Avast WEBforum

Consumer Products => Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier) => Topic started by: CraigLS on January 13, 2006, 06:38:09 PM

Title: email "suspicious message"flood
Post by: CraigLS on January 13, 2006, 06:38:09 PM
At startup, I get a huge number of "too many identical emails" message. The box lists the sender, the recipient, and the subject, but the only options given are "send" or "don't send." I cannot delete them from this dialogue box.

The box message looks like:

There are too many identical e-mails in appointed time


Sender: "Bright Melba"  <xgucgmfgka@caa.com
Recipient: iver@cablelynx.com
Subject: Re: There are too many e-mails in appointed time

and the "delete" option is grayed out and unuseable.

I know a virus has infected my system, but what can I do about it?

I also get a "connection timeout" error message that says:

Internet connection timeout elapsed. Continue waiting?
   (winlogon.exe -> smpt.publisingconcpets.com:25)

The statement in the parentheses changes. Sometimes it's:

(winlogon.exe ->gateway.mailrover.net:25)
 
or something else

So what do I do?
Title: Re: email "suspicious message"flood
Post by: DavidR on January 13, 2006, 08:20:53 PM
You have malware trying to connect to the internet using the email ports, and avast expects it to use the email protocol, this is what causes the time outs.

First step you can block the winlogon.exe from accessing the internet using your firewall (not if you have windows firewall).

What is your OS and Firewall?

If you haven't already got this software (freeware), download, install, update and run it. Start with Ewido.
1. Ad-Aware (http://www.lavasoft.de/support/download)
2. Spybot Search and Destroy (http://www.safer-networking.org/index.php?lang=en&amp;page=download)
3. Spywareblaster (http://www.javacoolsoftware.com/spywareblaster.html) Don't install this until you are clean.
4. Ewido Security Suite (http://www.ewido.net/en/) If using winXP. or a-Squared free (http://www.emsisoft.com/en/software/free/) if using win98/ME.
Title: Re: email "suspicious message"flood
Post by: CraigLS on January 13, 2006, 11:55:36 PM
I'm running Windows XP Professional on a 2.4 GHz Pentium 4. As far as I know, the only firewall i have  is whatever comes with the OS I haven't installed anything else. I suppose I should?

I'll try the software you list. Thanks. I'll let you know how it works.
Title: Re: email "suspicious message"flood
Post by: DavidR on January 14, 2006, 12:16:26 AM
The XP firewall is better than no firewall, but doesn't stop anything that does manage to penetrate your defences connecting to the internet and transmitting your personal data or downloading more of the same. Zone Alarm free is user friendly, Kerio or comodo are some others.
Title: Re: email "suspicious message"flood
Post by: Lisandro on January 14, 2006, 04:06:23 AM
(winlogon.exe ->gateway.mailrover.net:25)
This seems to be an infection.
Besides David's good suggestions of spywares, run avast at boot time (schedule it) and disable/enable again the System Restore feature of Windows.
Cleaning Internet temporary files is a good thing too  :)
Title: Re: email "suspicious message"flood
Post by: Olórin on February 21, 2006, 11:31:06 AM
hello Tech,
may i ask, how do i change those settings? i.e run avast at boot time, disable/enable System Restore feature of Windows
Title: Re: email "suspicious message"flood
Post by: Lisandro on February 21, 2006, 01:15:06 PM
hello Tech,
may i ask, how do i change those settings? i.e run avast at boot time, disable/enable System Restore feature of Windows
To run avast at boot time, just start avast, right click any part of the skin and in the popup menu choose Schedule boot time scanning.
To disable system restore in windows, just search the board. I've post a lot of times some links in Microsoft site for that. I'm on Linux right now and don't have my avast knowleadge database available... maybe later  8)
Title: Re: email "suspicious message"flood
Post by: DavidR on February 21, 2006, 04:19:13 PM
Win XP-ME - How to disable System Restore (http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm)

I've just noticed from one of your other threads that you are using win2k and that I believe that doesn't have system restore.
Title: Re: email "suspicious message"flood
Post by: Lisandro on February 21, 2006, 11:06:19 PM
I've just noticed from one of your other threads that you are using win2k and that I believe that doesn't have system restore.
Not only believe but could be sure... Windows 2k does not have this feature.