Thread: Hotmail Virus - Vacation Reply?
-
April 3rd, 2009, 06:04 PM #1Junior Member
- Join Date
- Apr 2009
- Posts
- 3
Hotmail Virus - Vacation Reply?
Sorry, I've replied to another thread here called HOTMAIL VIRUS thinking it was a recent post but it's actually a yr old!
I got a new laptop yesterday and set it up last night - connected to internet and downloaded AVG like i had on my old laptop
This morning I realised my hotmail account has sent a vacation reply to my contacts saying:
Dear friend:
We are wholesale company which can offer you laptops,Digital cameras,videos,GPS , cellphone,mp4,game console and many other electronic products with international guarrantee all over the world.
We can offer you both high quality products and good price. with the new beginning of 2008, we want to have a long term business with you/your company If you want to buy something ,please feel free contact us at:
our website : <http://www..com>
MSN : x@hotmail.com
E-mail : xhotmail.com
Welcome to x.com! MSN: x@hotmail.com
I'm angry thinking iv got a virus on my brand new laptop!
Any help greatly appreciated, as I say it's a new laptop and didnt/doesnt appear to have any spyware or malware, or a firewall, though i've downloaded AVG anti virus now.
Thank you,
Laura
Hera's my hijackthis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:59:43, on 03/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IDT\WDM\STacSV.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\msco rsvw.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\sttray.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\WINDOWS\system32\AESTFltr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AVG\AVG8\aAvgApi.exe
C:\Program Files\AVG\AVG8\avgui.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Documents and Settings\Laura Rennie\My Documents\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Yahoo!
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = BBC - BBC Scotland - Homepage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Yahoo!
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = Customize Your Settings
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IDTSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [AESTFltr] %SystemRoot%\system32\AESTFltr.exe /NoDlg
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Mobile Broadband] c:\SWsetup\HPQWWAN\HPMobileBroadband.exe /TrayMode
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV.exe
--
End of file - 6681 bytes
Please help!
-
April 3rd, 2009, 06:11 PM #2
First off, hotmail is webmail based, so unless you have outlook or some other mail app setup to send outgoing mail through your account it would not be a virus on your machine.
Second, since hotmail is webmail based, its more likely that your account has been accessed by an outside source. Likely phishing, possibly a Trojan on your old system (maybe even the new one) or something similar. You need to turn off the vacation reply function from hotmail and change your passwords.
Third, you can use the tools from this thread to check your logs HijackThis Analyzer & Tutorial.
TechIMO Folding@home Team #111 - Crunching for the cure!
“Because The People Who Are Crazy Enough To Think They Can Change The World, Are The Ones Who Do.”
-
April 3rd, 2009, 06:21 PM #3Junior Member
- Join Date
- Apr 2009
- Posts
- 3
Thank u, so there should not be an actual virus on my computer? Im currently trying to get my new laptop protected, I have XP SP3, so Im not sure if that already includes a firewall, spyware, malware etc?
Laura
PS Yes I've changed passwords and removed vaction reply
-
April 3rd, 2009, 06:26 PM #4
It is possible, you are running AVG however so if you had a virus your scans should show it.
I have XP SP3, so Im not sure if that already includes a firewall, spyware, malware etc?
XP has a firewall although its not a great one. ZoneAlarm or one of the other freebies would probably be a good idea. For Spyware/Malware protection, adaware and Spy-Bot Search and Destory would be good ideas.
TechIMO Folding@home Team #111 - Crunching for the cure!
“Because The People Who Are Crazy Enough To Think They Can Change The World, Are The Ones Who Do.”
-
April 3rd, 2009, 06:32 PM #5Junior Member
- Join Date
- Apr 2009
- Posts
- 3
I'll download those now, it was zone alarm I had on old laptop. I have looked at other posts from people with the same problem, even some moderators here have said this particular problem/trojan is not being picked up by most anti-virus programmes...One person said it wrecked their whole hard drive
but he said he had no anti virus software....God I hope that doesnt happen to my brand new laptop
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Similar Threads
-
Hotmail Virus?
By gyoung in forum Security and Privacy IssuesReplies: 36Last Post: May 29th, 2011, 02:18 PM -
Possible Hotmail Virus...My Dear Friends!
By whizkid2000 in forum Security and Privacy IssuesReplies: 18Last Post: April 1st, 2011, 04:53 PM -
HOTMAIL: Virus SPAM
By MatrixmaN in forum Security and Privacy IssuesReplies: 10Last Post: March 29th, 2011, 10:46 AM -
I think my hotmail has a virus
By Raych in forum Security and Privacy IssuesReplies: 4Last Post: September 29th, 2009, 03:06 PM -
Hotmail Virus Alerts
By robexe in forum General Tech DiscussionReplies: 1Last Post: March 2nd, 2004, 09:31 PM



LinkBack URL
About LinkBacks



Reply With Quote


Err...Uhmm..may I ask a seemingly naïve question...Why would a "mass murderer" want, of all things, a high-precision long-distance accuracy weapon? Did I understand it correctly? it waits for its...
The perfect gift for an aspiring...