I am getting desperate - Advice needed from techy members re spam sending email trojan

by 35 replies
43
For the past 6 months My ISP - edit - IP not ISP - has been blacklisted and I have tried everything I can think of, including what CBL advises me to do, in order to clear the spam sending trojan that my computer is apparently infected with.

This weekend I noticed that from Friday evening through Monday late afternoon, everything showed clear, then at about 16h45 (South African time) it started up again which makes me think that there is human intervention rather than a bot of some sort.

I really need some advice.

Thanks
#off topic forum #advice #desperate #email #members #needed #sending #spam #techy #trojan
  • What do you mean your ISP has been blacklisted? Are all their customers affected the same way?

    Or did you mean your IP is blacklisted? An IP and ISP are not the same thing.

    What is CBL?

    What is the name of the Trojan?

    Has it been detected and identified by anti-virus software?

    What do you mean Fri-Mon everything ran clear? Do you mean your anti-virus detected no infection? But then on Monday your anti-virus did detect an infection? That seems weird.

    Best thing to do would be run antivirus and antitrojan software to detect and remove it.
    • [ 1 ] Thanks
    • [1] reply
    • Sorry, I meant IP not ISP.

      CBL - Composite Blocking List - The CBL

      From time to time the name of the trojan changes according to the CBL report at the moment it is showing as the cutwail virus.

      My anti virus does not detect it. (I have tried several)

      When I said that Mon to Friday everything ran clear, I meant that CBL could not detect anything and then on Monday late afternoon CBL reported that it had started up agan.

      I have run all sorts of software that I know of to detect and remove it but no luck so far.
      • [1] reply
  • I would hire a pro to get under the hood and run some diagnostics, there can be stuff hiding in there that your anti-virus will not detect. You need some-one with skills in this area to do a deep clean.
    • [ 1 ] Thanks
  • Try manually searching for and deleting it - Tutorial here

    Skip installing AVG or delete your antivirus first, can't have two running, sometimes they fight each other.
    • [ 1 ] Thanks
    • [2] replies
    • Deleted - message duplicated
      • [1] reply
    • @ HDRider - Thanks will try it on the PC. though I do not send or receive any emails on it. I do all my emailing on my iMac.

      Edit:

      Have checked according to that tutorial, but the PC is clean.

      Whatever the problem is, it is on my Mac.
      • [1] reply
  • Oh thanks- I didn't know about the CBL.

    I don't have a lot of anti-virus protection on my PC so if I get a problem (happens rarely) then I usually use Google and the name of the file/virus to find solutions.
  • I believe you don't have a trojan on your computer. I believe you are a victim of spooking.

    What I think is happening to you is someone is using your return email address in spam emails being sent out from another server. When people complain you are viewed as the person sending the emails and the bounces come to your server or computer.

    The only cure I have found is to delete the from email address you are currently using and use a different email address. The bounces will stop coming back to you and you can then begin the process of trying to get removed from black listes.

    Keep in mind the black lists that want to charge you money to remove the black list may not be black lists that very many ISPs use. So you may not want un list from all of them.

    I hope this has been helpful,
    Steve Yakim
    • [ 1 ] Thanks
    • [2] replies
    • Steve, thank you.

      I have never heard of Spooking before. Changing my email addresses might be a problem, but I will work something out.

      Hopefully it will solve my problem.
    • Sandy, good to hear your problem has been cleared up by your ISP changing your IP address. Not sure how this happened to you in the first place, however, I would advise you to never post your email address anywhere in any forums, or social media sites -

      Take care out there
      • [ 1 ] Thanks
  • Run Malware Bytes. (You probably already have, but run it again.)

    Then go here and request help:
    Malware Removal Assistance | MalwareTips.com

    I recently had a problem with a virus I just couldn't beat. They had me fixed up in less than 24 hours.

    Of course, this will not help you if your address has been spooked.
    • [ 2 ] Thanks
    • [1] reply
    • Hi Dan,

      I ran it several times on the PC, but can't do so on the mac.
      • [1] reply
  • [DELETED]
  • Sandy,

    There are a number of different ways this can happen. But I DOUBT you mean IP, unless you have a fixed IP address. If you don't, they can't very well block the IP. And they never block the IP of the client anyway, it is of the server. If you DON'T have a fixed IP address, your system is likely the CLIENT. This is usually the case. Outlook, Pegasus, and the like are clients. People DO sometimes infect clients, but servers are often infected as well. Did you check the IP chain in a raw email of the spam? Did you check with the email provider yet? The email provider is NOT always the ISP. I, for example, have a gmail.com, a Reagan.com, outlook.com(NOT to be confused with outlook, which is the client), and OTHER email providers. BTW outlook,com is a Microsoft domain that likely uses a popular email server called exchange.

    There IS a good chance the problem is not YOURS! MOST client infections do things like go through the users contact list and send emails via the users email.

    Steve
    • [ 1 ] Thanks
  • I'm going to be really honest here.

    About the only thing I can think of in this situation is to simply wipe the entire hard drive out and start over.

    Wish I could help you further, but sometimes starting over is the best thing to do.
    • [1] reply
    • Ouch, that is definitely not what I want to hear, but will do so if I am forced to.
  • You're not going to stop spoofing, outside of tracking the origin, and asking the servers to tighten things. Many servers don't check, and some just check the user. If it checks the user and domain, spoofing will be impossible with that server.

    Did you check for the IP in the spams IP list? If it is an IP from your client, the problem is there. If it from your server, it is there. If neither, it is likely spoofed. Of course, there is other evidence there as well. But where it starts is where the problem is. If you don't believe, and the spam is constant, just turn off your client at a given time. If you get spam sent after that time, the problem is elsewhere.

    BTW setting up your system from scratch could take a long time.

    Steve
  • 03h30 over here and I am flagging, thanks for all the help and advice so far, will get back to you after a couple of hours sleep.
    • [1] reply
    • I was thinking about that. Enjoy the sleep.

      Joe Mobley


      • [1] reply
  • Update:

    Activation of SPF has not worked for me. Will now try using DMARC, though feeling a bit confused by it.
    If anyone has any other ideas I would greatly appreciated it.
    • [ 1 ] Thanks
    • [1] reply
    • To those of you who have tried to help and who have been so supportive, I would like to bring you up to date.

      It turned out that I was on a dynamic IP and not a static one. After a bit (ok, a lot) of nagging my internet provider changed my IP.

      After several days of checking my IP with CBL, I am still clear. No more blacklist.

      Thanks everybody

      All the best

      Sandy
      • [ 2 ] Thanks
  • Karen,

    With this situation, it has nothing to do with her email address. Someone else ended up using the same IP she had used, and their machine was infected.

    Cutwail is a huge botnet that was sending billions of spams daily at one point. Probably still is, although compromised servers are a bigger issue now in that area. If you're ever curious about just how dangerous these things can be, Google Cutwail. It's infected over a million machines.

    BTW... Wombat alert: It's spoofing, not "spooking."


    Paul
    • [ 2 ] Thanks
    • [1] reply
    • thanks, Paul, for the clarification -
      I've been reading up on it - holy moly - crazy stuff!

Next Topics on Trending Feed

  • 43

    For the past 6 months My ISP - edit - IP not ISP - has been blacklisted and I have tried everything I can think of, including what CBL advises me to do, in order to clear the spam sending trojan that my computer is apparently infected with. This weekend I noticed that from Friday evening through Monday late afternoon, everything showed clear, then at about 16h45 (South African time) it started up again which makes me think that there is human intervention rather than a bot of some sort.