From: Rick on
"Lil' Abner" <blvstk(a)dogpatch.com> wrote in
news:Xns9D29631A3F9E9butter(a)wefb973cbe498:
>
> This has been a highly frustrating situation. These people have two
> computers running through a router. Since they were spewing spam, the
> ISP blacklisted the router. The other computer had quite a bit of
> spyware and junk on it, so I copied off all their documents,
> reformatted it and put the documents back. She took that computer home
> and I have the other one here. The ISP says she is *still* spewing
> spam with the computer I wiped and reinstalled Windows in. The one I


You just formatted the drive? You didn't wipe the partitions and
repartition it? Possibly an MBR rootkit? You might try going to:

http://www.gmer.net/

and running GMER to see if it can find a rootkit on the system.

Another possibility is in the "documents" you copied over for them. Were
they scanned with a good AV program? One that scans ALL files? I've been
seeing a lot of infected .wma media files lately that people have been
picking up via Limewire.



--
Rick Simon rsimon(a)cris.com

Include "spam(trap)key" somewhere in the
body of any email to avoid my spam filters.
From: Lil' Abner on
Rick <rsimon(a)cris.com> wrote in
news:Xns9D297D5DDF796rlsomewhere(a)69.16.185.250:

> "Lil' Abner" <blvstk(a)dogpatch.com> wrote in
> news:Xns9D29631A3F9E9butter(a)wefb973cbe498:
>>
>> This has been a highly frustrating situation. These people have two
>> computers running through a router. Since they were spewing spam, the
>> ISP blacklisted the router. The other computer had quite a bit of
>> spyware and junk on it, so I copied off all their documents,
>> reformatted it and put the documents back. She took that computer
>> home and I have the other one here. The ISP says she is *still*
>> spewing spam with the computer I wiped and reinstalled Windows in.
>> The one I
>
>
> You just formatted the drive? You didn't wipe the partitions and
> repartition it? Possibly an MBR rootkit? You might try going to:
>
> http://www.gmer.net/
>
> and running GMER to see if it can find a rootkit on the system.

OK. Did that. It was clean
>
> Another possibility is in the "documents" you copied over for them.
> Were
> they scanned with a good AV program? One that scans ALL files?

Yes. Ran David's Multi-AV on it.
I've
> been seeing a lot of infected .wma media files lately that people have
> been picking up via Limewire.

No music except a few mp3's. They don't have LimeWire installed.

The ISP has unblocked the router. I'll know by morning if it will stay that
way.


--
--- Everybody has a right to my opinion. ---
From: Brian Cryer on
"Lil' Abner" <blvstk(a)dogpatch.com> wrote in message
news:Xns9D28AB6A08E4Ebutter(a)wefb973cbe498...
>I have a computer here that has been blacklisted by our provider because it
> was sending out spam email. The ISP recommends using Stinger (among other
> apps) to clean it up. So I ran it and when it was finished it did not
> indicate that it had found anything. My question is... is there supposed
> to
> be a report? Could it possibly be that it just fixed it and made no
> mention
> of it? Seems like I had that happen to me once before and the computer was
> clean.

Not all malware is classified as a virus, so it might be worth running
something like spybot or adaware on your PC and see if that throws up
anything.
--
Brian Cryer
www.cryer.co.uk/brian

From: Beauregard T. Shagnasty on
Brian Cryer wrote:

> "Lil' Abner" <blvstk(a)dogpatch.com> wrote:
>> I have a computer here that has been blacklisted by our provider
>> because it was sending out spam email. The ISP recommends using
>> Stinger (among other apps) to clean it up. So I ran it and when it
>> was finished it did not indicate that it had found anything. My
>> question is... is there supposed to be a report? Could it possibly
>> be that it just fixed it and made no mention of it? Seems like I had
>> that happen to me once before and the computer was clean.
>
> Not all malware is classified as a virus, so it might be worth
> running something like spybot or adaware on your PC and see if that
> throws up anything.

And:
MalwareBytes Anti-Malware for home use: http://malwarebytes.org/
SUPERAntiSpyware for home use: http://superantispyware.com/

--
-bts
-Four wheels carry the body; two wheels move the soul