Check alle échte Black Friday-deals Ook zo moe van nepaanbiedingen? Wij laten alleen échte deals zien

Mailrelay

Pagina: 1
Acties:
  • 127 views sinds 30-01-2008
  • Reageer

  • DJ.KRIZZ
  • Registratie: Mei 2002
  • Laatst online: 21-10 12:51
Beste mensen,

Ik heb een probleempje onder Windows 2003. Sinds enige tijd loopt internet soms voor enkele minuten vast, terwijl er wel verbinding is (de ping bijvoorbeeld, loopt wel door). Ik heb van alles hersteld en en gescanned met diverse antivirusprogramma's en antispywaresoftware (MS Antispyware, Hitman Pro, Trend, Xoftspy enz.), maar het probleem blijft bestaan. Ik vermoed zelf dat het aan een email-smtp-relay virus ligt, getuige onderstaande log van m'n netstat:
TCP w2k3-krizz:3550 la3.digilink.net:smtp TIME_WAIT
TCP w2k3-krizz:3551 rmail-158.hanmail.net:smtp TIME_WAIT
TCP w2k3-krizz:3552 xl.mx.aol.com:smtp TIME_WAIT
TCP w2k3-krizz:3553 202.96.74.67:smtp TIME_WAIT
TCP w2k3-krizz:3555 www.epage.com:smtp TIME_WAIT
TCP w2k3-krizz:3558 mx-ha02.web.de:smtp TIME_WAIT
TCP w2k3-krizz:3560 na.mx.aol.com:smtp TIME_WAIT
TCP w2k3-krizz:3562 ya.mx.aol.com:smtp TIME_WAIT
TCP w2k3-krizz:3563 mx-ha01.web.de:smtp TIME_WAIT
TCP w2k3-krizz:3564 nc.mx.aol.com:smtp TIME_WAIT
TCP w2k3-krizz:3566 yb.mx.aol.com:smtp TIME_WAIT
TCP w2k3-krizz:3567 na.mx.aol.com:smtp TIME_WAIT
TCP w2k3-krizz:3569 mx-ha02.web.de:smtp TIME_WAIT
TCP w2k3-krizz:3571 rmail-216.hanmail.net:smtp TIME_WAIT
TCP w2k3-krizz:3572 mx-ha01.web.de:smtp TIME_WAIT
TCP w2k3-krizz:3573 mx-ha02.web.de:smtp TIME_WAIT
TCP w2k3-krizz:3574 nc.mx.aol.com:smtp TIME_WAIT
TCP w2k3-krizz:3576 mx-ha02.web.de:smtp TIME_WAIT
TCP w2k3-krizz:3577 xl.mx.aol.com:smtp TIME_WAIT
TCP w2k3-krizz:3578 xl.mx.aol.com:smtp TIME_WAIT
TCP w2k3-krizz:3579 mx-ha02.web.de:smtp TIME_WAIT
TCP w2k3-krizz:3581 mx-ha01.web.de:smtp TIME_WAIT
TCP w2k3-krizz:3582 mx-ha02.web.de:smtp TIME_WAIT
TCP w2k3-krizz:3584 xl.mx.aol.com:smtp TIME_WAIT
TCP w2k3-krizz:3586 mx-ha01.web.de:smtp TIME_WAIT
TCP w2k3-krizz:3587 xl.mx.aol.com:smtp TIME_WAIT
TCP w2k3-krizz:3589 mx-ha02.web.de:smtp TIME_WAIT
TCP w2k3-krizz:3592 mx-ha01.web.de:smtp TIME_WAIT
TCP w2k3-krizz:3594 dimail1.emirates.net.ae:smtp TIME_WAIT
TCP w2k3-krizz:3597 mail.novaone.net:smtp TIME_WAIT
TCP w2k3-krizz:3600 mx-ha02.web.de:smtp TIME_WAIT
TCP w2k3-krizz:3601 rmail-216.hanmail.net:smtp TIME_WAIT
TCP w2k3-krizz:3602 dimail2.emirates.net.ae:smtp TIME_WAIT
TCP w2k3-krizz:3604 mx-ha01.web.de:smtp TIME_WAIT
TCP w2k3-krizz:3605 mx1.daemonmail.net:smtp TIME_WAIT
TCP w2k3-krizz:3606 mx-ha01.web.de:smtp TIME_WAIT
TCP w2k3-krizz:3608 dimail3.emirates.net.ae:smtp TIME_WAIT
TCP w2k3-krizz:3609 mx2.bund.de:smtp TIME_WAIT
TCP w2k3-krizz:3611 mx2.daemonmail.net:smtp TIME_WAIT
TCP w2k3-krizz:3615 mailin.webmailer.de:smtp TIME_WAIT
TCP w2k3-krizz:3616 mx4.daemonmail.net:smtp TIME_WAIT
TCP w2k3-krizz:3618 mx3.daemonmail.net:smtp TIME_WAIT
TCP w2k3-krizz:3632 mta-v6.mail.yahoo.com:smtp TIME_WAIT
TCP w2k3-krizz:3634 xl.mx.aol.com:smtp TIME_WAIT
TCP w2k3-krizz:3642 baym-sb164.msgr.hotmail.com:1863 ESTABLISHED
TCP w2k3-krizz:3645 65.54.194.118:http ESTABLISHED
TCP w2k3-krizz:3646 65.54.194.118:http ESTABLISHED
TCP w2k3-krizz:3647 65.54.194.118:http ESTABLISHED
TCP w2k3-krizz:3648 65.54.194.118:http ESTABLISHED
TCP w2k3-krizz:3649 65.54.194.118:http ESTABLISHED
TCP w2k3-krizz:3653 mx.terra.es:smtp TIME_WAIT
TCP w2k3-krizz:3665 usermail.freecity.de:smtp TIME_WAIT
TCP w2k3-krizz:3666 200.175.8.148:smtp FIN_WAIT_2
TCP w2k3-krizz:3668 mailin.webmailer.de:smtp TIME_WAIT
TCP w2k3-krizz:3672 ns1.mkd.de:smtp TIME_WAIT
TCP w2k3-krizz:3673 zelator.berlinet.de:smtp TIME_WAIT
TCP w2k3-krizz:3674 ns1.mkd.de:smtp TIME_WAIT
TCP w2k3-krizz:3677 xwing.aoltw.net:smtp TIME_WAIT
TCP w2k3-krizz:3678 imsmx08.netvigator.com:smtp TIME_WAIT
TCP w2k3-krizz:3679 dd6816.kasserver.com:smtp TIME_WAIT
TCP w2k3-krizz:3681 filter1.amigo.net:smtp TIME_WAIT
TCP w2k3-krizz:3682 fltr-in2.mail.dreamhost.com:smtp ESTABLISHED
TCP w2k3-krizz:3684 mail.reynoldswebsolutions.com:smtp TIME_WAIT
TCP w2k3-krizz:3685 mailwash27.pair.com:smtp TIME_WAIT
TCP w2k3-krizz:3689 mx2.ozu.es:smtp TIME_WAIT
TCP w2k3-krizz:3690 ns2.mkd.de:smtp TIME_WAIT
TCP w2k3-krizz:3691 ns2.mkd.de:smtp TIME_WAIT
TCP w2k3-krizz:3692 mailserv.fh-hannover.de:smtp TIME_WAIT
TCP w2k3-krizz:3697 mailrelay.grics.net:smtp TIME_WAIT
TCP w2k3-krizz:3698 mx2-1.vip.spray.net:smtp TIME_WAIT
TCP w2k3-krizz:3699 imsmx09.netvigator.com:smtp TIME_WAIT
TCP w2k3-krizz:3700 mail-mx-4.tiscali.it:smtp FIN_WAIT_2
TCP w2k3-krizz:3701 mx-ha02.web.de:smtp TIME_WAIT
TCP w2k3-krizz:3703 mx2.worldonline.co.za:smtp TIME_WAIT
TCP w2k3-krizz:3704 smtp.ee.ethz.ch:smtp TIME_WAIT
TCP w2k3-krizz:3706 mail.she.com:smtp TIME_WAIT
TCP w2k3-krizz:3707 mailin.webmailer.de:smtp TIME_WAIT
TCP w2k3-krizz:3708 mx-ha01.web.de:smtp TIME_WAIT
TCP w2k3-krizz:3710 mx-b.kundenserver.de:smtp TIME_WAIT
TCP w2k3-krizz:3711 two.mx.123-reg.co.uk:smtp FIN_WAIT_2
TCP w2k3-krizz:3712 mailin.webmailer.de:smtp TIME_WAIT
TCP w2k3-krizz:3714 mta-v20.level3.mail.yahoo.com:smtp SYN_SENT
TCP w2k3-krizz:3715 mxes14.enta.net:smtp TIME_WAIT
TCP w2k3-krizz:3717 imsmx10.netvigator.com:smtp TIME_WAIT
TCP w2k3-krizz:3718 135-53.125-70.tampabay.res.rr.com:smtp TIME_WA
T
TCP w2k3-krizz:3719 s82.n51.vds2000.com:smtp TIME_WAIT
TCP w2k3-krizz:3721 mta-v6.level3.mail.vip.mud.yahoo.com:smtp SYN_
ENT
TCP w2k3-krizz:3722 zebra.esosoft.net:smtp FIN_WAIT_2
TCP w2k3-krizz:3723 mailin.webmailer.de:smtp TIME_WAIT
TCP w2k3-krizz:3724 mxes18.enta.net:smtp TIME_WAIT
TCP w2k3-krizz:3725 mx12.ispgateway.de:smtp TIME_WAIT
TCP w2k3-krizz:3726 mailin.webmailer.de:smtp TIME_WAIT
TCP w2k3-krizz:3727 academy.he.net:smtp TIME_WAIT
TCP w2k3-krizz:3728 mail.hivelocity.net:smtp TIME_WAIT
TCP w2k3-krizz:3730 mx1-1.vip.spray.net:smtp TIME_WAIT
TCP w2k3-krizz:3731 Pumba.CGL.COM:smtp TIME_WAIT
TCP w2k3-krizz:3732 virtual.Register1.net:smtp TIME_WAIT
TCP w2k3-krizz:3733 imsmx11.netvigator.com:smtp TIME_WAIT
TCP w2k3-krizz:3735 mailin.webmailer.de:smtp TIME_WAIT
TCP w2k3-krizz:3736 mx-b.kundenserver.de:smtp TIME_WAIT
TCP w2k3-krizz:3737 mail01.tro.net:smtp TIME_WAIT
TCP w2k3-krizz:3738 dtiexchange2.digitaris.com:smtp TIME_WAIT
TCP w2k3-krizz:3739 kittys-family-board.de:smtp TIME_WAIT
TCP w2k3-krizz:3740 mailin.webmailer.de:smtp TIME_WAIT
TCP w2k3-krizz:3741 mx12.ispgateway.de:smtp TIME_WAIT
TCP w2k3-krizz:3742 mail.netbeat.de:smtp TIME_WAIT
TCP w2k3-krizz:3743 mx-b.kundenserver.de:smtp TIME_WAIT
TCP w2k3-krizz:3744 eispost5.serverdienst.de:smtp TIME_WAIT
TCP w2k3-krizz:3747 smtpin.livemail.co.uk:smtp TIME_WAIT
TCP w2k3-krizz:3748 mx.promo.it:smtp TIME_WAIT
TCP w2k3-krizz:3749 imsmx03.netvigator.com:smtp TIME_WAIT
TCP w2k3-krizz:3750 two.mx.123-reg.co.uk:smtp ESTABLISHED
TCP w2k3-krizz:3751 mx-b.kundenserver.de:smtp TIME_WAIT
TCP w2k3-krizz:3752 mx2.abac.com:smtp TIME_WAIT
TCP w2k3-krizz:3753 mail56.messagelabs.com:smtp ESTABLISHED
TCP w2k3-krizz:3755 ip621322547.mundivia.es:smtp TIME_WAIT
TCP w2k3-krizz:3756 mail02.myhosting.com:smtp TIME_WAIT
TCP w2k3-krizz:3757 mail2.es.34web.net:smtp TIME_WAIT
TCP w2k3-krizz:3759 master.igc.org:smtp ESTABLISHED
TCP w2k3-krizz:3760 h-66-134-207-44.snvacaid.covad.net:smtp TIME_W
IT
TCP w2k3-krizz:3761 ns1.develtop.net:smtp TIME_WAIT
TCP w2k3-krizz:3762 curry.kd-menue.de:smtp TIME_WAIT
TCP w2k3-krizz:3763 PorkyPig.cgl.net:smtp TIME_WAIT
TCP w2k3-krizz:3767 mxes18.enta.net:smtp TIME_WAIT
TCP w2k3-krizz:3768 imsmx04.netvigator.com:smtp TIME_WAIT
TCP w2k3-krizz:3769 iwhome.com:smtp TIME_WAIT
TCP w2k3-krizz:3770 67.105.80.231.ptr.us.xo.net:smtp TIME_WAIT
TCP w2k3-krizz:3771 mxes14.enta.net:smtp TIME_WAIT
TCP w2k3-krizz:3772 white-2.inmx.everyone.net:smtp TIME_WAIT
TCP w2k3-krizz:3773 mail-mx-4.tiscali.it:smtp ESTABLISHED
TCP w2k3-krizz:3774 mail-fwd.verio.de:smtp ESTABLISHED
TCP w2k3-krizz:3775 mailin.webmailer.de:smtp TIME_WAIT
TCP w2k3-krizz:3776 two.mx.123-reg.co.uk:smtp ESTABLISHED
TCP w2k3-krizz:3777 yoho.com:smtp TIME_WAIT
TCP w2k3-krizz:3780 67.109.66.230.ptr.us.xo.net:smtp TIME_WAIT
TCP w2k3-krizz:3782 imsmx05.netvigator.com:smtp TIME_WAIT
TCP w2k3-krizz:3787 mailin.webmailer.de:smtp TIME_WAIT
TCP w2k3-krizz:3788 mail3.webtapestry.net:smtp SYN_SENT
TCP w2k3-krizz:3791 mx-b.kundenserver.de:smtp TIME_WAIT
TCP w2k3-krizz:3794 lon1-hub.mail.demon.net:smtp ESTABLISHED
TCP w2k3-krizz:3799 mendedheart.com:smtp FIN_WAIT_1
TCP w2k3-krizz:3800 mailin.webmailer.de:smtp FIN_WAIT_1
TCP w2k3-krizz:3801 mail.playtechgaming.com:smtp ESTABLISHED
TCP w2k3-krizz:3802 mailhosting.gravityfree.com:smtp FIN_WAIT_1
TCP w2k3-krizz:3803 imsmx06.netvigator.com:smtp ESTABLISHED
TCP w2k3-krizz:3806 mx2.evanzo-server.de:smtp ESTABLISHED
TCP w2k3-krizz:3807 mx01.ispgateway.de:smtp SYN_SENT
TCP w2k3-krizz:3808 mx6.daemonmail.net:smtp SYN_SENT
En de lijst is nog veel langer...

Ik gebruik trouwens geen Outlook/Exchange maar enkel Thunderbird i.c.m. SSL-smtp. Verder zijn er geen verbindingen te zien wanneer de firewall aanstaat, maar ik wil zo graag dit probleem bij de bron oplossen. Iemand een idee?

You've got to try it to love it


  • F_J_K
  • Registratie: Juni 2001
  • Niet online

F_J_K

Moderator CSA/PB

Front verplichte underscores

Inderdaad is er vieze malware bezig. Kijk beter (met een betere virusscanner, en met de hand zoals in de "sticky" topics bovenaan BV) wat er allemaal draait. Kijk met iets als Portmon van Sysinternals welk proces de zooi loopt te versturen en biedt die executable aan aan een online virusscanner zoals bijv. Jotti's of Kaspersky's. Dan weet je meer over wat het is en kan je verder kijken naar hoe het op te lossen.

Als je nog niets vindt: zorg dat je backup uptodate is, formatteer, herinstalleer en patch+beveilig beter :)

'Multiple exclamation marks,' he went on, shaking his head, 'are a sure sign of a diseased mind' (Terry Pratchett, Eric)


Verwijderd

heb je wel een sterk password op je admin account staan? Als dat bijvoorbeeld password of wachtwoord is (of iets anders dat zeer makkelijk te achterhalen is) kan men authenticated relay doen via je server....

  • McMiGHtY
  • Registratie: December 1999
  • Laatst online: 29-11 18:08

McMiGHtY

- burp -

Wat je zou kunnen doen is poort 25 dicht gooien op je router of middels IPSEC. Op deze manier ben je "dicht" qua SMTP gebeuren.

NEW - Het Grote - 2025 Tweakers Social Ride- Topic!