I never really thought about he hijacked computers. I should have realized that after seeing different IPs for most erronius messages. I've been monitoring the site i've been working on for a couple of days and the spam is hitting the site every 15 minutes on average. Guess there's nothing that can be done outside of CAPTCHAs in the forms.
Ah well, here's 500 points!
Main Topics
Browse All Topics





by: TolomirPosted on 2009-11-04 at 01:57:36ID: 25737767
Problem with spam is that 99% are today sent by hijacked windows computers.
A hijacked computer keeps a (constant) connection to a control server downloading and installing tools without asking the user.
Last weekend I had such a windows 2000 computer, when I tried to run the ususal antivirus solutions it was able to deinstall some of the malware, but I was not able to remove the control component, afer 10 minutes on the network, something else was installed.
Then I ran an antivirus solution from bootdisk (avira) with latest virus patterns: Each and every exe file was infected by a virus, hidden from the 1st antivirus solution I tried with windows running. In the end I was lucky to move all data files on an usb stick and did move all files to a vista computer.
Will you sue such a user? Of cause that computer did send spam emails.... but without knowing, antivirus while running windows did show no infection.
Only tcpview did tell me that it was still connected to a control server and that control server was for sure just another victim....
Tolomir