Unsolved

This post is more than 5 years old

6 Posts

18311

June 25th, 2004 08:00

My computer or email acct is SENDING spam without my knowledge

Lately my computer has been a little slower and resource usage seems higher than I remembered. No serious problems.

But I have received spam saying it was FROM my own address -- first I thought it was just a new technique. But now I am getting undeliverable mail bounces from administrators with long lists of addresses that I have never sent.

My Norton Live Update is not updating completely either. I have to update manually now.

I called Verizon and they said I must have the Klez worm and referred me to Norton for FixKlez. I followed the Norton instructions completely (which destroyed all my restore points). After several hours, Norton said I did not have any worm or virus.

I am still receiving occasional emails from myself and bounces from administrators; I have started collecting them -- 33 since June 12.

Has anyone had a similar problem. Has my computer or just my email address been hijacked?

Nan

 

 

2 Intern

 • 

1.3K Posts

June 25th, 2004 09:00

i am not saying that there is not a problem, but it is possible that your email address was forged in the spam while it did not actually originate from your email account.. i have gotten spam-email bounced back to me that apparently had my email address as the "from" email address, but i did not send it.. i don't know how to tell you to resolve that problem if it persists.. i report spammers through http://www.spamcop.net ; if you get spam with your own email address as the return address, maybe reporting the spammer through spamcop will help to put the spammer out of business..

 

Message Edited by redwolfe_98 on 06-25-2004 06:58 AM

2 Intern

 • 

3.9K Posts

June 25th, 2004 10:00

Lets check your machine out
=====================
Use these to remove Malware (Virus, Spyware and Adware).

First :-
Spybot S&D and Ad-aware using the settings and links provided
Here

Failing those solving your problems a post of a hijackthis log for the experts to advise.
HijackThis From Here
or one of these other links:-
http://www.merijn.org/files/hijackthis.zip
http://www.aluriasoftware.com/tools/hijackthis.zip
http://mjc1.com/mirror/hjt/

Important: Create a folder on the C: drive called C:\HJT.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT. Unzip HijackThis into this folder. (See this link for graphical instructions)
Then run, scan, save log, then in notepad copy the FULL log by copy and paste as a reply to this post and an expert with HijackThis Knowldge, will have a go at giving advice. A lot of posters make mistakes here in copying and pasting so reread the left info sidebar called Copy and Paste
Please note the list of experts names below, very few forum regulars here have had this training.

DO NOT FIX ANYTHING WITH HIJACKTHIS WITHOUT EXPERT ADVICE
, most of what it finds you need for normal MS Windows tasks.

Known Spyware HijackThis fighters in DellTalk - If you are, and are not on the list please PM Me.

TomCoyote (of http://tomcoyote.com/forums/index.php fame)
YoKenny (Expert at TomCoyotes, Trusted Advisor Spywareinfo)
baskar1234 (Slyware Warrior at TomCoyotes, Trusted Advisor Spywareinfo)
ChrisRLG (Classroom Teacher at TomCoyotes, Trusted Advisor Net-Intergration and Spywareinfo, Spyware Fighter at Wilders)
Tuxedo Jack (Slyware Warrior at TomCoyotes, Trusted Advisor Spywareinfo)
Yellowhammer (Slyware Warrior at Tomcoyotes, Trusted Advisor at Net-Integration, First Responder at Computer Cops)
tashi (Slyware Warrior at TomCoyotes, Trusted Advisor Spywareinfo)
therock247uk (In Training at TomCoyotes and Spywareinfo)
irelynmisses (In Training at TomCoyotes and Spywareinfo)
Texruss (Spyware Fighter at Wildersecurity, Slyware Warrior at TomCoyotes)
PGPhantom (Trusted Advisor at Spywareinfo)

6 Posts

June 25th, 2004 16:00

Thank you very much for the replies. Just discovered this forum last night.

I am printing them and will try your suggestions on Sunday. Then I will post back what I learn from HijackThis.

(It's Fri am here in Calif. My son is leaving for university summer school in Costa Rica tomorrow night, so last minute preparations take priority now.)

BTW, I have been using Ad-Aware for a year and just started using Spybot too last week.

Is there any chance I'll get myself in trouble by reporting to Spamcop, since it appears that I am a spammer? I have started saving all these emails in a folder, as evidence.

Nan

4.4K Posts

June 25th, 2004 17:00

nanjowood,

You may find this tutorial on interpreting EMAIL headers from the University of Alberta, and this one from Earthlink Support helpful. It's important to emphasize that the apparent sender (you, in this case) is trivially easy to forge.

Jim

2 Intern

 • 

1.3K Posts

June 26th, 2004 01:00



@nanjowood wrote:

Is there any chance I'll get myself in trouble by reporting to Spamcop, since it appears that I am a spammer? I have started saving all these emails in a folder, as evidence.

Nan



yes, it is possible that if the network adminstrator of your service provider sees that your computer is actually being used to broadcast spam,  that the account would be temporrarily suspended.. on the other hand, if you report the spam through spamcop, it will show you where the spam originated, and you will still have the option of whether to report the spam, or not.. you could contact the service provider of your email account (like msn, aol, yahoo) and try to get them to help you to resolve the problem.. i am not sure, but i would think that an antivirus program would detect malware on your computer that would be sending out the spam, if it exists..

Message Edited by redwolfe_98 on 06-25-2004 10:47 PM

2 Intern

 • 

1.3K Posts

June 27th, 2004 04:00

i was just looking at this.. it might be pertinent..

http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=38650

6 Posts

June 28th, 2004 03:00

I'm back now. (And my son arrived safely in Costa Rica.)

I just read redwolfe's link describing the worm Netsky.P.

That could be what I have ... I've seen the name before as something Norton Antivirus intercepted in emails I've received; maybe one got through somehow.  But the Norton antivirus scan I run weekly hasn't ever reported an infection.

I'll go look now to see if there's a special check or tool for this one. And do the spam cop report.

Then I'll try the other suggestions tomorrow.

Thanks,

Nan 

317 Posts

June 28th, 2004 04:00

nanjowood,

To help ensure you don't have a virus, try Symantec's on-line scan (in case your local version has been compromised):

http://www.symantec.com/product/index_homecomp.html

Better yet, follow the directions above to run HijackThis (in ChrisRLG's post), and post the results.  The very knowledgable experts who voluntarilly assist via this forum can help interpret the results, and one of them will respond with any information on what they find.

It's important to remember that just because an email is bounced back to you, does not mean it was sent by your computer.  It's far more likely that someone else is infected, and the virus is randomly using names from their email address book to show faked return addresses.  Because of this, the infected person is quite likely someone you know.  Unfortuneately, this can make it extremely difficult to track down the other system which is trully infected.

 

Message Edited by Jason98036 on 06-27-2004 10:19 PM

6 Posts

June 28th, 2004 15:00

Thanks for the input.

I ran Symantec's scan and fix for Netsky last night, 3 times, but it said I was NOT infected. I downloaded it on a laptop to a 3.5" disk. I ran the online Symantec scan on June 13.

Tonight I will report to spamcop and then run the recommended HikackThis. I will post the results.

Nan

(BTW, this is a Dimension 4500, purchased June 2002.)

6 Posts

June 29th, 2004 03:00

I just ran HijackThis.

Here is the log:

Logfile of HijackThis v1.97.7
Scan saved at 8:57:04 PM, on 6/28/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
D:\Program Files\Norton Internet Security\NISUM.EXE
D:\Program Files\Norton Internet Security\ccPxySvc.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Symantec\DeepSight Extractor\ExtractorService.exe
C:\Program Files\Symantec\DeepSight Extractor\ExtractorServiceNPF03.exe
c:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
D:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
D:\Program Files\Winamp\Winampa.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
D:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
D:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\devldr32.exe
D:\Program Files\Sony Handheld\HOTSYNC.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\cidaemon.exe
C:\Documents and Settings\WHELAN\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.refdesk.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
O4 - HKLM\..\Run: [WinampAgent] "D:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] D:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [iTunesHelper] D:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] :"C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\Symantec\LIVEUP~1\SNDMon.EXE
O4 - Startup: HotSync Manager.lnk = D:\Program Files\Sony Handheld\HOTSYNC.EXE
O4 - Global Startup: HotSync Manager.lnk = D:\Program Files\Sony Handheld\HOTSYNC.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Save To Palm - D:\Program Files\Sony Handheld\HandStoryME.htm
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: C&lip To Palm - D:\Program Files\Sony Handheld\HandStoryMEC.htm
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://c:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: Translate Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Save To Palm (HKLM)
O9 - Extra 'Tools' menuitem: &Save To Palm (HKLM)
O9 - Extra button: Researcher (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://babelfish.altavista.com
O15 - Trusted Zone: http://download.com.com
O15 - Trusted Zone: http://www.hancockcollege.edu
O15 - Trusted Zone: http://www.netflix.com
O15 - Trusted Zone: http://securityresponse.symantec.com
O15 - Trusted Zone: http://dslstart.verizon.net
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) - http://office.microsoft.com/templates/ieawsdc.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {4A752EEF-26FA-4E8F-8FF0-4EB40FE1D33B} (ACNPlayer2 Class) - http://204.118.132.145/Harris/eplayer.cab
O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - http://www.gocyberlink.com/winxp/CheckDVD.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/28edcabd80ff5527e405/netzip/RdxIE601.cab
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productupdates/content/opuc.cab
O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://support.dell.com/us/en/systemprofiler/SysProfLcd.CAB
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://zinio.earthc.net/images.zinio.com/reader/isetup.cab
O16 - DPF: {92CA8ACC-4E99-4A2A-93F1-B2C5CADC8613} (NMInstall Control) - http://a14.g.akamai.net/f/14/7141/1d/www.nielsennetpanel.com/netmeter4_5/nminstall_en_4.52.30.0_SILENT_2.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37602.3961921296
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O16 - DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} (CTAdjust Class) - http://download.microsoft.com/download/7/E/6/7E6A8567-DFE4-4624-87C3-163549BE2704/clearadj.cab
O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} (Microsoft Office Tools on the Web Control) - http://officeupdate.microsoft.com/TemplateGallery/downloads/outc.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab

Nan

6 Posts

June 30th, 2004 06:00

I ran Hijack This and posted the log yesterday.

Does all that info make any sense?

Nan

317 Posts

June 30th, 2004 11:00

nanjowood,

I know it's hard when you have a problem you want solved,  but try to be patient.  There are only a very few who are fully trained on reading and using the HijackThis log to identify and resolve problems (I'm not, wish I were, but no time to commit to joining and taking the training classes right now).  They volunteer their time here, in addition to their regular full-time job, so it can sometimes take a few days to get a reply.

If you wanted to give it more visibility, you could create a new thread starting with the HJT log file, since the current one is burried on page two of this thread.  If you do this, be absolutely certain to go back to this thread and on your message above select "Options" > "Edit This Message" and remove the log from this one.  That way there's no risk of the volunteers having to read the same log twice (which would delay responding to others who have also posted their logs).

Good luck,

No Events found!

Top