Help with a possible virus.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Jshep17, Sep 29, 2010.

  1. Jshep17

    Jshep17 Private E-2

    Okay so recently my family seems to be having some weird issues with their emails.

    Okay so it starts off with my brothers email account sending an email to my mother with out him knowing. I know what your thinking because I thought it too but its not a typical virus. Because my mothers soon did the same but here is whats interesting. The only people in her contacts list that were email were family members. This again happened with out my mother actually sending the emails her self.

    Then of course it started on other family members accounts again and kept spreading. So what kind of virus only targets the members of a contact list who are close family? Another thing was interesting was the original email from my brothers account had a link which I believe is infected (due to everyone deleting the email thus losing the link before I can scan it.) but the one sent by my mothers email account had no link. It was just plain text like you see in my post. It was copied and pasted from a yahoo article. It wasn't even advertisement it was just copied and pasted crap. I've asked several people about this and they say you can attach a virus on to copy and pasted text.

    If so how do I find out if this is what happened? If anyone knows what this is please tell me. I know hackforums isn't the place to really ask about how to detect or remove viruses, but considering this thing acts so strangely I figured this would be the best place to ask.

    I'd like to also state that the emails from my mothers account had no links or attachments no images or anything.
    The contents were two sentences copied and pasted from a yahoo article about the economy.
    I'm pretty sure they were some how able to deploy a virus because one of the people who received their email soon had the same issue.

    I've run malwarebytes, kaspersky, avast, and avg all on these computers and came up with nothing.

    And again there wasn't any thing else in the email but the two sentences.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Malware detected in email databases has to be cleaned up by you. You have a few choices:

    1. delete the whole file which is not an option you normally want to use
    2. load the email folder that contains the infection and delete ALL unnecessary emails (hoping to remove the problem email) and then use the Mailbox Cleanup option to delete all old emails. Then compact the Outlook database to permanently remove data. See http://support.microsoft.com/kb/291645 If you do not cleanup and compact the databases, the deleted emails may still be leaving hidden information in the database that you just cannot see but a scanner may still pickup on it.
    3. create a new folder and move only emails you really need into the new folder and then delete the infected folder.

    I would also add a contact: aaa@aaa.com. This sometimes works to thwart email spamming.
     
  3. Jshep17

    Jshep17 Private E-2

    It was done through yahoo email not outlook. Also I've already deleted the email but I don't know what kind of virus it is. I'm not sure if my computer is infected as well but I know others who did get infected by it.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  5. Jshep17

    Jshep17 Private E-2

    I'm trying to find out what type of virus this could be and what signatures to look for. Its infected over a dozen computers so I'm just trying to figure this out so I can help my family get their computers cleaned. I'm also concerned as to why a virus would only choose family contacts to spread its self too?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't have enough information to answer any of those questions. And the name of it is irrelevant as every anti-virus software will probably have their own term for it. You need to do the Read and Run First instructions and then attach the requested logs so I can see what is happening in your system.
     
  7. Jshep17

    Jshep17 Private E-2

    Okay here is the logs.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks like you didn't make the agreement to run HJT. I doubt it will show anything, but I would still like to see it. Just go to C:\MGTools\analyse.exe and run it. Attach that log. So far I am not seeing any malware.
     
  9. Jshep17

    Jshep17 Private E-2

    Okay here is the hijack log
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds