Suspicious email attachment.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by aSILENTfire, Apr 10, 2012.

  1. aSILENTfire

    aSILENTfire Private E-2

    I got an email attachment in Gmail, it looks like this:

    04928545
    1K View Download

    When I hit View it goes to a blank page, but I think there is a script running and with the Noscript addon for Firefox I see that its blocking a Shockwave Flash object, but maybe that's something else..

    I downloaded it and opened it with notepad, here is what is say (without outer quotes):

    "<meta http-equiv="refresh" content="0; url=http://dsvtyr.ponderunnamed.ru?xcbvam.kr">"

    I don't know HTML so could someone tell me what this is?

    Thanks!
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Which forum do you wish to work with? Us or bonweb?

    In any case if you choose to work with us, I cannot go into the ins and outs of what that attachment's code is all about. I would just have you delete it away and then have you run these below procedures.


    READ & RUN ME FIRST. Malware Removal Guide
     
  3. aSILENTfire

    aSILENTfire Private E-2

    What is bonweb?
     
  4. aSILENTfire

    aSILENTfire Private E-2

    My laptop is putting worms on peoples SD cards

    My sister put an SD card from her camera into my laptop to share some pictures, and later she scanned it with Norton and it showed it having some kind of Worm. (She didn't remember details)

    I had a Gateway a while back and my network hijacked it before I even willingly connected to the internet and was putting viruses on it and sending them out in USB keys, again I have no idea what they were as only other peoples computers can recognize them.

    And with whatever I have it can take over antiviruses, sometime my Malwarebytes protection gets shut off and more commonly my Zone Alarm settings change. When I had Norton it would say that any file is trusted and verified as safe, I mean every file on the machine including malware, even if I just made the file.

    I suppose it is near impossible to know what is doing this without the name of the worm found, but I hope not.

    Thanks
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  6. aSILENTfire

    aSILENTfire Private E-2

    Yeah sorry about cross-posting, I was comparing forums to see which I want to be active in. I've already eliminated most forums and this is definitely one of the best support forums in the cosmos.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, I see they closed the thread. Therefore, if you wish to work with us, please follow the very instructions I provided you with in post number 2. Attach the requested logs once ready. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds