Board logo

How to remove email virus???
russbost - 19/9/11 at 12:39 PM

I believe my email account has somehow been infiltrated as apparently I have been sending the message below to all members on my contacts :-

Dear friend,
Just got an Nikon D80 10.2MP Digital SLR Camera on this website: abuby.com Much cheaper than the market price. If you want to buy digital products, just order online and you will get the high quality products.
Hope you can enjoy shopping!
Thanks & Regards!

I have received loads of similar messages recently from a number of different sources - obviously people who've similarly got infiltrated, but can't work out how my pc has been infected as I've not opened any attachments & I run malawarebytes, Avast & windows defender regularly. Malawarebytes didn't turn anything up in a regular scan but did on a boot scan all of which I've deleted, but I think i still have the infection as when someone emails me I get a copy of the above message appear in my inbox as though I've sent it, but to the address of the person whose just emailed me - if you can follow that.

Any ideas as to how I can get rid - I'm using Vista & windows Outlook Express BTW.

This sort of thing just drives me nuts - it's such a total waste of everyones time!!!


britishtrident - 19/9/11 at 12:51 PM

Avira do a free bootable rescue CD it boots up in its' own Linux system so is free to scan the whole Windows HD.

Download the ISO file and burn it to cd then boot from the cd.



Avria Rescue Boot Cd Iso file


mantisgb - 19/9/11 at 01:11 PM

It looks like your email account is with Google - if this is the account that has been sending the Spam messages, then change your password - if you haven't already. It is at least as likely an account compromise (your Google account) as a virus having infected your PC. Once you have changed your password, however, I would also look at searching for key loggers on your PC as well as general scans for viruses and malware - there is no point changing your Google password if the key logger simply captures the new one! Most major AV vendors offer rescue scan software, so run at least 2-3 of these from different vendors...

that said... In my experience, the safest way to be sure that a home PC is free from viruses (especially when you've clear evidence of some form of compromise) is to re-install the system. Many PC makers include re-install partitions which make it relatively easy to re-install Windows, and then immediately install AV and enable Windows firewall as a minimum.

hth, Keith


jossey - 19/9/11 at 01:12 PM

more likely they have your password for your email not that they are using your pc.

I can get you a trial key for sophos or something if it helps.

If you need any help drop me a email on davidj*sec-1.com

* = @


russbost - 19/9/11 at 03:01 PM

Brilliant - you were spot on (I think!!!) I've checked my googlemail account & the only people I've unintentionally spammed are my contacts on there, NOT my contacts list on Outlook, so I've changed my account password & deleted the contact list on there (I only usually use contacts from Outlook).

Can anyone think of anything else I should do???

As usual many thanks for assistance! I could have wasted hours on this!!!


eddie99 - 19/9/11 at 03:33 PM

Yup i got your email