MajorGeeks Support Forums

Go Back   MajorGeeks Support Forums > ----------= PC, Desktop and Laptop Support =---------- > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.


Reply
 
Thread Tools Display Modes
  #1  
Old 01-30-06, 14:05
ppreheim ppreheim is offline
Senior Member
 
Join Date: Dec 2004
Posts: 119
Thanks: 14
Thanked 0 Times in 0 Posts
Default My computer is sending out email viruses?

I work at a high school teaching basic computer applications. Our schools computer tech (who I do not trust) came to me and informed me that this computer was sending out viruses through email even though email had never been set up on it. I have done all the steps in the "do this first thread". There were 5 hits in the panda scan that I will post along with the HJT. If I trusted the teach I would have him fix it but that would mean the computer would be out of my hands for about 6 months. With 36 kids a class and only 32 computers it is vital I get this one back online as soon as possible. Please help!
Attached Files
File Type: txt Activescan.txt (2.2 KB, 3 views)
File Type: log hijackthis13006.log (3.7 KB, 3 views)
Reply With Quote
Sponsored links
  #2  
Old 01-30-06, 14:11
ppreheim ppreheim is offline
Senior Member
 
Join Date: Dec 2004
Posts: 119
Thanks: 14
Thanked 0 Times in 0 Posts
Default Re: My computer is sending out email viruses?

Sorry, the HJT log below was made whilein safe mode. The one attached to this message was made after a normal boot.
Attached Files
File Type: log hijackthis.log (5.1 KB, 1 views)
Reply With Quote
  #3  
Old 01-30-06, 14:20
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,442
Thanks: 62
Thanked 7,688 Times in 4,147 Posts
Default Re: My computer is sending out email viruses?

You HJT log appears to be from safe mode. We require normal boot mode logs.

Did you run BitDefender? Did you save the log to attach it?

Observations:
1) You antivirus program does not seem to be installed properly. Components that I would expect to see auto loading at run time do not exist. I only see two service entries for McAfee. Is it an old version? Something seems to be missing.

2) You do not appear to have a firewall installed. This is not a good idea.

You log show no major problems other than above but a normal boot mode log may show otherwise.

You can delete the one file Panda found below:

C:\Documents and Settings\student\Local Settings\Temporary Internet Files\Content.IE5\43TVQ2ZP\mysearch_default_hplogo2[1].gif
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
Reply With Quote
  #4  
Old 01-30-06, 14:30
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,442
Thanks: 62
Thanked 7,688 Times in 4,147 Posts
Default Re: My computer is sending out email viruses?

Okay! In normal boot mode, more of the normal processes from McAfee seem to be running okay. So that application is probably fine.

I see no signs of any malware. We could did a little deeper (and look for a rootkit) but are you sure that students are not sending stuff out using this PC. How is the computer tech observing that this PC is emailing viruses? Is he looking at logs somewhere like in a hardware firewall or similar? Or is someone getting the email with viruses attached?
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
Reply With Quote
  #5  
Old 01-30-06, 14:39
ppreheim ppreheim is offline
Senior Member
 
Join Date: Dec 2004
Posts: 119
Thanks: 14
Thanked 0 Times in 0 Posts
Default Re: My computer is sending out email viruses?

I deleted everything from the temporary internet files per the panda find.

Over the summer my lab was used by another teacher who did not monitor the students while they used/played with these computers. I have many with malware/spyware that I am getting to. I am positive they used their online email accounts to send/receive. The outlook express and the explorer email have never been set up however. The tech said he traced the senders ip address to this computers ip. I do not trust him but I took the computer offline when he told me this and am trying to get it cleaned. He did not inform me how the email was sent other than it was infecting other computers on the network (huge school district).

Digging a little deeper is entirely up to you. Thanks for everything so far.
Reply With Quote
Sponsored links
  #6  
Old 01-30-06, 15:04
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,442
Thanks: 62
Thanked 7,688 Times in 4,147 Posts
Default Re: My computer is sending out email viruses?

Well IP addresses can be spoofed (faked) too.

Please follow the below steps...
  1. Please download and unzip Rootkit Revealer to your desktop.
  2. Please leave the defaults set as they are to:
    • Hide NTFS Metadata Files: this option is on by default
    • Scan Registry: this option is on by default.
  3. Launch rootkit revealer on the system and press the Scan button.
  4. RootkitRevealer scans the system reporting its actions in a status area at the bottom of its window and noting discrepancies in the output list. It may take a long time please disconnect from the internet and leave the PC to be scanned until it is finished.
  5. The log can be very large please edit out the items in the following folders in the log : C:\System Volume Information, if in the log, before posting it.
  6. Please attach the the log here in this thread to your next post.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
Reply With Quote
  #7  
Old 01-30-06, 15:37
ppreheim ppreheim is offline
Senior Member
 
Join Date: Dec 2004
Posts: 119
Thanks: 14
Thanked 0 Times in 0 Posts
Default Re: My computer is sending out email viruses?

I ran the program but I must have done something wrong. I attached the log but it was very short. I ran the program a 2nd time and it found nothing.

I am also experiencing an error on boot on occasion. Will write that down next time I see it. Some Web program is experiencing an error.

Let me know what I did wrong so I can fix it and do it right.
Attached Files
File Type: txt RootkitReveal.txt (142 Bytes, 2 views)
Reply With Quote
  #8  
Old 01-30-06, 15:43
ppreheim ppreheim is offline
Senior Member
 
Join Date: Dec 2004
Posts: 119
Thanks: 14
Thanked 0 Times in 0 Posts
Default Re: My computer is sending out email viruses?

The error I get upon boot is a problem with WebscanX. Microsoft says it is a problem with Mcafee.
Reply With Quote
  #9  
Old 01-30-06, 16:42
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,442
Thanks: 62
Thanked 7,688 Times in 4,147 Posts
Default Re: My computer is sending out email viruses?

Quote:
Originally Posted by ppreheim
The error I get upon boot is a problem with WebscanX. Microsoft says it is a problem with Mcafee.
Remember earlier I did say:
Quote:
Observations:
1) You antivirus program does not seem to be installed properly. Components that I would expect to see auto loading at run time do not exist. I only see two service entries for McAfee. Is it an old version? Something seems to be missing.
WebscanX is part of McAfee. It handles the security scan for web related applications such as e-mails, file-downloads, and web applets ( Java/ActiveX ). So perhaps my first observation was correct and you are missing some required component from McAfee. You may need to uninstall McAfee, reboot, then reinstall and then re-update.

No root kits were found.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
Reply With Quote
  #10  
Old 01-30-06, 17:09
ppreheim ppreheim is offline
Senior Member
 
Join Date: Dec 2004
Posts: 119
Thanks: 14
Thanked 0 Times in 0 Posts
Default Re: My computer is sending out email viruses?

Quote:
Originally Posted by chaslang
No root kits were found.
Is that a good thing? I am hoping it is, lol.


I really can't stand McAfee as its really hard to update and I am much more familiar with Avast. Too bad Avast is only free for home use. Any suggestions on a free antivirus application for business/school use?
Reply With Quote
Sponsored links
  #11  
Old 01-30-06, 17:50
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,442
Thanks: 62
Thanked 7,688 Times in 4,147 Posts
Default Re: My computer is sending out email viruses?

Quote:
Originally Posted by ppreheim
Is that a good thing? I am hoping it is, lol.
Yes it was a good thing.

Quote:
Originally Posted by ppreheim
I really can't stand McAfee as its really hard to update and I am much more familiar with Avast. Too bad Avast is only free for home use. Any suggestions on a free antivirus application for business/school use?
There are not too many of them around and they may not give you full coverage (like scanning emails, files etc).

The only one I know of here on MGs is ClamAV I don't know anything about it.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
Reply With Quote
  #12  
Old 01-31-06, 10:16
ppreheim ppreheim is offline
Senior Member
 
Join Date: Dec 2004
Posts: 119
Thanks: 14
Thanked 0 Times in 0 Posts
Default Re: My computer is sending out email viruses?

Thanks for everything!!!!!!
Reply With Quote
  #13  
Old 01-31-06, 13:21
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,442
Thanks: 62
Thanked 7,688 Times in 4,147 Posts
Default Re: My computer is sending out email viruses?

You're welcome!
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 14:44.

MajorGeeks.Com Menu

MajorGeeks.Com \ All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ NEW! PC Games \ System Tools \ Macintosh \ Demonews.Com \ Top Downloads

MajorGeeks.Com \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds


All content Copyright MajorGeeks.com source code Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger