Thread: My turn
View Single Post
Old 10-07-2006, 11:08 AM   #6 (permalink)
sUBs
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,500
OS: N/A


Quote:
Mail server report.

Our firewall determined the e-mails containing worm copies are being sent from your computer.

Nowadays it happens from many computers, because this is a new virus type (Network Worms).


Using the new bug in the Windows, these viruses infect the computer unnoticeably.
After the penetrating into the computer the virus harvests all the e-mail addresses and sends the copies of itself to these e-mail addresses

Please install updates for worm elimination and your computer restoring.

Best regards,
Customers support service
Hello Horse,

Have you checked the authencity of the above email? The message looks a bit suspect & may be just a hoax.

Nevertheless, let's take a deeper look & see if we cna find any lurkers. Please do the following:

* Download StartDreck

Unzip to its own folder and start the program:
Press 'Config'
Press 'mark all'

Uncheck this box only - List Modules (listed under 'Running Proceses')
Press 'OK'

Press 'Save' and select the location to save the log file (default is the same folder as the application)


* Download gmer from http://www.gmer.net & extract the contents to desktop
Disconnect from internet and close running programs.
There is a small chance this application may crash your computer so save any work you have open.
Double click gmer.exe.
Let the gmer.sys driver load if asked.
If it gives you a warning at program start about rootkit activity and asks if you want to run scan...say NO.
To the right of the program you will see a bunch of boxes that have been checked... leave everything checked and uncheck the Registry box. Then click the Scan button. Wait for the scan to finish.
Once done click the Copy button.
Open Notepad and hit ctrl+v to paste the log.


* Click Gmer's Autostart tab then the scan button. Once its done click the Copy button and paste it into a new notepad document.


Kindly post the above 3 logs
__________________

Question - what have you done for the community today?
sUBs is offline