Author Topic: strange behaviour mail scanner  (Read 5129 times)

0 Members and 1 Guest are viewing this topic.

batterio

  • Guest
strange behaviour mail scanner
« on: January 15, 2007, 10:19:22 PM »
hi avast friends.
os  win xp sp2
av avast 4.7 home
anybody would know why lately the little mail scan mail icon pops up every so often when no mail client is in use? hovering on it it says that it is scanning mail for: 147.163.79.126
i have scanned my notebook with different anti spy/adware and it results clear. ???
thanks

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89056
  • No support PMs thanks
Re: strange behaviour mail scanner
« Reply #1 on: January 16, 2007, 12:32:03 AM »
You may well have a trojan spambot on your system, enable the 'Show detailed info on performed actions' this will show you what is going on.



Exactly what were you doing when this happened, browsing, p2p, etc. what ?
What is your firewall, this should ideally be stopping unauthorised outbound connections ?

If you haven't already got this software (freeware), download, install, update and run it, preferably in safe mode.
1. Ewido, a.k.a. avg anti-spyware If using winXP. or a-Squared free if using win98/ME.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

batterio

  • Guest
Re: strange behaviour mail scanner
« Reply #2 on: January 16, 2007, 11:35:49 AM »
thanks DavidR. when it happens i am actually browsing and p2p.
i performed scans with adaware, spybot, spyware terminator and superantispyware and everything was ok. now i will try the soft you indicated and see.my firewall is the windows default :-[
thanks for now.
« Last Edit: January 16, 2007, 11:38:37 AM by batterio »

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: strange behaviour mail scanner
« Reply #3 on: January 16, 2007, 11:55:08 AM »
my firewall is the windows default :-[
It does not protect you to 'outbound' connections, programs that connect the Internet from your computer.
Use TCPView to see if this will identify the processes making the connections http://www.sysinternals.com/Utilities/TcpView.html
The best things in life are free.

batterio

  • Guest
Re: strange behaviour mail scanner
« Reply #4 on: January 16, 2007, 12:07:59 PM »
the process is very random and not relly obsessive and constant.
could you please reccomend me a good firewall that would complete and cohabit well with avast?
thanks

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: strange behaviour mail scanner
« Reply #5 on: January 16, 2007, 12:16:49 PM »
could you please reccomend me a good firewall that would complete and cohabit well with avast?
Comodo or ZoneAlarm.
Both are free. Comodo is stronger in protection. ZoneAlarm is easier to start and understand.

Personal Firewall Tests & Results. Firewall rating: http://www.matousec.com/projects/windows-personal-firewall-analysis/leak-tests-results.php#firewalls-ratings

Freeware firewalls:
http://www.firewallleaktester.com/tests_overview.php
http://www.thefreecountry.com/security/firewalls.shtml
http://forum.avast.com/index.php?topic=22742.0;topicseen
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89056
  • No support PMs thanks
Re: strange behaviour mail scanner
« Reply #6 on: January 16, 2007, 02:29:37 PM »
thanks DavidR. when it happens i am actually browsing and p2p.
i performed scans with adaware, spybot, spyware terminator and superantispyware and everything was ok. now i will try the soft you indicated and see.my firewall is the windows default :-[
thanks for now.

What P2P program are you using ?
Some communicate using email ports and that causes the Internet Mail scanner which monitors those ports to scan the content. The 'Show detailed info on performed actions' if you enabled it as I suggested should show this.

You could also change some settings in the Internet Mail, set the protection to High, click the Customize button, Advanced Tab, enable the Timeout section, reduce the delay to say 20 seconds and have it Ask. These settings can be reversed after the test to identify what is the cause I would hoever recommend you leave the scanner sensitivity on High.

If it is your p2p application communicating on the email ports the timeout warning should show this, do a screen shot of the warning if you get it.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

batterio

  • Guest
Re: strange behaviour mail scanner
« Reply #7 on: January 16, 2007, 05:04:02 PM »
thanks very much guys. i use bit torrent and i have all avast settings set on high, just in case.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89056
  • No support PMs thanks
Re: strange behaviour mail scanner
« Reply #8 on: January 16, 2007, 05:18:49 PM »
Your welcome.

Sorry I don't use any P2P application so I don't know who you would check the communication port settings in bit torrent.

Have you made the tweaks I suggested as those or TCPView is likely to pinpoint the true problem ?
Let us know what is found as suggestions without feedback makes it hard knowing what you tried, etc.
« Last Edit: January 16, 2007, 05:20:23 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: strange behaviour mail scanner
« Reply #9 on: January 16, 2007, 05:22:55 PM »
I have all avast settings set on high, just in case.
The better balance between protection and performance is 'Normal' level of the Standard Shield provider  ;)
The best things in life are free.

batterio

  • Guest
Re: strange behaviour mail scanner
« Reply #10 on: January 16, 2007, 05:31:31 PM »
I have all avast settings set on high, just in case.
The better balance between protection and performance is 'Normal' level of the Standard Shield provider  ;)
ok i didn't know.
Your welcome.

Sorry I don't use any P2P application so I don't know who you would check the communication port settings in bit torrent.

Have you made the tweaks I suggested as those or TCPView is likely to pinpoint the true problem ?
Let us know what is found as suggestions without feedback makes it hard knowing what you tried, etc.

i changed the settings as you suggested, but since i posted it hasn't happened again. as i say it is not a constant issue. a few times last week, a couple this morning. it is very random.
if i get some result i will come back to you.
thanks

Offline alanrf

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3870
  • Just an avast user
Re: strange behaviour mail scanner
« Reply #11 on: January 16, 2007, 10:52:08 PM »
If, as seems most likely, that this is a p2p connection that is being scanned by avast then how frequently it happens has nothing to do with your settings. 

The problem occurs when another peer out in the network tells you to connect to the peer at its port 25, 110, 119 or 143.  It is the fact that you are making the connection to that port at the other peer that avast is intercepting.  So it is not under your control at all and you will only see it happening infrequently since many other peers will not use those ports. 

The best way to stop this happening is to tell the avast Internet Mail provider not to scan connections made by bit torrent. 

To do this edit the avast4.ini file (usually found at C:\Program Files\Alwil Software\Avast4\DATA\avast4.ini ) and in the section headed:

[MailScanner]

add a line:

IgnoreProcess=bittorrent.exe


If you continue to see the "blue light" tray icon after this when you are not processing your email or newsgroups would be a cause for further investigation.

@avast team

Any good reason why this process should not be in the list of automatic exclusions for the Internet Mail provider?