Re: Virus problems



From: "Info" <info@xxxxxxxxxxx>

| What anti-virus software would you recommend for Windows XP? It has all the
| security patches on it. I use Outlook for friends and relatives only. I
| get no spam or suspicious emails in that account - none. I use Outlook
| Express for newsgroups; that's just habit. I get tons of spam emails in OE
| and I never open any of the emails. I just delete them. I use Yahoo for
| all my shopping and Firefox as my browser. My wife uses IE for her Yahoo
| email and everything else. I know my MySpace account was hacked because
| there was a posting there that wasn't mine.

| Here's the current stuff I use and what's been happening:

| a) Norton 2006 and no firewall. A scheduled scan runs every Friday night.
| Every once in awhile I get a message
| that Live Update failed. It's invariably LU1845

| I just used Live Update twice and got these two messages. I did not reboot
| the computer after the first one; I just ran Live Update a

| "Norton Internet Security security updates has 1 aborted update for the
| following reason: "
| LU1845 not updated due to a processing error.

| Symantec Internet Intrusion Detection Signatures has 1 aborted update for
| the
| following reason: "
| LU1845 not updated due to a processing error.

| The screen said everything else updated and was downloaded properly.
| --------
| It appears that my Outlook Express email gets an occasional attachment that
| Norton or Webroot catches. Again I never open any OE emails and the OE
| address is not my Yahoo or the real address and account that I use only for
| friends.

| b) I started using Webroot about two weeks and run sweeps. I sweep every
| Friday night after the Norton scheduled scan has finished. Webroot picked
| up the following and put them in "quarantine." Should I delete the stuff in
| "quarantine?" After each of the Webroot items below I've listed WebRoot's
| web site's explanation of the threat. As far as I can tell, Norton never
| picked any of this stuff up.

| Mal/EncPk -CZ -- no threat with this name in our database

| Mal/Generic-A --- malicious file for Windows platform

| Troj/Agent-IAO --- no threat with this name in our database

| Troj/FakeVir-GL --- no threat with this name in our database

| ======

| Because I'm certain I got hacked I need to change all my passwords. There
| was something with "hack" in its name. How can I be certain that my
| computer's free of the things that capture passwords and other form stuff I
| enter? I NEVER, EVER answer spam emails or enter info other than my Yahoo
| address into web sites into which I have the slightest suspicion. I only
| enter other info on my banking web site, Safeway, my HMO, Amazon, or
| whatever. A few charges that I had nothing to do with showed up on my Visa
| card about 4 days ago. Craigs List & Astrology.com. They're bogus & I'm
| working with VISA to get them killed and to get a new card.

| Any all help will be deeply appreciated. Thanks muchly.



Download and execute HiJack This! (HJT)
http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe

Then post the contents of the HJT log in your post in one of the below expert forums...

{ Please - Do NOT post the HJT Log here ! }

Forums where you can get expert advice for HiJack This! (HJT) Logs.

NOTE: Registration is REQUIRED in any of the below before posting a log

Suggested primary:
http://www.thespykiller.co.uk/index.php?board=3.0

Suggested secondary:
http://www.bleepingcomputer.com/forums/forum22.html
http://castlecops.com/forum67.html
http://www.malwarebytes.org/forums/index.php?showforum=7

Suggested tertiary:
http://www.dslreports.com/forum/cleanup
http://www.cybertechhelp.com/forums/forumdisplay.php?f=25
http://www.atribune.org/forums/index.php?showforum=9
http://www.geekstogo.com/forum/Malware_Removal_HiJackThis_Logs_Go_Here-f37.html
http://gladiator-antivirus.com/forum/index.php?showforum=170
http://forum.networktechs.com/forumdisplay.php?f=130
http://forums.maddoktor2.com/index.php?showforum=17
http://www.spywarewarrior.com/viewforum.php?f=5
http://forums.spywareinfo.com/index.php?showforum=18
http://forums.techguy.org/f54-s.html
http://forums.tomcoyote.org/index.php?showforum=27
http://forums.subratam.org/index.php?showforum=7
http://www.5starsupport.com/ipboard/index.php?showforum=18
http://aumha.net/viewforum.php?f=30
http://makephpbb.com/phpbb/viewforum.php?f=2
http://forums.techguy.org/54-security/
http://forums.security-central.us/forumdisplay.php?f=13


--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


.



Relevant Pages

  • Re: Outlook 2003 Patch to Address Receiving E-mail Error
    ... Do you by any chance have Norton Internet Security or the like installed? ... it is not an Outlook problem but a Symantec one. ... Install the product again but turn Live Update OFF ... > the emails and I'll get multiples of the same emails every time it ...
    (microsoft.public.outlook.general)
  • Re: Outlook 2003 Patch to Address Receiving E-mail Error
    ... it is not an Outlook problem but a Symantec one. ... So here is the story from Symantec Technical Support. ... > bug in the latest via Live Update. ... >> emails using webmail with no trouble. ...
    (microsoft.public.outlook.general)
  • Virus problems
    ... I use Outlook for friends and relatives only. ... I get tons of spam emails in OE ... I just used Live Update twice and got these two messages. ... "Norton Internet Security security updates has 1 aborted update for the ...
    (alt.comp.anti-virus)
  • Re: Worm.SomeFool.I
    ... Norton is scanning both incoming and outgoing email. ... screen display is changing everytime I bring Outlook up. ... telling me I have been sending emails with the somefool.I ... >How is Outlook acting like it has a worm or virus? ...
    (microsoft.public.outlook)
  • Re: outlook 2003 send problem
    ... I have Outlook 2003 ... if I so much as visit the outbox (not even ... opening any of the emails), any e-mail that is highlighted becomes ... > if it might be the Norton Outlook Antispam pluggin in some way? ...
    (microsoft.public.outlook.general)