Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 





Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Networking Forum > Security and Firewalls
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read

Security and Firewalls Protecting you against unwanted people and programs

Reply
 
Thread Tools
Old 12-22-2007, 03:16 PM   #1 (permalink)
Registered User
 
Join Date: Dec 2007
Posts: 1
OS: Windows XP


Virus I can't remove...

It started out about 2 weeks ago. I took notice my computer was acting a slow, and my cable modem's transmit and receive lights were constantly going, like I was doing something over the internet, ie. playing a game or browsing the web.

I talked to a bunch of friends and some suggested the program called Axence NetTools, so I went to their website and downloaded it. I am computer literate but it took a little to find out what I needed it to show me.

I clicked on the Local Info button, along the top of the screen, and it brought up all of my network traffic, incoming and outgoing. and to my suprise there were over 50 connections using the same PID, and used the svchost.exe program. The connections (on the remote side) would be connected on port 25, and the ip addresses, and domains seemed to be mostly mail servers.

I basically terminated the process ID that all this was causing, and then all my network activity went back to normal, even my cable modem stopped the activity.

I thought I was safe but a few hours later, I walked by my computer and saw the cable modem lights going nuts again, so I check my network activity, and sure enough the same thing was going on.

After restarting my computer, I monitored my activity, and it seems either a specific domain is polling my computer or the virus contacts the other computer to let it know I am online, it goes to reverse-mtl-60-87.existservers.com and after it contacts that address, all hell breaks loose and all of those connects start spawning.

One day, I had over 100 connections.

No virus software has been able to detect it, and I have been trying multiple free ones just to see if any can find it. I am at my whits end on this.

Thanks for taking the time to read this,
C.W.
theoneptd is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 12-23-2007, 02:11 PM   #2 (permalink)
Manager, Networking Forums
 
johnwill's Avatar
 
Join Date: Sep 2002
Location: S.E. Pennsylvania, US
Posts: 28,753
OS: XP-Pro, Vista, Linux


Blog Entries: 1
Re: Virus I can't remove...

Please follow this HJT Log 5 Step Process to post a HijackThis log in the HijackThis Log Help forum here.
__________________
If TSF has helped you, Tell us about it! or Donate to help keep the site up!

Microsoft MVP - Windows Desktop Experience
johnwill is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -7. The time now is 05:58 AM.



Copyright 2001 - 2008, Tech Support Forum

Search Engine Friendly URLs by vBSEO

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81