Viagra Emails being sent to address book

Discussion in 'Malware Help (A Specialist Will Reply)' started by janner66, Oct 6, 2010.

  1. janner66

    janner66 Private E-2

    I have been having reports that I am sending spam emails (particularly viagra emails) to people in my address book. I have performed the usual scans and have followed all guidance in your FAQ.
    Every time it looks like it is clear of malware,viruses etc.... I get another report.
    Could you check my system please. Thanks.
    Part two to follow.......

    Thanks Again.
     

    Attached Files:

  2. janner66

    janner66 Private E-2

    Part Two

    Thanks.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First, you should read this:
    Warning about Porn, Keygens, Cracks, and other Illegal Software

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and delete:
    C:\Program Files (x86)\Tonec.Inc.Internet.Download.Manager.v5.19.Build.3.Incl.Keygen.and.Patch-Lz0\Tonec.Inc.Internet.Download.Manager.v5.19.Build.3.Incl.Keygen.and.Patch-Lz0\Internet Download\Internet Download Manager\IDMan.exe

    Malware detected in email databases has to be cleaned up by you. You have a few choices:

    1. delete the whole file which is not an option you normally want to use
    2. load the email folder that contains the infection and delete ALL unnecessary emails (hoping to remove the problem email) and then use the Mailbox Cleanup option to delete all old emails. Then compact the Outlook database to permanently remove data. See http://support.microsoft.com/kb/291645 If you do not cleanup and compact the databases, the deleted emails may still be leaving hidden information in the database that you just cannot see but a scanner may still pickup on it.
    3. create a new folder and move only emails you really need into the new folder and then delete the infected folder.

    You may be helped by adding this as a contact:
    aaa@aa.com

    Let me know how that goes.
     
  4. janner66

    janner66 Private E-2

    Hi Tim

    Thanks very much for your help.

    The Regedit notepad file did merge with my registry successfully and I have deleted the IDM programme and scripts. I have tried to delete as many emails as I can from my Yahoo email account also but am not aware that I can compact Yahoo. I have added aaa@aa.com to my contacts.

    Do I need to provide you with any more logs or perform any more scans?

    Thanks again.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds