PC was sending SPAM - Did I get everything off?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by logger, Jan 10, 2007.

  1. logger

    logger Private E-2

    Hi,

    On December 22, this machine began sending spam. The user remembers going to a suspect site....

    I tried to clean all the stuff off, over the next few days, and it seemed to be okay. But yesterday, it started sending spam again.

    The way I knew it was sending spam is that 10-20 Symantec windows checking the outbound mail popped up with strange titles (mostly about prescription meds) and email addresses.

    I have run through all the steps in the "READ and RUN ME FIRST" and I have noticed that there are still some issues.

    Step 0.
    Nothing to remove via add/remove as I didn't see any of those items listed.

    Step 1.
    Didn't find an nprotect folder, but deleted what was quarantined (corporate norton, SBS version)
    Was unable to log in to some user accounts to run CCleaner as the user accounts no longer exist. (Jenny Brown)

    Step 4.
    Spybot found Smitfraud.C
    Counterspy didn't find anything (although it found something the first time I used it, before following all the steps prescribed here. both results are posted in the txt file.)

    Step 5.
    Bitdefender seemed to find and delete stuff.
    PandaScan deemed to find issues but not do anything.

    Getrunkey, shownew, and HJT files will be added in second post.

    Thanks for your help.
     

    Attached Files:

  2. logger

    logger Private E-2

    Additional files attached.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    First an important warning!

    IMPORTANT NOTE: You had been infected with a Password Stealing Trojan: Trojan.W32.Torpig

    See this links for what you had!: http://www.liutilities.com/products/wintaskspro/processlibrary/ibm00001/

    Yes CounterSpy removed it, but you need to determine if any of your private information has been stolen.

    You must take this possible threat seriously especially if you use this PC for anything financial related (even on line purchasing).

    You are strongly advised to do the following immediately:
    1. Disconnect infected computer from the internet and from any networked computers until the computer can be cleaned. If you have network compters, start checking them for problems too.
    2. Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
    3. From a clean computer, change *all* your online passwords -- for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
    Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passords and transaction information.

    ===============================

    Okay now onto your remaining issues which are very few!

    Did you configure your PC to bypass the Windows Welcome Screen?


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 9
    Java 2 Runtime Environment, SE v1.4.2_06
    Mozilla Firefox (1.5.0.6)

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox


    Now attach a new log from GetRunKey.

    Are you having any other malware problems?
     
  4. logger

    logger Private E-2

    Not that I am aware of. Is this an issue?


    Done

    None that I've notice although this machine is somewhat of a spare so I haven't used it until we're sure there's nothing wrong with it.

    Thanks so much again for your help.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well it is less of an issue if you did it versus malware doing it. Some people don't want the Welcome Screen, but this is a less secure way to use the PC. Right now it seems to be disabled. You decide what you want to do. If you want to enable the welcome screen, continue with the below.


    Now Copy the bold text below to notepad. Save it as EnableWS.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    If you later decide you want to disable the welcome screen Copy the bold text below to notepad. Save it as DisableWS.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    You log was clean! If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds