PC infection - How do I find which email was responsible ?

Downloaded approx 200 emails today - nothing out of the ordinary…

During the download (OE), an Avast warning popped-up to the effect of ‘infected file found, you
do not need to do anything else.’
2 minutes later, my PC was screwed up with a Trojan Infection !!!

All sorted now, but HOW do I find out which email was the culprit ?

Looked on the ‘Graph’ in the email-scanner - sure enough, 1 infected file ‘spike’ at the time of download.

Any suggestions appreciated, thanks all :wink:

You can inspect the log for the email scanner but I’m not sure it will tell you which email contained the infection that was detected. Also, I would suspect that the trojan that did get on the system came from another email containing something that Avast! did not have a detection signature for.

Hi
I don’t use OE but you may give this a try :

[i]Outlook Express stores email messages in DBX files which are located in the

%USERPROFILE%\Local Settings\Application Data\Identities{Identity-GUID}\Microsoft\Outlook Express\

  • You will need to adjust Windows Explorer settings to show hidden objects - the Local Settings folder is hidden from view with the default system settings.
  • {Identity-GUID} - Globally Unique Identifier (GUID) associated with the specific user identity, something like {1234567890-12AB-CD34-EF12-123456789ABC}.

Outlook Express stores message folders in separate .dbx files, one folder per file. The corresponding files are named according to their respective Outlook Express folder names.[/i]

Use the avast explorer extension.
Regards
Sarakael

Why should simply downloading an email result in an infection?

Check you computer with Secunia and update any insecure software.

Secunia Online Software Inspector (OSI)
Secunia Personal Software Inspector (PSI)

see the report files C:\ProgramData\Alwil Software\Avast5\report >>> Email shield, you’ll get the details there.

(if you’re on XP, it’s in documents and settings, all users, application data) hope you had the “generate report file” on in the mail shield expert settings, can’t tell if it’s on by default.

edit: your infected mail should be in “Chest” now anyway, you should see it there. But I’ve never seen it happen, so I don’t know in which form it would appear when quarantined, if it tells anything about sender etc…or just a mail file number with extension. Hmm…don’t restore it to tell :wink:

A big hug to everyone who has worked to help me get to the bottom of this :slight_smile:

Thanks to Logos, I located the culprit - here is an extract from the log :

  • avast! Real-time Shield Scan Report
  • This file is generated automatically
  • Started on: Saturday, August 14, 2010 10:35:45 AM

8/14/2010 10:52:07 AM Incoming email ‘H4H Home Dedication August 14th’ From: “Lindsey Schmidt” unhingeds4685@rogerjtreglown.com, To: XXXX@XXXXXXXX.co.uk|>2009-2010 Driving Directions.zip#3662504802|>2009-2010 Driving Directions.exe [L] Win32:Spyware-gen [Spy] (0)
While moving file to chest, error occurred: The system cannot find the file specified

Thankfully, I do not recognise the sender !

I keep my avast software up to date and download new rules and definitions daily.

Cheers guys.