A few friends of mine told me they received an e-mail with a link in it. One of these sites advertising viagra etc (very embarassing considering it sent it to EVERY e-mail address in my mailing list). Even I received the e-mail
I found out because a friend told me and also because I received delivery failure notifications from a few defunct addresses. I noticed the link varies from mail to mail and it sent out the mails in batches (10 to 20 addresses per message)
the link in the e-mail I received was –> http://gammaruchephws6.webs.com?Pkeiknw
In the right panel, you will see several boxes that have been checked. Uncheck the following …
Sections
IAT/EAT
Drives/Partition other than Systemdrive (typically C:\)
Show All (don't miss this one)
Then click the Scan button & wait for it to finish.
Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop, and post it in your next reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
ok. i followed all the instructions and ran GMER. it ran for a few mins then came up with that blue screen (the "commencing memory dump" one). I decided to restart my computer (the only option) and try again. this time, GMER ran for about 4 hours (which is why I'm only just able to type this now), consumed ALL my system resources and ended up with the same blue screen just now.
FRUSTRATING! is there anything else I can do? I'm really trying to co-operate but…this is pretty strange…
I really appreciate the help so far. Not sure I understand your last message fully though. You say I should uncheck "files" but intially you said "Drives/Partition other than Systemdrive". Please clarify. Do I uncheck files altogether or everything except "C:"? I'm also not sure how to
note if there are any rootkit entries,hidden entries or suspicious modifications.
Basically I can't just go ahead and run GMER again until I understand what is supposed to be happening here. Is it supposed to spend 5 hours scanning? I have 2GB of RAM with only about 5% in use…until GMER starts running. Then it goes up to 100% and never comes back down. It slows everything down and I have to restart my computer so I can do things. I couldn't even post this simple message.
I've attached DDS.txt and Attach.txt in the meantime but please please please clarify EXACTLY what I'm supposed to do and what's supposed to be happening because otherwise I'll be like a crazy person doing the same thing over and over expecting new results…
Hi,
I added "files" to uncheck, so that GMER would not take as long:
so if you uncheck
files,
sections
IAT/EAT
make sure only the C:\ drive is selected and make certain 'Show All' is unchecked.
I expect that you have already changed passwords for all your email accounts already.
If you haven't make certain that you do as your email accounts have been hacked from what you are describing.
Also make certain you report this to your ISP as well as the email account (Yahoo, Gmail etc) as the spam emails will be sent from remote locations, just using your credentials, not from your machine.
Let GMER scan uninterrupted with all other windows closed then it will run faster.
The DDS log isn't showing any signs of infection on your machine, nor is the GMER scan showing any sign of rootkit activity, Your Kaspersky antivirus must have been interfering with GMER the first time you tried to run it.
Just to make certain nothing has infected your machine, we can run a couple of scan, but as long as you have changed passwords on all your online accounts (email as well as chat and any social networking sites you belong to) and have reported this to your ISP and email providers, there isn't much more you can do.
This can happen if you get tricked into filing out a fake form with your credentials, or a link in an email or IM received by yourself etc.,
Here's a link to how it works for instant messaging and what to do about it, what to watch for and avoid. And another with some links to additional information.
This works the same for emails.
Please do the following:
Please open your MalwareBytes AntiMalware Program
Click the Update Tab and search for updates
If an update is found, it will download and install the latest version.
Once the program has loaded, select "Perform Quick Scan", then click Scan.
The scan may take some time to finish, so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and clickRemove Selected. <– very important
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Copy&Paste the entire report in your next reply.
Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.
NEXT
Make sure Kaspersky is disabled for this scan:
Go here to run an online scanner from ESET.
Note: You will need to use Internet explorer for this scan
Turn off the real time scanner of any existing antivirus program while performing the online scan
Tick the box next to YES, I accept the Terms of Use.
Click Start
When asked, allow the activeX control to install
Click Start
Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
Click Scan
Wait for the scan to finish
Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
Copy and paste that log as a reply to this topic and also let me know how things are now.