Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

pc sending emails, can't fix it. 1

Status
Not open for further replies.

petermeachem

Programmer
Aug 26, 2000
2,270
GB
Not a virus, but I can't think of a better place to ask.
It's a customers pc running win98.
It is sending a stream of emails every minute or so. Sample below of part of the bounce back of invalid addresses it sent:-
Content-type: text/rfc822-headers

Received: from 218.165.105.47 by user3 ([82.69.14.49] running VPOP3) with ESMTP; Tue, 30 Dec 2003 10:14:09 -0000
From: =?Big5?B?uvS49KbmvlCqQbDIpKSk37Nxqr4uLi4=?= <k7wnk.2wrjy@zdl.net>
Subject: =?big5?B?wdmmYqXOtseyzqahqrqm5r5QpOiqa7bcP6bzpKO41bjVuXGkbKbmvlAss8y1dc==?= =?big5?B?rsm2oaS6s8yk1qq6uXe64iyn4qdBqrqyo6t+sGWo7FVTRVKqurK0q2W=?=
To: =?Big5?B?uvSttqxbs10splez5qbmvlAspU6ryLVvq0gsq0/D0sX9p0G6obdOqrqqQbDI?= <nds2343@yahoo.com.tw>
Content-Type: multipart/alternative; boundary=&quot;=_NextPart_2rfkindysadvnqw3nerasdf&quot;; charset=&quot;BIG-5&quot;
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Sender: &quot;ºô¸ô¦æ¾PªA°È¤¤¤ß³qª¾...&quot; <k7wnk.2wrjy@zdl.net>
Date: Tue, 30 Dec 2003 18:14:34 +0800
X-Priority: 1
X-Library: Dynamailer®Ö¤ß§Þ³N
X-Mailer:Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE:produced By Mircosoft MimeOLE V6.00.2600.0000
Message-Id: <VPOP31.5.0e.20031230101411.760.7.24.143f15df@user3>
X-Server: VPOP3 V1.5.0e - Registered

User 3 if the name of the pc. The pc use Vpop to send mail and you can see the bad mail going out of the vpop status window. OE is used as a client, but doesn't need to be running to send the bad mail. The other pc connected to this one is not to blame.
Spybot came up with a couple of things, Alexa and a Media Player exploit, which I cleared. Didn't fix the problem. Nortons doesn't find anything nor does Pestpatrol.
When I looked at it originally, Zonealarm was allowing a programme called psybnc internet access. The staff say they neither downloaded it nor let Zonealarm run it. This seems to be a Unix irc programme? Removed, but still thesame problem. Msinfo showed that hwinfo.exe was in the start list with psybnc as a name, now removed. Hwinfo hadn't been changed, just added to the start list.
SFC came up with nothing bad.

Stopping vpop stops the problem, but is a bit incovenient.

I assume something is executing and using the smtpserver address from the registry to send email. This would send via Vpop.

Has anyone got the slightest idea what is going on here? I am completely stuck. If I can't fix it soon, I shall have to format the disc and reinstall everything. I'd rather avoid that as it takes a time.



 
Get your client to login as vpop postmaster and remove the junk emails from the vpop3 out queue before they get sent - short term measure until you can get something done properly.
I am uk based so will be here in the morning.

John
 
I think I've cracked it. Pestpatrol mentioned Ghost Radmin. The office uses a copy of Radmin, and I thought this was just a strange name and why did they think it was a baddy. Just looked on Their radmin doesn't work at the moment as it asks for a password...
Try binning that in the morning.

 
Right, I ran Pestpatrol and I still have the problem. Log below

Logfile of HijackThis v1.97.7
Scan saved at 11:41:43, on 31/12/03
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\POPROXY.EXE
C:\PROGRAM FILES\AHEAD\INCD\INCD.EXE
C:\PROGRAM FILES\ALCATEL\SPEEDTOUCH USB\DRAGDIAG.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\PROGRAM FILES\PESTPATROL\PPCONTROL.EXE
C:\PROGRAM FILES\PESTPATROL\PPMEMCHECK.EXE
C:\PROGRAM FILES\PESTPATROL\COOKIEPATROL.EXE
C:\PROGRAM FILES\ANALOGX\PROXY\PROXY.EXE
C:\PROGRAM FILES\WINZIP\WINZIP32.EXE
C:\WINDOWS\TEMP\HIJACKTHIS.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [NAV DefAlert] C:\PROGRA~1\NORTON~1\DEFALERT.EXE
O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NAVAPW32.EXE /LOADQUIET
O4 - HKLM\..\Run: [Norton eMail Protect] C:\Program Files\Norton AntiVirus\POPROXY.EXE
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] &quot;C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe&quot; /icon
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\Program Files\PestPatrol\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] &quot;C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe&quot; -reg
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - Startup: Microsoft Office.lnk = c:\WINDOWS\Application Data\Microsoft\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\misc.exe
O4 - Startup: proxy.lnk = C:\Program Files\AnalogX\Proxy\proxy.exe
O4 - Startup: VPOP3.lnk = C:\vpop3\vpop3.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://c:\PROGRA~1\MICROS~1\OFFICE10\EXCEL.EXE/3000
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -


 
Hello,

I've looked at the log and there doesn't seem to be anything I have positively identified as known malware or otherwise dodgy code, but the &quot;MISC.EXE&quot; file in the Microsoft Office folder doesn't look like a normal part of the MS Office suite to me, but I haven't used the latest version and am not 100% sure.

Also, in between the first emails and the HijackThis log - the IE version has gone from 6.00.2600.0000 to IE6 SP1 (6.00.2800.1106) - did you update it this morning?

John
 
I've removed misc.exe and yes I did update IE.
The bugger had added an ip address to local servers on vpop. This seems an awful lot of trouble to go to to advertise ink jet cartridges. Just waiting to see if that has fixed it. I'm going to buy these people a hardware firewall. They switched off Zonealarm which may or may not have caused the grief in the first place.
So far I've found
Ghost Radmin
IRC programme
Addition of ip address to vpop

Like to find one of these people and give them a good smack, although I have earned myself quite a bit of cash in the process.

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top