Archive for 14th August 2008

Can you say “SpamBot?”


So today I was working on this lady’s virus laden computer.  I thought it was clean.  Until I suddenly realized that it was making a massive number of connections to port 25 on random IP addresses all over the globe.  Check out this nestat:

Spam Bots

Spam Bots

All of this to say…  this is why a “flatten and restore” aproach to virus removal is ALWAYS the best.  I thought it was clean.  It ran clean, it “felt” clean - anyone who has spent over 40 hours in their life removing computer viruses will know what that means.  BUT IT WASN’T CLEAN.  So, if in doubt, or even if not in doubt, reformat.

Best Wishes,

Luke