email returned notifications

Discussion in 'Malware Help (A Specialist Will Reply)' started by Wolfy450, Oct 30, 2012.

  1. Wolfy450

    Wolfy450 Private E-2

    I'm getting groups of email returned notifications in my outlook, I had 212 overnight even though I havent sent them. They have random email addresses. They appear as postmaster undeliverables or Mailer daemon notifications and all appear to have a file attached with something like an advert for viagra or similar.
    I have run the various processes under the malware removalcleaning instructions and have attached the logs. Thanks for any help.
     

    Attached Files:

  2. Wolfy450

    Wolfy450 Private E-2

    Guys I really need some help with this problem - I opened my outlook this morning and had another 22 of the notifications. Could someone please analyse the logs and let me know what I should do next
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not sure what is causing it, but let's start with this:

    Rescan with RogueKiller and have it fix this item:
    [RUN][SUSP PATH] HKLM\[...]\RunOnce : !BingBar ("C:\Documents and Settings\All Users\Application Data\Microsoft\BingBar\BBSvc\7.1.391.0oemBingBarSetup-Partner.EXE" /C:"BBSetup.exe cabLocation=.\BingBarPartnerConfig.cab ui=false ismu=2") -> FOUND

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Now use windows explorer to find and delete:
    C:\Documents and Settings\Martin C\Desktop\cryptocrack\CryptoCrack.exe ( as well as the PDF and Zip files)
    C:\WINDOWS\system32\gswdll32.dll
    C:\WINDOWS\system32\waytaexuw.exe

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the aboveto the registry. If you do not get a success message, it definitely did not work.

    Now tell me how things are running.
     
  4. Wolfy450

    Wolfy450 Private E-2

    Hi Tim, I did all as per your instructions, but couldnt locate the waytaexuw.exe file. The reg fix reported as successfully merged. I am attaching the log as per your request. I had got another 120 return notifications and another 20 whilst on this morning. I have restarted the laptop and will report on any progress in the next couple of hours. I see from another thread started that I'm not the only one to suffer this problem.
    Thanks for your help so far.
     

    Attached Files:

    • JRT.txt
      File size:
      5.6 KB
      Views:
      1
  5. Wolfy450

    Wolfy450 Private E-2

    Unfortunately, I'm still getting the returned email notifications - any further action I can take?:banghead
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use a different computer and change your password. Then go back to your email program and clean it out. There doesn't seem to be any malware on your system.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds