• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Virus/spyware sending email?

DevilMan

Gawd
Joined
Jan 15, 2001
Messages
542
I was contacted by my isp about sending spam emails. This occured from one of the computers from work. We have 4 with two having email on them.
Is there such a thing as a virus that can send an email without it going through the email program?
I have run every virus scan and spyware programs known to man but it finds the regular crap spyware and no viruses. I have checked the in/out logs through the firewall and everything looks ok going out.

Anyone know of any spyware/viruses that send mass emails? Or what I could use to find out what is doing it?
 
On the other computers I would set a first address. If it's just one computer then set it to a known bad address. IE: 01abc@fisheatworms.com that way if you get a returned mail notice you will know something on your system is sending out.

If it's more than one I would make a default first and have that address come back to the admins computer. Set up a rule on the admin computer to put any mail into a special inbox folder. Be sure that the preview windows are closed and if the admin gets a mail in that box then they know to check out a machine that sent the email.

Yes there are viruses out that will send out mail, but whats more common now is spoofing the sender. The virus will get the address from and infected users inbox and spoof the return address. Using the header information you can normally tell which ISP/domain the infected computer with.
 
I am using Sygate personal firewall.

I do not have any of the information pertaining to the emails. I just got an email from our ISP saying we were turned in for spamming. The tech was not very helpful at all when I asked what the person got as an email so I might be able to track it down on the system.
I asked if maybe it was someone spoofing the email and he reasured me that it was our IP address that it came back to. He felt pretty confident in his answer.
A month went by with nothing then all of a sudden I get another email for the same thing. Almost a month to the day as the other.
Like I said I monitor the comps as best I can but with 8 people that have access to them it can get tough to know when things are happening.
Would it be helpful to keep and eye on all the activity on the computer? I do not want to spy but I really need to know what people are doing and where they are going on the interenet to narrow it down. They are reluctant to tell me what they have been doing that might not be on the up and up (ie. porn sites)

I also use AVG AntiVirus, Ad-Aware, and just installed File Checker.
 
Is this just a small peer to peer network with no server? What kind of internet connection? For email you are using your ISP's mail server correct?
 
It is a small network with one server and three workstations. Two of the workstations are using outlook express with the default email assigned with your ISP. I have checked outgoibng email on the days they said this was happening but there was nothing outgoing that registered in the outbox. Maybe it wouldn't though.

I used a couple of other programs that scan ports and one found Port 1025 being used by "network Blackjack" Remote Storm.

I seem to get a lot of hits on the server with people trying to scan Remote Administrator. The firewall picks them up though.

Thanx for the replys by the way. I am pulling whats left of my hair out trying to pinpoint this.
 
Back
Top