Trojan Appears To Be Sending Email From My Account - Can't Find Trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by Lydster, Jan 11, 2018.

  1. Lydster

    Lydster Private First Class

    Hi. I've followed the instructions in READ ME FIRST, and logs are attached. Here's a run-down of my issue:

    About a week ago, my computer kept freezing, especially in Outlook. I suspected a virus, so I ran a few scans, and MBAM found one; I believe it was a trojan. Unfortunately, in a hurry at the time, I didn't take note of which virus it was; I just used MBAM to get rid of it. (I shortly thereafter uninstalled MBAM with REVO, so all the old logs are gone, I'm pretty sure, so I can't go back and see what it was.)

    After MBAM removal at that time, my computer went back to normal, and all seemed fine. Now it's been about a week, and I'm getting bounce-back email messages, as replies from emails being sent from my account. I can tell from the header on the original messages that this appears not to be spoofing - the header shows that the emails are actually sending from my email account using my "Authenticated ID." So I believe my email account must be compromised.

    To troubleshoot: I signed directly into the email server and changed my password (and updated Outlook to match). The bounce-backs stopped for about an hour; but then they started up again. So, it seems that the trojan somehow obtained the new password that I had just changed earlier today. Trying to determine if the password is being captured from the email server itself or if there's something on my computer that is able to capture the password when I visit the site on my computer, I turned off Outlook "Send" (not Receive) to see if bounce-backs stopped. Bounce-backs have stopped. which seems to indicate that the problem is on my computer, not out at the email server website.

    I've run all the scans, and the logs are attached.** From what I saw of the logs, the only thing that the scans seemed to think was a trojan is PSTPassword. That is a program from NirSoft that I downloaded years ago when I couldn't remember a PWD I put on a PST. It worked for me, and I don't think it's actually malware.

    **NOTE ON MGLOG ZIP FILE: Since I'm only able to attach 5 files, I added a PDF to the MGlogsR zip file which shows the 2 error messages I received. I hope this isn't a problem.

    Thanks in advance for your help. I've dealt with viruses before, but this one's got me worried...
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. I can only suggest you use a different computer to change your password.

    In addition:
    Malware detected in email databases has to be cleaned up by you. You have a few choices:

    1. delete the whole file which is not an option you normally want to use
    2. load the email folder that contains the infection and delete ALL unnecessary emails (hoping to remove the problem email) and then use the Mailbox Cleanup option to delete all old emails. Then compact the Outlook database to permanently remove data. See http://support.microsoft.com/kb/291645 If you do not cleanup and compact the databases, the deleted emails may still be leaving hidden information in the database that you just cannot see but a scanner may still pickup on it.
    3. create a new folder and move only emails you really need into the new folder and then delete the infected folder.
     
  3. Lydster

    Lydster Private First Class

    UPDATE: I just received a message from Windows Defender that it located TrojanDownloader:O97M/Donoff. See snip attached. WD quarantined it and recommended removal, so I clicked REMOVE button. A subsequent WD quick scan shows no threats now.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would still suggest you change your password using a different computer. Let me know if your issues continue or return.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds