Malware - Spam being sent from my email. IP blocked. HELP

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Sweetkarma, Oct 22, 2014.

  1. Sweetkarma

    Sweetkarma Private E-2

    I went through the entirety step by step process of cleaning up my computer, but the ISP is still seeing unexplained activity coming from the IP. I have all the logs and am wondering if I should post here?

    Issue:

    It started with trying to FTP and upload items to the server, of which would time out saying there were too many connections.

    This was strange since it was only I, and I was only connecting once to then upload a few items and never seen this error before.

    I walked through your Malware Removal tutorial, cleaned the computer with Norton, and still am having FTP trouble.

    My email is routed to go into outlook and delete off the server, but I noticed my email box on the server still getting fuller. I logged in and see 2,500 messages of bounce backed messages from emails of course I didn't send. But these for some reason are not coming into my outlook but remaining on the server.

    what do I do next. Do I upload my logs here for someone to review?
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    May or may not be able to assist with this.
    Yes please, attach them, and if any malware is present and showing, we can remove it.
     
  3. Sweetkarma

    Sweetkarma Private E-2

    here are the logs
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi SweetKarma.

    Re run Hitman Pro and have it remove all that it finds.

    Do you have the log from Malware Bytes??

    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-1766003464-3297112040-2205141517-1001\Software\Microsoft\Internet Explorer\Main | Search Page : http://feed.helperbar.com-> Found
    • [PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-1766003464-3297112040-2205141517-1001\Software\Microsoft\Internet Explorer\Main | Search Page : http://feed.helperbar.com-> Found
    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.

    ...and the same for these entries on the Tasks tab please...

    • [Suspicious.Path] MySearchDial.job -- C:\Users\Tracy\AppData\Roaming\MYSEAR~1\UPDATE~1\UPDATE~1.EXE (/Check) -> Found
    • [Suspicious.Path] \\MySearchDial -- C:\Users\Tracy\AppData\Roaming\MYSEAR~1\UPDATE~1\UPDATE~1.EXE (/Check) -> Found

    ...Same for these on Web Browsers tab...

    • [PUP][FIREFX:Addon] xjh23c2s.default : We-Care Reminder [wecarereminder@bryan] -> Found
    • [PUM.HomePage][FIREFX:Config] xjh23c2s.default : user_pref("browser.startup.homepage", "http://feed.helperbar.com/?p=mKO_AwFzXIpYRa8ldwnKG51HJOT1XRoA82gVkoQAdOkQrprEHljji2GIt8fTAeqmM0uhWiC2cLksSSsADhn__WXMjLL8gdvtceKG5uyp-qWbugr-xf9HYh8EB85Mz2dcZJLEziYCsj8o3vfscjTRuYZUsSzpOBs-CjMge-u3TINLZ7uy8m3DWNBBG7yv-UDDU77VS85c"); -> Found
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.


    MGTools did not run to completion.

    Please click Start, Run, and enter cmd. cmd.exe will pop up, right click it and run as admin. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    • cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    • nwktst<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • GRK64 <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • SN64 <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.

    Attach the MGlogs.zip


    Re run RogueKiller and attach log.
    Same for Hitman.
     
  5. Sweetkarma

    Sweetkarma Private E-2

    here it is
     

    Attached Files:

  6. Sweetkarma

    Sweetkarma Private E-2

    Rogue Killer Logs
     

    Attached Files:

  7. Sweetkarma

    Sweetkarma Private E-2

    runkeys newfiles
     

    Attached Files:

  8. Sweetkarma

    Sweetkarma Private E-2

    MG logs zip
     

    Attached Files:

  9. Sweetkarma

    Sweetkarma Private E-2

    last logs
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you purposely set up to use a proxy? Hitman is showing that now where it wasn't before. If NOT, then re run Hitman and have it fix it. Then rescan and attach new log.
     
  11. Sweetkarma

    Sweetkarma Private E-2

    I guess I have no idea
    it showed up, inquired if I should fix, and I did?
     
  12. Sweetkarma

    Sweetkarma Private E-2

    no threats found.
    how do I stop it from using proxy server setting
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Reimage Repair <<< Uninstall this junk.

    Delete this if it remains:
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    The proxy no longer shows.

    How are things running?
     
  14. Sweetkarma

    Sweetkarma Private E-2

    everything seems to be fixed!! THANK YOU SO MUCH!!:)
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Excellent! :) You are most welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  16. Sweetkarma

    Sweetkarma Private E-2

    also this may not be necessary as it was the first thing I did and had problems after until following this forum, but it does show some info of what was on it before I ran Norton initially. not sure if you can open these or need them or not.
     
  17. Sweetkarma

    Sweetkarma Private E-2

    nevermind, guess they wont attach. .mcf files
    mentioned Trojan a few times though
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What are you trying to attach? A log from Norton? If so is it showing past alerts or is is alerting to something new?
     
  19. Sweetkarma

    Sweetkarma Private E-2

    all is good so no real need to attach anything. it was the first scan I ran which caught some things but only your awesome forum actually fixed it! I donated. THank you so much for all your help
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thanks for your donation, much appreciated! Glad to hear all is well. :)
     
  21. Sweetkarma

    Sweetkarma Private E-2

    ITs BAAAACKKK. I can not find ANYTHING on my computer but supposively my IP has been black listed again and there is unusual traffic from my computer. is there any website I can use to monitor this traffic or see it for myself? any suggestions?
     
  22. Sweetkarma

    Sweetkarma Private E-2

    ITs BAAAACKKK. I can not find ANYTHING on my computer but supposively my IP has been black listed again and there is unusual traffic from my computer. is there any website I can use to monitor this traffic or see it for myself? any suggestions? :confused
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then please begin a NEW thread in Malware Removal. Thanks. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds