AVG autopop3 email??

Discussion in 'Malware Help (A Specialist Will Reply)' started by retartedazn, Dec 23, 2007.

  1. retartedazn

    retartedazn Private E-2

    hi, im pretty bad with computers so sorry if i skipped something.

    I'm currently using AVG Anti Virus and just until recently, there were some popups on my screen that said it tried to connect to some ip(it changes every time)

    someone suggested me to use hijackthis and post it here so yeah.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please uninstall HJT as it will be properly installed when you do the following:

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. retartedazn

    retartedazn Private E-2

    ok, i think i've followed the instructions and did them all. then i ran hijack this again
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the instructions Tim gave to you. No place in those instructions was a HijackThis log requested.
     
  5. retartedazn

    retartedazn Private E-2

    OH sorry, i did not see the cleaning procedure link :S
    but, here ya go, hope i did it right this time :)
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'm not seeing anything in your logs to suggest malware ....what exactly did the pop ups say? Are you sure it wasn't AVG checking your mail as it downloads for viruses?
     
  7. retartedazn

    retartedazn Private E-2

    it couldn't have been checking my email because i don't use outlook and my browser was not open either. i looked at my avg emc.log and it showed something like this

    23.12.2007 03:11:33 AutoPOP3(10110): Connection from process 488
    23.12.2007 03:11:33 AutoPOP3(10110): Connection from 127.0.0.1:2323

    and that part just repeats over and over except for 127.0.0.1:xxxx which keeps changing then it says

    23.12.2007 03:14:17 AutoPOP3(10110): Cannot connect to 79-67-2-68.dynamic.dsl.as9105.com:110
    23.12.2007 03:14:17 AutoPOP3(10110): Cannot connect to 79-67-2-68.dynamic.dsl.as9105.com:110

    in the popup it kept saying connection to that dynamic dsl thing but my ISP is not dsl. i dunno if its relevant, but its been happening recently when i use bittornado, but i've been using that for months and i've never gotten this problem before
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is the ip address:
    Tiscali UK

    http://www.tiscali.com

    Are you familiar with it? Perhaps you need to install a firewall.
     
  9. retartedazn

    retartedazn Private E-2

    hrm..never heard of it. do you know any good free firewalls to download?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    He already has one:

    O4 - HKLM\..\Run: [OnlineArmor GUI] "C:\Program Files\Online Armor\oaui.exe"


    Tiscali in an ISP.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds