If you haven't already got this software (freeware), download, install, update and run it, preferably in safe mode.
1.
Ewido, a.k.a. avg anti-spyware If using winXP. or
a-Squared free if using win98/ME.
These spambot trojans are often difficult to detect as there is no harmful effect, ither than this clogging of system resources and sending spam.
Your firewall should be able to stop unauthorised outbound connections, unfortunately XP's firewall provides no such protection.
Whilst the windows XP firewall is usually good at keeping your ports stealthed (hidden) it provides no outbound protection and you should consider a third party firewall.
Any malware that manages to get past your defences will have free reign to connect to the internet to either download more of the same, pass your personal data (sensitive or otherwise, user names, passwords, keylogger retrieved data, etc.) or open a backdoor to your computer, so outbound protection is essential.
- Zone Alarm free
http://www.zonelabs.com works fine with avast and has a reasonably friendly user interface. There are others, Comodo, Sunbelt Kerio, Jetico, etc.
See some firewall tests for comparison, some are freeware but many are paid for versions
http://www.firewallleaktester.com/tests.php. Also see
http://www.thefreecountry.com/security/firewalls.shtmlYou could also try TCPView which shows what connections are established and what program/file initiated them, get it at
http://www.microsoft.com/technet/sysinternals/default.mspx .
If none of the above detects it, I would like to hope one of them should be able to detect it, then try HiJackThis, useful as a diagnostic tool - Download
HiJackThis.zip - HJT Information
HiJackThis Tutorial 1 or
HiJackThis Tutorial 2 or
HiJackThis Tutorial 3On-line analysis -
HiJackThis Log file - On-line Analysis OR
HiJackThis Log file - On-line Analysis 2Ignore any 023 reference to avast processes, this is a hiccup in the HJT 1.99.1 (especially missing file entry for avast), if you need any help with any of the analysis let us know.
X-RayPc Spyware Remover Process Analyzer
http://www.x-raypc.com/