Spam emails sent fr my AOL acct originating fr Yahoo

  1. I am having a really hard time with repeated spam emails being sent to my AOL address book looking as if I sent them. First go round, I found them in my outgoing box also, as I had auto add turned on in my aol sw. Turned that off and blocked all email addys and ip addys in the details of the emails sent. That stopped. They started again and this time none were showing in my sent box, but I am copied in the sends as well. So, I get the emails too from myself, to myself. In the details yahoo accounts are mostly what are showing before the diversion to my aol acct. I have run all the virus software I can find, Malware, Pest patrol, Adaware, Registry Repair, etc. I cannot stop it. I am stumped to the point of closing my AOL acct and I have so much business and bills etc tied to this acct it is a nightmare. I have had this screen name since 1996. Where do I turn? AOL does not give a crap. Is there a place that I can turn that prosecutes these ppl?
    AOL and Yahoo are both web-based emails. So they can be hacked from the internet. It is very difficult to track down this type of hack because it can be perpetuated from outside your computer by a mass mailing bot who sends mail to everyone in an address book. If you happen to be in someone else's address book, that's all it takes to get the mass mail going.

    If you would like us to check the system for malware, please follow the steps in the Preliminary Virus and Malware Removal thread HERE.

    When you have finished, leave the logs for review in your next reply .
    NOTE: Logs must be pasted in the replies. Attached logs will not be reviewed.

    Please do not use any other cleaning programs or scans while I'm helping you, unless I direct you to. Do not use a Registry cleaner or make any changes in the Registry.
    Ty so much and yes I do want your help. I need to get to my system I am on my iPad at the moment so I will be back ib a bit to start the process. I have had one person jump me about it and I told him that I feel strongly it is not in my computer but happening fr somewhere else.
    Okay. Post when ready.
    Had unexpected guests all day and I am worn out but I am looking forward to dealing with this with you tomorrow. This has been awful. One thing is there a charge and if so, how much? Thank you so much.
    No problem- take your time.
    I am a little bit confused. I recognize that once I started, this will take a minute and I will have to do it when I have more than I have right now. However, when I was doing the first part, the posts below it confused me. Do I skip the parts that are noted to skip?? I did the virus scan, and the temp folder removal and the malware scar, and was getting ready to do the emerg thingy but then I started reading below and it got crazy. Do I send the info to you in a reply, or a new post or etc etc, and do I skip number four...started hyperventilatng..hahaha...I run the malware sw all the time, none of that on here,and anti virus, none of that, and do maintenance emptying temps all the time,but I used your dl to do it. So, do I read ahead and follow suit or do the 8 step and put it all in a reply? Help me Jesus, head is spinning....for reals.
    You're making something easy confusing. Just follow the directions, paste the log in next reply. The rest is up to me! You keep all logs, questions and scans for this problem together in this thread!

    I need to see the results of the scans so you paste in the logs from Malwarebytes, GMER and DDS (2 logs for DDS). If you need more than 1 post to paste the logs, that's okay. Just keep it all together here.
    Ok, here they are:

    EMails are going out as if from me every single day. It is out of control. FYI, I have not been able to use system restore in some time. Nor will my cd player read home made cds, that probably is not related, but thought that I would throw that in just in case.
    You should not attempt to do a System Restore while I'm helping to clean the system. It could reinfect the system. I'll have you check the status of SR later- it might be turned off. We'll skip the CD problem for now.
    As for the email problem, I suggest you close the current email account, set up a new email account and generate a new password for it. If it was hacked from the outside, it's not going to get better.
    You have 3 antivirus programs running:
    Norton 360 (Norton Removal Tool)
    McAfee Security scan. (McAfee Removal)
    Lavasoft Ad-Watch Live! Anti-Virus
    This makes the system more vulnerable, not less. Please get this down to one AV program. I have left. Reboot the computer when finished
    Run Eset NOD32 Online AntiVirus scan HERE
    1. Tick the box next to YES, I accept the Terms of Use.
    2. Click Start
    3. When asked, allow the Active X control to install
    4. Disable your current Antivirus software. You can usually do this with its Notification Tray icon near the clock.
    5. Click Start
    6. Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is checked
    7. Click Scan
    8. Wait for the scan to finish
    9. Click on "Copy to Clipboard"> (you won't see the 'clipboard')
    10. Click anywhere in the post where you want the logs to go, the do Ctrl V. The log will be sent from the clipboard and pasted in the post.
    11. Re-enable your Antivirus software.
      NOTE: If you forget to copy to the clipboard you can find the log here:
      C:\Program Files\EsetOnlineScanner\log.txt. Please include this on your post.
    Download Combofix from HERE or HERE
    • Double click combofix.exe & follow the prompts.
    • ComboFix will check to see if the Microsoft Windows Recovery Console is installed. It is recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode if needed.
      **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
    • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
    • .Click on Yes, to continue scanning for malware
    • .If Combofix asks you to update the program, allow
    • .Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • .Close any open browsers.
    • .Double click combofix.exe[​IMG] & follow the prompts to run.
    • When the scan completes , a report will be generated-it will open a text window. Please paste the C:\ComboFix.txt in next reply..
    Re-enable your Antivirus software.
    1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
    2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
    3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.
    4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
    Hi, for what it is worth, my SR will not work, even though it is turned on. It never can finish, says it has some type of error, which it does not specify. As for the AOL account, I have changed the password repeatedly, and the emails are sent out whenever the conputer is off. I think that they are being generated elsewhere and being sent via redirect or diverting. I hesitate on closing the account since it is tied to so many billing accounts and other things, it would cause major issues for me unless I could figure all that out and got to all the accounts in question and change the emails there. I have had the email account over ten years. I have my own email name in my addy book so I get the spam email as well. They all only have one hyperlink in them selling viagra or something like that. Also, they only send them to a couple or three ppl at a time so as not to be flagged as spam. I do think that whether my account is open or not may not matter, but I defer to you to tell me this. It will cause a major problem to close it. I wonder if there is a way to just deactivate it for this period? I hate AOL, they are nonresponsive to issues.
    I am still waiting to hear fr you...


    I am sorry, I have run the ESET three times. It creates a file in my program files that has a log.txt after I run it but it has nothing there. However, the scan comes back good with no virus' found, it comes back clean. I do not know what else to do. I cannot imagine what I am going wrong. I turn the virus protection, all aspects of it, off, go to your link, click on it, check and uncheck the boxes you specify. After the undated files run, the scan runs. But at the end there is never a copy to clip board anything. Just a finish button and an offer to either buy the sw or sign up for the trial. Then nothing. I have no idea what else to do. However, it shows clean. I humbly await your next steps and I am going to run traces on the ip addys and turn some of these aholes into their providers as well. They have not sent anything from my address in a couple of days. Maybe they have moved on. As I understand it, their whole intention is to make money, and if no one is biting, they do move on.

    Still working on the ESET. But, here is the combofix

    Ok, I ran the ESET program and it did not give me the option at the end to copy to any clip board. It did create a file in my programs, and a log and it says there were no viruses found. When I tried ot run it again, to see why, it will not run it again, throws an error up saying it has run a scan within the past 24 and will not again. So, did I do something wrong? I will cut and paste that log if you like. I am stumped. Please do not think I am an ***** but please be aware that I do have MS and it affects me a lot cognitively. I have gone from a great career in financial planning to being cognitively disabled and as frustrating and troubling as this may be to you, it is more so to me. It is embarassing to even post this and know it is probably something that I did wrong. I will go to the next one.

    would it help you to see the details header of one of the emails? They are all different but they are all seemingly from Yahoo accts.
    oh and I did delete all the av programs except for norton360. I am running the sw you requested now, emailing you fr my iBad, since the 2nd out.


    Yes, I am running them...when it rains, it pours. I received notice that the state is auditing us for 2008 and 2009...Why? Just to be Aholes? umm hmm. I do think so. So, I have been in a tizzy finding that crap as they said we have only x number of days to get it to them, and I cannot get turbo tax to download 08 and for some reason the return is not in my paper work. I am having that GD problem where no matter what I do, when I am on IE, I get the request to dl flash player over and over. I have jninstalled it, reinstalled it, purged, cleaned, used the uninstaller that you are pointed to at the Vista page, nothing works and I think that is why I cannot open the turbo tax forms as they are in pdf form and it is messing up as well. I have uninstalled that one and reinsttaled it but I do not know if it will work again or not. I am telling you, I want to open a vein. Todays priorities: fax geek squad papers to Allstate to try to get my desk top replaced and get off of this lap top. do your thing and then work on the audit. do you have any extra hemlock?
    If you have something to add, please use the Edit feature to include it in your prior reply. I get email feedback for every reply.

    No, I don't want the email header. There is nothing I can do about it. The only thing I can do is look for malware on your system. If infection is found in emails, it will show on one of the logs.

    I understand the complications of giving up a long time email account. AOL had most of us chained to them for years. When I left them years ago and wrote to cancel and close my account, they threatened to give my email address to someone else. You will not get any help from them.

    IF you want my help in this matter, you need to go ahead with he scans. The logs will give me information that my help me help you. If you aren't going to do this, I will free up the time to help others.

    Have you don't anything about the multiple AV programs?
    Have you run the Eset scan?
    Have you run Combofix?

    I can help you troubleshoot the System Restore settings later. at this point, you should not be attempting to use the feature.
    I also waited a week to hear from you. Closed due to inactivity.
    Thread being reopened at member's request. Edit function was used to input the logs and they did not show when the thread was closed.
    Take any McAfee and Registry Repair process off of Startup menu> Uninstall any McAfee or Registry Repair entry in Add/Remove> Use Windows Explorer to access My Computer> Local Drive(C)> Programs> right click> Delete on the program folders.
    Sony Software Bundled with VAIO Computers: The applications listed HERE are currently identified as having compatibility issues after installing the Windows Vista operating system.
    Digsby InstallQ:> When it sounds too good to be true, it isn't! This process is insidious. Please see the information HERE about junk software and what this program does and will attempt.
    The following are being loaded from the Registry at Startup, the running in the background. None of these need to start on boot. Please tell if if you 1. Still use -or-2. No longer use:
    This does not mean you cannot use these programs or apps and it doesn't uninstall them. But none need to start on boot and run in the background.
    C:\unused AOLs to get off desktop> either delete or move to appropriate folders.
    You are using Telnet (2009): c:\windows\system32\telnet.exe. See this for WHY you shouldn't be using it!
    Please see if you can run this online virus scan:
    Run Kaspersky Online Scanner in Internet Explorer

    Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.
    • Click Accept and the web scanner will begin to load
    • If a yellow warning bar appears at the top of the browser, click it and choose Install ActiveX Control
    • You will be prompted to install an ActiveX component from Kaspersky, click Install
    • If you are prompted about another ActiveX control called Kaspersky Online Scanner GUI part then allow it to be installed also.
    • The program will launch and then begin downloading the latest definition files:
    • Once the files have been downloaded click on NEXT and then Scan Settings
    • In the scan settings make that the following are selected:
      [o] Scan using the following Anti-Virus database> Extended (if available otherwise Standard)
      [o] Scan Options: Scan Archives> Scan Mail Bases
    • Click OK
    • Now under select a target to scan:
      [o] Select My Computer
    • The program will start to scan your system.
    • Once the scan is complete, click on the Save as Text button and save the file to your desktop
    Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the license, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license is accepted, reset to 100%.
    For some reason, Karpesky will not run. It updated but when it tried to run, it stopped with a message about needing constant internet connection. So I went directly to the internet site and clicked to the free online virus scan and it said that it is on the process of being improved, I guess it is not available right now. It was not available to use, it would not allow a click. I spoke with AOLs fraud division. I don't know if you have ever heard of this but they said that a person will get your password and sign on to your email online. Then not sign out. Long as they do not sign out, regardless of the fact that you change your password, they have access to your acct. They send the emails and immediately delete them from your out box. I am a little skeptical, but they did something that would break any online open connection and reset everything. I still want to pursue this. What would I do about Kaspersky? Do you want me to wait a day or so and try again?

    unforfunately, I have had to be gone all day today to a baby shower then a childs birthday party so I hope to get on it tonight. I have just not been able to work on it yet, but I will tonight or in the morning. When it rains it pours...I have the audits for my income taxes also for 2008 and 2009...for the state of all things. That is really the dark side of hell.


    I am going to reply only to be sure you see this since I have so much info in the other reply from editing and I will ony edit this one going forward to add info to you and will reply to provide log info or other info as we discussed.

    In the past week, I did discover how to remove the pop up that I was getting to down load flash player, by diabling UAC. I just want you to know that because that will not show in the information you are seeing because I ran and posted the combofix info five days ago.
    That's fine. How are you doing with Kaspersky.
    Hey, I don't think that I do the right thing with the edit because you do not seem to see it. The kaspersky was being updated and would not run. I will try again. The message was something like, look for the new and better online scan. Also, AOL did a thing where they went in and made sure no one could have opened my acct via the web and not closed it thereby making my password changes of no consequence to them. But, they did it at noon to oneish on the 29th and one spam went out to three ppl around 3 and no more have since. Could that have been in the works somehow? I am hoping against hope.

    here is the message that I get when I try to get to the online scanner through IE

    Detect viruses on your computer with Kaspersky’s Online Virus Scanner. Our scanner searches your computer for the latest threats and lets you know which files are infected!

    The Kaspersky Online Virus Scanner is being updated and improved!

    But you don’t have to wait to protect your computer. Scan, detect and remove malware with a FREE 30-day trial of our latest, most advanced security protection.

    If I try to click on your hyper link, I cannot even open the site. it fails. I have no idea what to do. I counted 400 emails that were sent from my account last August when I could see them in my sent box. They were all crazy. When I caught it, and stopped them by blocks, etc. they stopped util this past Feb and they are sending a hyper link to a virus now and nothing is in my outbox and maybe 100+ have gone.

    What now?
  21. seeknpeace

    Remove all of the addons in the browser and add them back one at a time to find the offender.

    Check the Event Viewer for Error messages that corresponds the the Fatal Error message. Errors are time coded.

    If the problem continues, please post in the Windows BSOD forum.
