Wierd unknown emails being sent

Discussion in 'Malware Help (A Specialist Will Reply)' started by drgrim, Jun 26, 2007.

  1. drgrim

    drgrim Private First Class

    Hi, When I open up my email (server based) there are many messages from the servers email system saying that it couldnt send an email apparently from my email program (also server based). All the addresses are @aol.com or similar. So far they seem to be alphabetical in address name and I have received nine warnings that these emails couldnt be sent, each containing many of these AOL addresses. I am running ad aware SE, spybot search and destroy, avast antivirus and PC Tools firewall plus and nothing is coming up on any scans apart from the odd tracking cookie. Do I have a worm or some sort of adware/spyware??
    Any ideas??
    PS..I have run all the scans in safe mode and found nothing.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Hi ..my name is Tim and I will be helping you with this. Please follow our standard procedures and then post the logs. We can not tell what is happening in your system without them.

    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. drgrim

    drgrim Private First Class

    Ok Tim. Will have a go after work tonight and post the results as I get them.
     
  4. drgrim

    drgrim Private First Class

    Ok Tim. Here is the first one. I wasnt able to run Counterspy or AVG so I did run Super anti spyware. It found nothing but bitdefender looks like it found a fair bit. Log attatched. Sorry this is so slow but the pc isnt real fast at the moment
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Still need:
    • runkeys.txt - the log from GetRunKey.bat
    • newfiles.txt - the log from ShowNew.bat
    • HijackThis
     
  6. drgrim

    drgrim Private First Class

    here they are Tim!
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 3

    Reboot and install:
    Java Runtime 6

    NOw, please follow the instructions in the Read and Run First..
    You did not follow the first instruction - CCleaner: removing all the temp. files.

    You did not follow step 2 ..enabling the viewing of hidden files.

    Where did you get those versions of ShowNew and Get Run? They are both old versions ..please uninstall and get the latest versions.

    Finally, you did not follow the instructions for downloading and running HJT ...you put it exactly where we tell you not to put it and did not rename it as instructed.

    Please correct these items and attach new logs.
     
  8. drgrim

    drgrim Private First Class

    I got the versions of shownew and getrun from the links on the Read and Run First page!! Apologies for the stuff up with the others..will redo and post shortly
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but a very long time ago!! You must always work from the current online version of the READ ME. Get the proper versions of them and get new logs.
     
  10. drgrim

    drgrim Private First Class

    We did remove temp files with Ccleaner. Just went into it again in safe mode and it said there was nothing to remove!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you see message # 9?

    See the last log from ShowNew that you posted. Tim was commenting on the fact that it show a load of files in

    C:\Documents and Settings\mitchell\Local Settings\Temp\

    And a few files in:
    C:\WINDOWS\Temp\
     
  12. drgrim

    drgrim Private First Class

    Ok..I think we finally have this right. See how we go from here
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean. You may uninstall any programs we had you download (including Counterspy).

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  14. drgrim

    drgrim Private First Class

    Thanks for your help Tim. Unfortunately we are still having problems. We are still getting wierd emails being sent from our address and the mouse seems to have a mind of its own from time to time. Any more ideas?
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, how rude!!

    Lets see if you have a rootkit infection that is hiding GMER

    Attach the log.
     
  16. drgrim

    drgrim Private First Class

    Um.....which log?
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    • Then click the Scan button. Wait for the scan to finish.
    • Once done, click the Copy button.
    • This will copy the results to the clipboard. Open Notepad and press CTRL + V to paste the log, and save it to your desktop. Attach this log to your next reply.
    NOTE: If you're having problems with running gmer.exe, try it in Safe Mode. This tool works in Safe Mode whereas many other rootkit revealers do not.
     
  18. drgrim

    drgrim Private First Class

    OK Tim. Here it is.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Mouse problems are rarely (if ever) related to malware. I suggest you first try another mouse and see what happens. In more than two dozen cases I have seen like this thus far, it has always been the mouse.

    As far as email being sent from your PC. Are you sure it is really being sent? Shutdown your PC for a day or so (however long it takes to see test this) and then when you turn it back on see if there are reports of emails being sent during a time frame when your PC is turned off.

    You could just be getting spammed and someone is spoofing your IP or email address.
     
  20. drgrim

    drgrim Private First Class

    Got the mouse thing sorted. I have had problems trying to open majorgeeks site. Only this particular site has been giving us problems (apart from the endless emails..yes theyre still getting sent but only when we have the pc on and online)..everywhere else we try to go no probs..would it be possible for a nasty of some sort to stop us coming here? I am actually having to write this from another PC.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is your method of knowing these emails are being sent and who are they being sent to. Is it addresses in your email programs Address Book? What email program?

    Yes it could be malware but I doubt it based on your logs. It is more likely something you have done. Are you sure you are not blocking it with anything? Check your firewall to make sure it is not blocking it. Even try temporarily disabling the firewall to see if that changes anything. Also make sure you did not put MajorGeeks in your Restricted Zone.
     
  22. drgrim

    drgrim Private First Class

    We are using our servers email program and are getting returned emails that we never sent. Most of them are to AOL addresses. The addressees are varied and many. Getting around twenty per day now. Was more when all this started. Definately havent blocked major geeks in any way. Was only the other night when we couldnt access you...now all seems to be ok. Maybe there were just too many people using your site at once.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Perhaps you are cleaning the wrong PC! From what you are writing you are saying you have a server someplace else. We are cleaning your PC not the server. You need to find out if the server is sending emails.

    If it only happen once during a small time frame then it could have been while MG's had a brief outage.
     
  24. drgrim

    drgrim Private First Class

    I just went through the list of extra scans to do and found a trojan dropper and a couple more trojans. Got rid of them and so far everything seems back to normal. Will let you know if the mail thing happens again. Thanks for all your hep yet again guys!
     
  25. drgrim

    drgrim Private First Class

    Sorry...we dont have a server..our isp has its own email webmail which we use online
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds good! Do you know the name of what was found and where it was found? Was it in the System Volume Information folder which is System Restore? What scans did you run?


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  27. drgrim

    drgrim Private First Class

    I ran the alternative scans you have isted on the read and run first page. It was the A squared online scanner that found the last ones. Was a trojan...wasnt in the system restore folder..sorry..I cant remember where it was found. think it mightve been system32 or similar..I shouldve written it down.
    Cheers
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Thanks for trying anyway!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds