system
February 23, 2010, 8:32am
1
Hi everybody
I have a problem with a notbook (Vista).
When I see the shield Mail or shield web (avast 5), I notice that a lot of emails are sent (from an unknown adress to an unknow adress) and a lot of web sites are visited.
The consequence is if I want to send my email in the same time of this “automatic email”, my sending bug. Same think if I vist web site…
I noticed that because the Wifi led flash even if I don’t use the PC…
Avast don’t detect anything.
I try spybot, adware, hyjack and nothing…
???
If anyone have an idea to correct this…
Thank by advance and sorry for my poor english.
Pondus
February 23, 2010, 9:05am
2
Check your computer for Malware with
Malwarebytes Antimalware http://filehippo.com/download_malwarebytes_anti_malware/
after install click UPDATE and run cuick scan, click on REMOVE SELECTED to quarantine anything found
SUPERAntiSpyware http://filehippo.com/download_superantispyware/
Are cookies really spyware and are they dangerous?
http://www.superantispyware.com/supportfaqdisplay.html?faq=26
If anything is found come back and post the scan logs here
system
February 23, 2010, 9:09am
3
Thanks for your help
I test it this night and I tell you the result
system
February 24, 2010, 7:42am
4
Malwarebytes’ Anti-Malware found trojan.
Thanks for your advise
This is the log file (in french sorry) :
Malwarebytes’ Anti-Malware 1.44
Version de la base de données: 3781
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18882
23/02/2010 18:11:26
mbam-log-2010-02-23 (18-11-06).txt
Type de recherche: Examen rapide
Eléments examinés: 98752
Temps écoulé: 13 minute(s), 39 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 1
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 1
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
C:\Windows\System32\ntsdexts32.dll (Trojan.Agent) → No action taken.
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\Windows\System32\ntsdexts32.dll (Trojan.Agent) → No action taken.
Pondus
February 24, 2010, 9:28am
5
Your log say " No action taken. " so you need to rescan and click REMOVE SELECTED to quarantine the infection
and also run superantispyware
When done rescan and see if you come up clean / problem gone ?