![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
I work at a high school teaching basic computer applications. Our schools computer tech (who I do not trust) came to me and informed me that this computer was sending out viruses through email even though email had never been set up on it. I have done all the steps in the "do this first thread". There were 5 hits in the panda scan that I will post along with the HJT. If I trusted the teach I would have him fix it but that would mean the computer would be out of my hands for about 6 months. With 36 kids a class and only 32 computers it is vital I get this one back online as soon as possible. Please help!
|
| Sponsored links |
|
|
|
#2
|
|||
|
|||
|
Sorry, the HJT log below was made whilein safe mode. The one attached to this message was made after a normal boot.
|
|
#3
|
||||
|
||||
|
You HJT log appears to be from safe mode. We require normal boot mode logs.
Did you run BitDefender? Did you save the log to attach it? Observations: 1) You antivirus program does not seem to be installed properly. Components that I would expect to see auto loading at run time do not exist. I only see two service entries for McAfee. Is it an old version? Something seems to be missing. 2) You do not appear to have a firewall installed. This is not a good idea. You log show no major problems other than above but a normal boot mode log may show otherwise. You can delete the one file Panda found below: C:\Documents and Settings\student\Local Settings\Temporary Internet Files\Content.IE5\43TVQ2ZP\mysearch_default_hplogo2[1].gif
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#4
|
||||
|
||||
|
Okay! In normal boot mode, more of the normal processes from McAfee seem to be running okay. So that application is probably fine.
I see no signs of any malware. We could did a little deeper (and look for a rootkit) but are you sure that students are not sending stuff out using this PC. How is the computer tech observing that this PC is emailing viruses? Is he looking at logs somewhere like in a hardware firewall or similar? Or is someone getting the email with viruses attached?
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#5
|
|||
|
|||
|
I deleted everything from the temporary internet files per the panda find.
Over the summer my lab was used by another teacher who did not monitor the students while they used/played with these computers. I have many with malware/spyware that I am getting to. I am positive they used their online email accounts to send/receive. The outlook express and the explorer email have never been set up however. The tech said he traced the senders ip address to this computers ip. I do not trust him but I took the computer offline when he told me this and am trying to get it cleaned. He did not inform me how the email was sent other than it was infecting other computers on the network (huge school district). Digging a little deeper is entirely up to you. Thanks for everything so far. |
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
Well IP addresses can be spoofed (faked) too.
Please follow the below steps...
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#7
|
|||
|
|||
|
I ran the program but I must have done something wrong. I attached the log but it was very short. I ran the program a 2nd time and it found nothing.
I am also experiencing an error on boot on occasion. Will write that down next time I see it. Some Web program is experiencing an error. Let me know what I did wrong so I can fix it and do it right. |
|
#8
|
|||
|
|||
|
The error I get upon boot is a problem with WebscanX. Microsoft says it is a problem with Mcafee.
|
|
#9
|
||||
|
||||
|
Quote:
Quote:
No root kits were found.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#10
|
|||
|
|||
|
Quote:
I really can't stand McAfee as its really hard to update and I am much more familiar with Avast. Too bad Avast is only free for home use. Any suggestions on a free antivirus application for business/school use? |
| Sponsored links |
|
|
|
#11
|
||||
|
||||
|
Quote:
Quote:
The only one I know of here on MGs is ClamAV I don't know anything about it.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#12
|
|||
|
|||
|
Thanks for everything!!!!!!
|
|
#13
|
||||
|
||||
|
You're welcome!
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
![]() |
| Thread Tools | |
| Display Modes | |
|
|