Spam e-mail received not sure if infected

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by trisha, Jan 2, 2011.

  1. trisha

    trisha Corporal

    My friend sent me an e-mail yesterday that had an attachment of a video. I NEVER open things like that but unfortunately I did. Shortly after opening said e-mail I noticed she was sending me the same e-mail again. I logged onto my GMail account to see how many e-mails were on the site because the download from the server indicated I was received 825 mb and a total of 12 e-mails.

    I was able to delete the e-mails in GMail Inbox and reported it as spam. However, they still downloaded to my computer even though they no longer showed up in GMail.

    Anyway, she sent the same e-mail to 30 of her friends. She had no clue this was going to spam everyone until a friend called her to ask what the heck was going on and how can they stop it. Of course she called me then. :cry

    I am submitting the log files from Read and Run First.

    The only problem I encountered was with MG Tools. I ran the program several times, even disabled the antivirus. The program appeared to run but never deposited said MGLog.zip file in C drive. I saved the MGTools.exe file in C as directed. The point is I don't have a log for MGTools.

    I will be fixing my friend's computer later today. Please help. Thanks
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    So far I am not seeing any issues, but let's try to get MGTools to run.

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
     
  3. trisha

    trisha Corporal

    Hi Tim,

    Here are the log files produced by your instructions. I did not experience any error messages.

    Thanks for getting to my case so quickly. So, what could have caused the problem on my friend's end? Everyone she e-mailed received no less than 12 of the same e-mail. Someone mentioned it just keeps multiplying.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    She may have either opened a spam email that then went through her contacts list and started spamming her contacts. She needs to find the spam and remove it. You also should just delete any emails from her until this issue is sorted on her end.

    I am not seeing any problems in your files, but let's look at HJT to see what it reports. Please go to C:\MGTools\analyse.exe and run it. It will produce a log for you ( Do a system scan and save a log ). Attach that log to your next reply.
     
  5. trisha

    trisha Corporal

    So, what I am understanding from what you said is that the e-mail she forwarded to everyone that was duplicated is not necessarily the source of the infection.

    Here is the log for HJT
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Correct. At least I believe so in this case as your email program is not replicating the situation. Your logs are clean.

    I usually suggest that one adds a contact to their contacts list such as:

    aaa@aaa.com.


    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  7. trisha

    trisha Corporal

    Thanks for all of your help, Tim.

    I am off to see if I can fix my friend's computer woes. If I need to come back here and run scans and submit logs can I use this same thread or do I need to start a new thread?

    Just to be clear on the e-mail spam. The only people who received the duplicated e-mails are the ones she intended to receive the original e-mail. No one else has received the duplicates, that is no unintended recipients.

    I took your advice from last time re aaa@aaa.com. That is in all of my contacts lists.

    Once again, thanks for all of your help. Have a Happy New Year.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Start a new thread if you are working on a different computer. That way there is no chance of confusion.

    Happy New Years to you as well!!;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds