E-mails being sent from Outlook Express.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by nickpforster, Feb 26, 2007.

  1. nickpforster

    nickpforster Private E-2

    In the last few weeks my Outlook Express POP account has been sending out rubbish messages from non existant account names from my address. Consequently I get a lot of returned messages 'Not able to deliver message to this address' etc every day. The account names are, for example, 'abc@nickforsterltd.freeserve.co.uk' or 'xyz@nickforsterltd.freeserve.co.uk' etc.

    I have 'read & run me first' from your sheet and attach the logs. I was unable to run 'Counterspy' so used AVG Antispyware. Could not run either 'Bitdefender' or 'PandaActiveScan'

    I am on 'dial up'
    There will be an additional post as I have 4 files to upload.
    Have you any ideas?

    Regards Nick
     

    Attached Files:

  2. nickpforster

    nickpforster Private E-2

    E Mails being sent from Outlook Express

    Futher to my last post attached is HijackThis log

    Regards Nick
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: E Mails being sent from Outlook Express

    Welcome to Majorgeeks!

    Please remember to stay in one thread for your current problem!

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: ToolHelper - {CDEEC43D-3572-4E95-A2A5-F519D29F00C0} - C:\PROGRA~1\ADVANC~1\Toolbar.dll (file missing)
    O4 - HKLM\..\Run: [websx] C:\Program Files\websx\int310659.exe -auto
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
    O16 - DPF: {7589EEE6-E336-11D4-8A7E-EE1D971D9B47} - http://secure.aconti.net/acontix/goodthinxx.cab

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\websx <--- the whole folder:

    Now run Ccleaner

    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.
    1. ShowNew
    2. HJT


    Make sure you tell me how things are working now!
     
  4. nickpforster

    nickpforster Private E-2

    Thanks for your reply. I ran HijackThis, selected the required lines. Fixed and exited. Went into safe mode, but folder c:\Progran Files\websx did not seem to exist. Ran CCleaner and then ran HijackThis again & getnew.bat. Attached are logs.

    I probably wont know for a couple of days if this has stopped Outlook Express messages. Will let you know.

    Regards Nick
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your current logs, you are clean! Do you need the below proxy server setting?


    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=http://www-cache.freeserve.com:8080;http=http://www-cache.freeserve.com:8080


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  6. nickpforster

    nickpforster Private E-2

    Many Thanks. It all seems to be OK now.

    Regards Nick
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds