Hijacked Email account? and Slowness...

Discussion in 'Malware Help (A Specialist Will Reply)' started by kev6873, Jul 21, 2010.

  1. kev6873

    kev6873 Private E-2

    Thinking I may have malware since my AOL account was used to send out malicious link to all my contacts within my account. I have also noticed the pc is very very slow and getting some popus infrequently. Any help would be greatly appreciated. Please see attachments.

    Also, how do turn the defogger back on? do i need to? Anything else (besides firewall, AV, etc) that I need to renable or turn back on or edit?

    Thanks again.
     

    Attached Files:

  2. kev6873

    kev6873 Private E-2

    And here is the remaining log. Thank you.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. The issue of slowness could be quite a number of factors. This is something you might want to pursue in the software forum.

    As to your email account:

    As a general rule, malware detected in your emails needs to be removed by you.

    1. delete the whole file which is not an option you normally want to use
    2. load the email folder that contains the infection and delete ALL unnecessary emails (hoping to remove the problem email) and then use the Mailbox Cleanup option to delete all old emails. Then compact the Outlook database to permanently remove data. See http://support.microsoft.com/kb/196990 If you do not cleanup and compact the databases, the deleted emails may still be leaving hidden information in the database that you just cannot see but a scanner may still pickup on it.
    3. create a new folder and move only emails you really need into the new folder and then delete the infected folder.

    For online accounts, this is a good example of cleaning for a hotmail account:
    http://blogs.msdn.com/b/securitytipstalk/archive/2010/07/07/hotmail-hacked-take-these-steps.aspx


    Since you are not having any malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     
  4. kev6873

    kev6873 Private E-2

    Thank you, Tim. Good news all in all. Im guessing ill need more memory or something. Thanks again for reviewing.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your memory looks adequate, but you may just need to defrag the system. Also be aware that McAfee will slow you down also.
     
  6. kev6873

    kev6873 Private E-2

    Tim, quick question. I tried to uninstall Combofix using your directions, but when i click ok, instead of unistalling, it appears as though it is trying to run a scan. Any thoughts?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It should have worked. You can always just right click it and choose delete. Then do a search for your C:\ComboFix.txt and delete it as well.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds