1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Yahoo email sending spam to contacts

Discussion in 'Malware and Virus Removal Archive' started by trub, 2011/06/23.

  1. 2011/06/23
    trub Lifetime Subscription

    trub Well-Known Member Thread Starter

    Joined:
    2009/07/09
    Messages:
    306
    Likes Received:
    0
    Did exactly as you said and got the same result as with run.. Quick flash as though a pop up window was trying to open but closes in an instant. Looks like a dos type window trying to open.

    Saved fix.bat in notepad to desktop just as suggested.

    ?

    Is this really a problem?
     
  2. 2011/06/23
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    That's normal.

    See, if you can access "documents and settings ".
     

  3. to hide this advert.

  4. 2011/06/23
    trub Lifetime Subscription

    trub Well-Known Member Thread Starter

    Joined:
    2009/07/09
    Messages:
    306
    Likes Received:
    0
    and what may have caused it?
     
  5. 2011/06/23
    trub Lifetime Subscription

    trub Well-Known Member Thread Starter

    Joined:
    2009/07/09
    Messages:
    306
    Likes Received:
    0
    Broni, I know I am doing this correctly. Still no access.
     
  6. 2011/06/23
    trub Lifetime Subscription

    trub Well-Known Member Thread Starter

    Joined:
    2009/07/09
    Messages:
    306
    Likes Received:
    0
    Hey Broni I have windows 7 if this matters.

    For all I know it has always been this way but I just discovered it today..
     
  7. 2011/06/23
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Are you logged as administrator?

    Re-run System Look with this script:

    Code:
    :dir
    C:\
    
     
  8. 2011/06/23
    trub Lifetime Subscription

    trub Well-Known Member Thread Starter

    Joined:
    2009/07/09
    Messages:
    306
    Likes Received:
    0
    SystemLook 04.09.10 by jpshortstuff
    Log created at 19:31 on 23/06/2011 by Steven
    Administrator - Elevation successful

    ========== dir ==========

    C: - Parameters: "(none) "

    ---Files---
    autoexec.bat --a---- 24 bytes [02:04 14/07/2009] [21:42 10/06/2009]
    bootmgr -rahs-- 383786 bytes [21:43 06/11/2009] [12:40 20/11/2010]
    BOOTSECT.BAK -rahs-- 8192 bytes [21:43 06/11/2009] [21:43 06/11/2009]
    ComboFix.txt --a---- 15691 bytes [22:27 23/06/2011] [22:27 23/06/2011]
    config.sys --a---- 10 bytes [02:04 14/07/2009] [21:42 10/06/2009]
    hiberfil.sys --ahs-- -1880608768 bytes [21:44 06/11/2009] [22:33 23/06/2011]
    JavaRa.log --a---- 20497 bytes [03:44 21/02/2011] [03:44 21/02/2011]
    pagefile.sys --ahs-- -1075822592 bytes [21:44 06/11/2009] [22:33 23/06/2011]

    ---Folders---
    $RECYCLE.BIN d--hs-- [22:27 23/06/2011]
    Boot d------ [21:43 06/11/2009]
    Config.Msi d------ [08:01 19/06/2011]
    Documents and Settings d--hs-- [04:53 14/07/2009]
    MSOCache dr----- [22:12 06/11/2009]
    PerfLogs d------ [02:37 14/07/2009]
    Program Files dr----- [02:37 14/07/2009]
    ProgramData d------ [02:37 14/07/2009]
    Qoobox d------ [04:17 21/02/2011]
    Recovery d------ [18:50 06/11/2009]
    System Volume Information d--hs-- [21:44 06/11/2009]
    Users dr----- [02:37 14/07/2009]
    Windows d------ [02:37 14/07/2009]

    -= EOF =-
     
  9. 2011/06/23
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Now, wait a second...I'm confused...
    I just realized, you're running Windows 7.
    There is no "Documents and Settings" folder being Windows 7 native.
    Is it some backup/leftover from Windows XP?
     
  10. 2011/06/23
    trub Lifetime Subscription

    trub Well-Known Member Thread Starter

    Joined:
    2009/07/09
    Messages:
    306
    Likes Received:
    0
    C:/Documents and Settings is not accessible.

    Access is denied.

    This is what pops up.

    I am going my computer...C then in the list is Doc and Sett

    I am puzzled
     
  11. 2011/06/23
    trub Lifetime Subscription

    trub Well-Known Member Thread Starter

    Joined:
    2009/07/09
    Messages:
    306
    Likes Received:
    0
    The machine originally came with vista. I did the 7 upgrade when 7 first came out. I think this junction folder with no real use in the 7 system hence unable to access? Agree?
     
  12. 2011/06/23
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    There shouldn't be such folder neither in Vista, or Windows 7.
    Let's see what's inside.
    BTW, my .bat file was incorrect (wrong "slash ").

    Re-run SL with this code:

    Code:
    :dir
    C:\Documents and Settings /s
    
     
  13. 2011/06/23
    trub Lifetime Subscription

    trub Well-Known Member Thread Starter

    Joined:
    2009/07/09
    Messages:
    306
    Likes Received:
    0
    I was just reading some stuff. I find this interesting. If you hit start C:/documents and settings nothing appears.

    To find this folder I go to my computer click on C drive (local disc c) and thare she blows. Then the lock out fun begins. I do not remember if I did a clean install or upgrade seems to me it was clean.

    The other folder I cannot access is computer>local disk C>users>default user.

    SystemLook 04.09.10 by jpshortstuff
    Log created at 20:00 on 23/06/2011 by Steven
    Administrator - Elevation successful

    ========== dir ==========

    C:\Documents and Settings - Parameters: "/s "

    ---Files---
    None found.

    No folders found.

    -= EOF =-
     
  14. 2011/06/23
    trub Lifetime Subscription

    trub Well-Known Member Thread Starter

    Joined:
    2009/07/09
    Messages:
    306
    Likes Received:
    0
  15. 2011/06/23
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    It looks like Documents and Settings folder is empty.

    Just to make sure....
    Delete .bat file, I asked you to create.

    Open Notepad.
    Copy all text from the following code box and paste it into Notepad window:

    Code:
    @echo off
    attrib -h -s  "C:\documents and settings "
    exit
    
    Save the file as fix.bat.

    Double click fix.bat to run it.
    A pop-up window will open and you'll see number of files being copied.
    The window will close, when all copying is done.

    Can you access it now?
     
  16. 2011/06/23
    trub Lifetime Subscription

    trub Well-Known Member Thread Starter

    Joined:
    2009/07/09
    Messages:
    306
    Likes Received:
    0
  17. 2011/06/23
    trub Lifetime Subscription

    trub Well-Known Member Thread Starter

    Joined:
    2009/07/09
    Messages:
    306
    Likes Received:
    0
    Negative still no access..
     
  18. 2011/06/23
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    "default" user is also hidden/system folder in Windows 7, but....one thing a ta time.
     
  19. 2011/06/23
    trub Lifetime Subscription

    trub Well-Known Member Thread Starter

    Joined:
    2009/07/09
    Messages:
    306
    Likes Received:
    0
    my bad
     
  20. 2011/06/23
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
  21. 2011/06/23
    trub Lifetime Subscription

    trub Well-Known Member Thread Starter

    Joined:
    2009/07/09
    Messages:
    306
    Likes Received:
    0
    OK. It let me in to documents and settings.

    Is this more or less a copy of C:/Users?

    Should I do the same for default user?

    Keep or uninstall the Ownership program?

    Thanks Broni I knew you could do It...
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.