***spamhaus.org*** - Technology Forum - Home Theater, Computer, Televisions, Personal Electronics and more!
Technology Forum -  Home Theater, Computer, Televisions,  Personal Electronics and more!  
Go Back   Technology Forum - Home Theater, Computer, Televisions, Personal Electronics and more! > Computer Discussion > Networking & WiFi
User Name
Password


Reply
 
LinkBack Thread Tools Display Modes
Old 08-10-2006, 01:13 AM   #1 (permalink)
Senior Member
 
Join Date: Aug 2006
Referrals: : 0
Posts: 194
Points: 8,988.10
Bank: 0.00
Total Points: 8,988.10
Default ***spamhaus.org***

Hello all. Hopefully everyone had a great Thanksgiving and will have a wonderful Christmas.

The problem we've been having today is suddenly our outgoing mail is being rejected.

The error message we get is from www.spamhaus.org Hopefully some of you are familiar with the site. It's a spam guarding site that supposedly protects email reciepiants from spam, etc.

The problem is of course...we are not spammers and don't send out bulk emails in anyway what so ever. I went to the website but they list NO phone number and no way to contact them. Supposedly our IP adddress is not listed on their site either...I don't know if typing it in was a smart idea but I wasn't sure what to do at all...and we need to be able to send out emails.

If any of you had experience in dealing with this nonsense, please let me know. Thank you very much.
vega55 is offline   Reply With Quote
Old 08-10-2006, 01:14 AM   #2 (permalink)
Member
 
Join Date: Aug 2006
Referrals: : 0
Posts: 65
Points: 2,069.75
Bank: 0.00
Total Points: 2,069.75
Default

You need to contact your ISP and see where the e-mails are being blocked from.
iceman99 is offline   Reply With Quote
Old 08-10-2006, 01:14 AM   #3 (permalink)
Senior Member
 
Join Date: Aug 2006
Referrals: : 0
Posts: 218
Points: 7,598.86
Bank: 0.00
Total Points: 7,598.86
Default

There is a good chance that your computer has been infected and is being used as a zombie system to distribute SPAM... If so, there is probably other garbage there as well... It would be a good idea to post a HijackThis log to check it out...

To run HJT, extract it to a permanent folder such as one
you create like C:\HJT. Close all open windows and
browsers and make sure that all programs are enabled if
you use msconfig. Run it and Scan, then Save the log.
When the log window appears, Right click to Copy it, open
your browser and come here to Paste the entire log. Do
not make any changes until it is checked since most items
are either benign or essential to the computer.
heatwave is offline   Reply With Quote
Old 08-10-2006, 01:14 AM   #4 (permalink)
Senior Member
 
Join Date: Aug 2006
Referrals: : 0
Posts: 194
Points: 8,988.10
Bank: 0.00
Total Points: 8,988.10
Default

Okay, thanks for the advice. So here is what the Hijack log says.

Logfile of HijackThis v1.99.1
Scan saved at 9:24:41 AM, on 12/20/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security Professional\NISUM.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Norton Internet Security Professional\ccPxySvc.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe
c:\program files\common files\installshield\updateservice\isuspm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\DOCUME~1\Felix\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.prmcmortgage.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://v4.windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = localhost
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windows...b?1129217058350
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microso...b?1130769443218
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security Professional\ccPxySvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: Intuit Fuse Service - Intuit - C:\Program Files\Common Files\Intuit\Fuse\Service\Intuit Fuse Service.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton Internet Security Professional Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security Professional\NISUM.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

Thanks again for the advice. Hopefully the problem and solution lies here.
vega55 is offline   Reply With Quote
Old 08-10-2006, 01:15 AM   #5 (permalink)
Member
 
Join Date: Aug 2006
Referrals: : 0
Posts: 65
Points: 2,069.75
Bank: 0.00
Total Points: 2,069.75
Default

Unless you are running a mail server on your windows XP machine you are waisting your time. You did not mention what mail server you are using or if someone is hosting your mail server. when you went to spamhaus what IP address did you search on? was it your mail servers MX record address? try going to ordb.org and search on your e-mail domain name or mail.yourdomain.com or smtp.yourdomain.com then have it check third party RBLs to see if you are listed there. if you are, you need to find the reason why the "MAIL SERVER" is blacklisted fix the problem and submit for rescan to verify you corrected the issue and they will remove you from the list.
iceman99 is offline   Reply With Quote
Old 08-10-2006, 01:15 AM   #6 (permalink)
Senior Member
 
Join Date: Aug 2006
Referrals: : 0
Posts: 194
Points: 8,988.10
Bank: 0.00
Total Points: 8,988.10
Default

Okay. At first I did a search using the Router IP because I was under the impression that the router IP was the one used. However, a friend of mine had me go to www.myipaddress.com where it picked out showed me the IP address of each pc you logged on from.

In myipaddress.com, it automatically appears to give you the ip address of YOUR pc. I then checked under THAT and turns out we were black listed under the pc ip and not the router.

Please bare with me as my knowledge on this type of stuff is extremely limited. I apologize BUT thank you all for the help.
vega55 is offline   Reply With Quote
Old 08-10-2006, 01:15 AM   #7 (permalink)
Senior Member
 
Join Date: Aug 2006
Referrals: : 0
Posts: 218
Points: 7,598.86
Bank: 0.00
Total Points: 7,598.86
Default

You only have a bit of corporate spyware on your system that shows up in the HJT log... It would probably be a good idea to run a couple of other scans that go deeper... First run the Blacklight scan for rootkits...
heatwave is offline   Reply With Quote
Old 08-10-2006, 01:15 AM   #8 (permalink)
Senior Member
 
Join Date: Aug 2006
Referrals: : 0
Posts: 194
Points: 8,988.10
Bank: 0.00
Total Points: 8,988.10
Default

Okay, I understand now. Thanks.

We use our ISP's mail server. It's a very small office, so we dont have an IT guy or use our own setup. We currently have Rode Runner as our ISP. Hope this information is what you were asking for.
vega55 is offline   Reply With Quote
Old 08-10-2006, 01:15 AM   #9 (permalink)
Senior Member
 
Join Date: Aug 2006
Referrals: : 0
Posts: 218
Points: 7,598.86
Bank: 0.00
Total Points: 7,598.86
Default

"noadware" was only delisted as a rogue program last year and I still would not trust it to accurately report problems on your PC and to fix them... Also, if you have a trojan that has installed a server on your PC that is distributing SPAM, it is unlikely that the scans you ran have been effective... I suggest that you continue "waisting your time" (sic) and follow the instructions I posted earlier...
heatwave is offline   Reply With Quote
Old 08-10-2006, 01:16 AM   #10 (permalink)
Member
 
Join Date: Aug 2006
Referrals: : 0
Posts: 65
Points: 2,069.75
Bank: 0.00
Total Points: 2,069.75
Default

you still did not answer the question do you have your own mail server or are you using your ISPs mail server???? if you have your own mail server go to the mail server and go to myipaddress.com to see what its public address is as, usualy it will be different then the network PCs public address (the PCs usualy share an address and the mail server will have its own). The mail server public address is what you want to search on and test against as it will have port 25 open this is the SMTP port and if you close it you will not recieve e-mail then.
iceman99 is offline   Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Points Per Thread View: 1.00
Points Per Thread: 15.00
Points Per Reply: 5.00


» Links

» Links


Football Forum | Basketball Forum | Hockey Forum | Baseball Forum | Soccer Forum | Golf Forum | Lacrosse Forum
Wrestling Forum | Boxing Forum | MMA Forum | Paintball Forum | Snowmobile Forum | Snowboarding Forum | PWC Forum


Copyright (C) Verticalscope Inc Search Engine Optimization by vBSEO 3.3.2