MON PC ARRETE PAS DE SPAMER!!!!
actarus01
-
T -
T -
Mon pc envoi des mails tout seul et je c pas pourkoi....
J'ai NAV2003 a JOUR, J'ai AntiTrojan derniere version a jour
et j'ai meme TheCleaner derniere version a jour et ZONEALARM PRO!!!!
Au debut ca ma trouver des trojans, et la apparemment yen a plus puiske kan je lance les 3 prog je trouve plus rien donc pkoi ca continue d'envoyer des mails????
Je vois ke les mails sont envoyes car j'ai enclancher l'option email scanning de NAV2003 donc tous les mails envoyes et recus sont scannes, je ne sais plus koi faire a present, et JAI PAS ENVIE DE FORMATER!!!!
De plus depuis peu, o demarrage de mon PC ya 2 trucs louche ki lance ma connection internet a savoir :
r4.862378397571.com et 64.246.60.83 j'arrive pas a men debarrasser, a chake fois ke mon pc demarre 2 fois la connection internet se lance!!! Ca me soule!! plizzz HELLPP aidez moi!!!!
Derniere chose : Antitrojan me dis les choses suivantes :
Port 1080 ouvert : possibilite du trojan wingate
port 5000 ouvert : possibilite du trojan sockets de troie, Blazer 5
J'ai Windows XP Pro, athlon xp2000+ 512 Mo
je c pas si ca sert mais o moins jorais rien oublier.
Jespere que vous allez pouvoir m'aider PLIZZZZZZZ,Merci d'avance
J'ai NAV2003 a JOUR, J'ai AntiTrojan derniere version a jour
et j'ai meme TheCleaner derniere version a jour et ZONEALARM PRO!!!!
Au debut ca ma trouver des trojans, et la apparemment yen a plus puiske kan je lance les 3 prog je trouve plus rien donc pkoi ca continue d'envoyer des mails????
Je vois ke les mails sont envoyes car j'ai enclancher l'option email scanning de NAV2003 donc tous les mails envoyes et recus sont scannes, je ne sais plus koi faire a present, et JAI PAS ENVIE DE FORMATER!!!!
De plus depuis peu, o demarrage de mon PC ya 2 trucs louche ki lance ma connection internet a savoir :
r4.862378397571.com et 64.246.60.83 j'arrive pas a men debarrasser, a chake fois ke mon pc demarre 2 fois la connection internet se lance!!! Ca me soule!! plizzz HELLPP aidez moi!!!!
Derniere chose : Antitrojan me dis les choses suivantes :
Port 1080 ouvert : possibilite du trojan wingate
port 5000 ouvert : possibilite du trojan sockets de troie, Blazer 5
J'ai Windows XP Pro, athlon xp2000+ 512 Mo
je c pas si ca sert mais o moins jorais rien oublier.
Jespere que vous allez pouvoir m'aider PLIZZZZZZZ,Merci d'avance
A voir également:
- MON PC ARRETE PAS DE SPAMER!!!!
- Mon pc est lent - Guide
- Plus de son sur mon pc - Guide
- Reinitialiser pc - Guide
- Mon pc s'allume mais ne démarre pas windows 10 - Guide
- Ma cle usb n'est pas reconnu par mon pc - Guide
2 réponses
Hello. Don't know if you speak english, but I think, I have same problem as you. My Windows Explorer is still trying to connect to address 64.246.60.83 and I don't know what to do with it. I tried antivirus, trojan horse remover, but nothing helped. If you discover something, please let me know...
Hi, sorry, no french here either.
In response to Petr, I found the same situation on my machine and just discovered what is the cause: This seems to be a relatively new / not widespread malware which is turning your machine into a spam zombie, i.e. phoning home to a master machine (the ip you mentioned) and sending out spam afterwards. The activity is bound to explorer.exe, and in my case it was a dll loaded by explorer which was responsible.
So to get rid of this, do the following:
- find the file "wthunk32.dll" on your machine.
- rename or delete it.
- if it is not possible because the file is in use, you will first have to close down explorer: open a task manager and a command prompt, find the explorer process in task manager, kill it, rename the file using the command prompt, use task manager to start explorer.exe again afterwards.
To control success, use the command "netstat -ano" (win xp) on the command prompt. you should not find any open ports associated to the explorer process any more (compare the PID column with the PID column in task manager, can be activated using the "view" menu).
More to be posted on usenet ...
Greets, T.
In response to Petr, I found the same situation on my machine and just discovered what is the cause: This seems to be a relatively new / not widespread malware which is turning your machine into a spam zombie, i.e. phoning home to a master machine (the ip you mentioned) and sending out spam afterwards. The activity is bound to explorer.exe, and in my case it was a dll loaded by explorer which was responsible.
So to get rid of this, do the following:
- find the file "wthunk32.dll" on your machine.
- rename or delete it.
- if it is not possible because the file is in use, you will first have to close down explorer: open a task manager and a command prompt, find the explorer process in task manager, kill it, rename the file using the command prompt, use task manager to start explorer.exe again afterwards.
To control success, use the command "netstat -ano" (win xp) on the command prompt. you should not find any open ports associated to the explorer process any more (compare the PID column with the PID column in task manager, can be activated using the "view" menu).
More to be posted on usenet ...
Greets, T.