all outgoing and incoming emails. a popup in the lower right corner opens from norton saying its scanning an email. norton lets the scan through.

there are no weird registry entries of any kind.

i determined the svchost.exe process that the virus/trojan was attached to by running filemon from sysinternals. i got the PID of the process and killed it. the mass emailing has stopped after that. upon the service restarting the mass emailing begins.

i got no clue what to do. :(


Report Offensive Message For Removal


Response Number 1
Name: Iceberg_Slim
Date: April 24, 2004 at 23:39:21 Pacific
Reply: (edit)

the virus/trojan tries to create a file called faeec41a.tmp in the folder

C:\WINDOWS\Temp

and i would guess its trying to take that file and mail it out


Report Offensive Follow Up For Removal

Response Number 2
Name: Valerie (by Garibaldi)
Date: April 25, 2004 at 01:23:17 Pacific
Reply: (edit)

Got a name for the trojan or process running in svchost???

V...


Report Offensive Follow Up For Removal

Response Number 3
Name: bbqbeef
Date: April 25, 2004 at 12:46:14 Pacific
Reply: (edit)

try http://trojanscan.com/ to identify the culprit.

A firewall would stop undesired outgoing traffic.


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you have your own blog?

Yes
No
I did before
I will soon


View Results

Poll Finishes In 4 Days.
Discuss in The Lounge
Poll History




Data Recovery Software