Page 1 of 1

Welcome To Zombie.com

Posted: Mon Nov 08, 2004 3:13 pm
by bash
I think I'm a zombie. I've noticed activity on the router when none should be happening and even after I quit out of Outlook, when I look in the Task Manager it shows Outlook.exe running and using 50% of my CPU resources. This all started recently when I updated MS Office Suite. I also notice a new message when I start up Outlook that says *Some Application Is Trying TO Access Your Address Book, Allow or Disallow?* or something along those lines. Any guesses and any way to verify whether I've become a spam machine for the living dead? Thanks in advance for any insights.

I'm running updated AntiVir 24/7, as well as have firewall on and periodically check things with Spybot and Adaware. All come back with no alerts. Intel P4.

Posted: Mon Nov 08, 2004 3:47 pm
by WarAdvocat
Did you try an online virus scan? If not, I suggest Trend Micro's Housecall. It usually works even when malware has disabled Norton & Macafee :)

At the very least it's an additional angle of attack for you to try.

Posted: Mon Nov 08, 2004 6:34 pm
by Avder
Get a strong firewall that can be set to completely kill all net traffic except dhcp and dns. Sit online overnight with it, and check the log the next day to see if applications are trying to access the net without your consent. A good firewall should log the following things: The full path of the application that tried to access the net, the address they tried to contact, and what port they were trying to send from.

I cannot stress the full path thing enough because a lot of things will simply dump to %systemroot%\system32 and rename themselves to the names of often used programs in hopes that the firewall only checks the executeable name.

Posted: Tue Nov 09, 2004 4:15 pm
by Top Wop
WarAdvocat wrote:...even when malware has disabled Norton & Macafee :)...
Last time that happened to me I just stopped using their ★■◆● and relied more on that Housecall (never had a reason to use it yet!) and Adaware. Common sense is the best anti-virus. I dont need a resource hogger to substitute for that.

Posted: Tue Nov 09, 2004 10:54 pm
by MD-2389
bash, download a copy of Hijack This! and post the log it generates.

Hijack This!

Posted: Tue Nov 09, 2004 10:59 pm
by Grendel
Try Tcpview, look for weired connections..