1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Outlook keeps sending is link: kdqj.allew.com

Discussion in 'Malware and Virus Removal Archive' started by mbremer, 2010/06/21.

  1. 2010/06/27
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Run this instead...

    Please run a BitDefender Online Scan

    • Disable your antivirus program.
    • Click Start Scanner button.
    • Click Start scan button
    • Allow browser plug-in to be installed when prompted.
    • Click I Agree to agree to the EULA.
    • Please refrain from using the computer until the scan is finished.
    • When the scan is finished, click on View log.
    • Notepad will open with scan results.
    • Save the report to your desktop and post its content in your next reply.
     
  2. 2010/06/28
    mbremer

    mbremer Inactive Thread Starter

    Joined:
    2010/06/21
    Messages:
    17
    Likes Received:
    0
    Completed scan with BitDefender, here is the log:

    <HTML>
    <HEAD>
    <TITLE>BitDefender Online Scanner -Scan Report</TITLE>
    <META HTTP-EQUIV= "Content-Type" CONTENT= "text/html; charset=iso-8859-1 ">
    <meta name= "generator" content= "Namo WebEditor v5.0(Trial) ">
    </HEAD>
    <BODY BGCOLOR=#FFFFFF leftmargin= "10" marginwidth= "0" topmargin= "20" marginheight= "0" >


    <table align= "center" border= "0" cellpadding= "0" cellspacing= "0" width= "90% ">
    <tr>
    <td width= "458 ">
    <p><font face= "Arial" color=red><span style= "font-size:14pt; "><b>BitDefender
    Online Scanner</b></span></font></p>
    </td>
    <td width= "40% ">
    <p>&nbsp;</p>
    </td>
    <td width= "10% ">
    <p>&nbsp;</p>
    </td>
    </tr>
    <tr>
    <td colspan= "3" width= "912 ">
    <p><font face= "Arial "><span style= "font-size:11pt; "><B>Scan report generated
    at: Mon, Jun 28, 2010 - 01:33:49</b></span></font></p>
    </td>
    </tr>

    <tr>
    <td width= "458 ">
    <p><font face= "Arial "><span style= "font-size:11pt; "><B>&nbsp;</b></span></font></p>
    </td>
    <td width= "40% ">
    <p>&nbsp;</p>
    </td>
    <td width= "10% ">
    <p>&nbsp;</p>
    </td>
    </tr>

    <tr>
    <td width= "458 ">
    <p><font face= "Arial "><span style= "font-size:11pt; "><B>Scan
    path: </b></span><span style= "font-size:10pt; ">C:\;D:\;</span></font></p>
    </td>
    <td width= "40% ">
    <p>&nbsp;</p>
    </td>
    <td width= "10% ">
    <p>&nbsp;</p>
    </td>
    </tr>

    <tr>
    <td width= "458 ">
    <p><font face= "Arial "><span style= "font-size:11pt; "><B>&nbsp;</b></span></font></p>
    </td>
    <td width= "40% ">
    <p>&nbsp;</p>
    </td>
    <td width= "10% ">
    <p>&nbsp;</p>
    </td>
    </tr>

    <tr>
    <td width= "458 ">
    <table border= "1" cellspacing= "0" bordercolordark= "white" bordercolorlight= "black" width= "100% ">
    <tr>
    <td width= "451" colspan= "2" bgcolor= "#CCCCCC ">
    <p><font face= "Arial" size= "2 "><B>Statistics</b></font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">Time</font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">05:15:59</font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">Files</font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">700792</font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">Folders</font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">9088</font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">Boot Sectors</font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">0</font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">Archives</font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">7729</font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">Packed Files</font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">155312</font></p>
    </td>
    </tr>
    </table>
    </td>
    <td width= "40% ">
    <p>&nbsp;</p>
    </td>
    <td width= "10% ">
    <p>&nbsp;</p>
    </td>
    </tr>



    <tr>
    <td width= "458 ">
    <table border= "1" cellspacing= "0" bordercolordark= "white" bordercolorlight= "black" width= "100% ">
    <tr>
    <td width= "451" colspan= "2" bgcolor= "#CCCCCC ">
    <p><font face= "Arial" size= "2 "><B>Results</b></font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">Identified Viruses </font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">1</font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">Infected Files </font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">1</font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">Suspect&nbsp;Files </font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">0</font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">Warnings</font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">0</font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">Disinfected</font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">0</font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">Deleted Files</font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">1</font></p>
    </td>
    </tr>
    </table>
    </td>
    <td width= "40% ">
    <p>&nbsp;</p>
    </td>
    <td width= "10% ">
    <p>&nbsp;</p>
    </td>
    </tr>

    <tr>
    <td width= "458 ">
    <table border= "1" cellspacing= "0" bordercolordark= "white" bordercolorlight= "black" width= "100% ">
    <tr>
    <td width= "451" colspan= "2" bgcolor= "#CCCCCC ">
    <p><font face= "Arial" size= "2 "><B>Engines Info</b></font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">Virus Definitions</font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">6328317</font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">Engine build</font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">AVCORE v2.1 Windows/i386 11.0.0.33 (Jun 10 2010)</font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">Scan plugins</font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">17</font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">Archive plugins</font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">44</font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">Unpack plugins</font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">10</font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">E-mail plugins</font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">6</font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">System&nbsp;plugins</font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">4</font></p>
    </td>
    </tr>
    </table>
    </td>
    <td width= "40% ">
    <p>&nbsp;</p>
    </td>
    <td width= "10% ">
    <p>&nbsp;</p>
    </td>
    </tr>

    <tr>
    <td width= "458 ">
    <table border= "1" cellspacing= "0" bordercolordark= "white" bordercolorlight= "black" width= "100% ">
    <tr>
    <td width= "451" colspan= "2" bgcolor= "#CCCCCC ">
    <p><font face= "Arial" size= "2 "><B>Scan Settings</b></font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">First Action</font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">Disinfect</font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">Second Action</font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">Delete</font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">Heuristics</font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">Yes</font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">Enable Warnings</font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">Yes</font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">Scanned Extensions</font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">*;</font></p>
    </td>
    </tr>

    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">Exclude Extensions</font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">&nbsp;</font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">Scan Emails</font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">Yes</font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">Scan Archives</font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">Yes</font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">Scan Packed</font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">Yes</font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">Scan Files</font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">Yes</font></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">Scan Boot</font></p>
    </td>
    <td width= "43%" align= "right ">
    <p><font face= "Arial" size= "2 ">Yes</font></p>
    </td>
    </tr>
    </table>
    </td>
    <td width= "40% ">
    <p>&nbsp;</p>
    </td>
    <td width= "10% ">
    <p>&nbsp;</p>
    </td>
    </tr>

    <tr>
    <td colspan=2> &nbsp;
    <table border= "1" cellspacing= "0" bordercolordark= "white" bordercolorlight= "black" width= "100% ">
    <tr>
    <td width= "252" bgcolor= "#CCCCCC ">
    <p><font face= "Arial" size= "2 "><B>Scanned File</b></font></p>
    </td>
    <td width= "195" bgcolor= "#CCCCCC" align= "right ">
    <p align= "left "><b><font size= "2" face= "Arial ">&nbsp;Status</font></b></p>
    </td>
    </tr>
    <tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">C:\Documents and Settings\Mark Bremer\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst=>[Subject: Happy New Year!][From: Andy I. Hess]=>postcard.exe</font></p>
    </td>
    <td width= "43%" align= "left ">
    <p><font face= "Arial" size= "2 ">Infected with: Worm.Generic.64491</font></p>
    </td>
    </tr><tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">C:\Documents and Settings\Mark Bremer\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst=>[Subject: Happy New Year!][From: Andy I. Hess]=>postcard.exe</font></p>
    </td>
    <td width= "43%" align= "left ">
    <p><font face= "Arial" size= "2 ">Deleted</font></p>
    </td>
    </tr><tr>
    <td width= "57% ">
    <p><font face= "Arial" size= "2 ">C:\Documents and Settings\Mark Bremer\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst</font></p>
    </td>
    <td width= "43%" align= "left ">
    <p><font face= "Arial" size= "2 ">Updated</font></p>
    </td>
    </tr>
    </table>
    </td>

    <td width= "10% ">
    <p>&nbsp;</p>
    </td>
    </tr>

    <tr>
    <td width= "458 ">
    <p><font face= "Arial "><span style= "font-size:11pt; "><B>&nbsp;</b></span></font></p>
    </td>
    <td width= "40% ">
    <p>&nbsp;</p>
    </td>
    <td width= "10% ">
    <p>&nbsp;</p>
    </td>
    </tr>

    <tr>
    <td width= "458 ">
    <p><font face= "Arial "><span style= "font-size:11pt; "><B>&nbsp;</b></span></font></p>
    </td>
    <td width= "40% ">
    <p>&nbsp;</p>
    </td>
    <td width= "10% ">
    <p>&nbsp;</p>
    </td>
    </tr>

    </table>
    <p>&nbsp;</p>

    </body>
    </html>
     

  3. to hide this advert.

  4. 2010/06/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    There was only one infected file, which was removed:
    =================================================================

    OTL Clean-Up
    Clean up with OTL:

    * Double-click OTL.exe to start the program.
    * Close all other programs apart from OTL as this step will require a reboot
    * On the OTL main screen, press the CLEANUP button
    * Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    ===============================================================

    Your computer is clean :)

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point.

    Turn off System Restore:

    - Windows XP:
    1. Click Start.
    2. Right-click the My Computer icon, and then click Properties.
    3. Click the System Restore tab.
    4. Check "Turn off System Restore ".
    5. Click Apply.
    6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
    7. Click OK.
    - Windows Vista and 7:
    1. Click Start.
    2. Right-click the Computer icon, and then click Properties.
    3. Click on System Protection under the Tasks column on the left side
    4. Click on Continue on the "User Account Control" window that pops up
    5. Under the System Protection tab, find Available Disks
    6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C: ")
    7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
    8. Click OK

    2. Restart computer.

    3. Turn System Restore on.

    4. Make sure, Windows Updates are current.

    [SIZE= "4"]5. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately![/SIZE]

    6. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    7. Run defrag at your convenience.

    8. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

    9. Please, let me know, how is your computer doing.
     
  5. 2010/06/29
    mbremer

    mbremer Inactive Thread Starter

    Joined:
    2010/06/21
    Messages:
    17
    Likes Received:
    0
    Followed last instructions - all is well with this today's Restart :)

    A heartfelt thank you broni for a very positive experience!

    Mark
     
  6. 2010/06/29
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Excellent!
    Good luck and stay safe :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.