|
Donation/Premium |
|
 |
|
|
|
|
|
|
|
 |
 |
| View previous topic :: View next topic |
| Author |
Message |
cattula
Cadet

 Joined: Feb 18, 2005 Posts: 1 Location: USA
|
Posted: Fri Feb 18, 2005 10:16 pm Post subject: Not Sure What This Is? Phishing?? |
|
|
Hi,
When my IE page loads, a command prompt screen appears and runs an executable (dd.exe) that is resident on my C: drive. I delete this, and it regenerates itself (the dd.exe). This program, when opened with Wordpad contains the following:
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN">
<html dir=ltr>
<head>
<style>
a:link {font:8pt/11pt verdana; color:FF0000}
a:visited {font:8pt/11pt verdana; color:#4e4e4e}
</style>
<META NAME="ROBOTS" CONTENT="NOINDEX">
<title>Page cannot be found</title>
<META HTTP-EQUIV="Content-Type" Content="text-html; charset=Windows-1252">
</head>
<body bgcolor="FFFFFF">
<table width="410" cellpadding="3" cellspacing="5">
<tr>
<td align="left" valign="middle" width="360">
<h1 style="COLOR:000000; FONT: 13pt/15pt verdana"><!--Problem-->Page cannot be found</h1>
</td>
</tr>
<tr>
<td width="400" colspan="2">
<font style="COLOR:000000; FONT: 8pt/11pt verdana">The page you are looking for might have been removed, had its name changed, or is temporarily unavailable.</font></td>
</tr>
<tr>
<td width="400" colspan="2">
<font style="COLOR:000000; FONT: 8pt/11pt verdana">
<hr color="#C0C0C0" noshade>
<p>Please try the following:
<ul>
<li>If you typed the page address in the Address bar, make sure that it is spelled correctly.<br>
</li>
<li>Open the <A HREF="http://59.158.112.135:818/">59.158.112.135</a>
home page, and then look for links to the information you want.</li>
<li>Click the <a href="javascript:history.back(1)">Back</a> button to try another link.</li>
</ul>
<h2 style="font:8pt/11pt verdana; color:000000">Problem: Connection timed out</h2>
<hr color="#C0C0C0" noshade>
</font></td>
</tr>
</table>
</body>
</html>
Is this some type of phishing? Any help would be appreciated.
David
|
|
| Back to top |
|
 |
OJ_did_it
Major
 Premium Member
 Joined: Nov 13, 2004 Posts: 1059
|
Posted: Sat Feb 19, 2005 2:56 am Post subject: |
|
|
| Quote: | <li>Open the <A HREF="http://59.158.112.135:818/">59.158.112.135</a>
home page, and then look for links to the information you want.</li> |
This part worries me somewhat. Were you trying to connect to a website in Japan, namely:
usen-59x158x112x135.ap-US02.usen.ad.jp
If not, then I would recommend cleaning up your computer as it might be infected with something. Here's some advice:
- Perform a free online scan by clicking HERE
- Alternatively, you can have McAfee Scan your system free by going Here
- Download and Install Spybot 1.3TX and Ad-Aware SE v1.05 by clicking Ad-Aware SE v1.05 and Spybot S/D
- Be sure to clean out your system regularly by using CCleaner, download CCleaner
- If you arent protected by an antivirus program, download and install and run one of these "FREE", highly rated packages:
AVG AntiVirus v7.0
AntiVir PE
Panda Platinum Internet Security
- Pick one of these free trojan scanners to scan for speecifically trojans:
Trojan Remover v6.3.4
Trojan Hunter v4.1
- Get this good malware cleaner to complement both Spybot and Ad-Aware: A2 Personal Edition
- Also, if you are not protected by a firewall, pick, download and install ONE of these highly popular firewalls:
Zone Alarm's Firewall
Sygate Firewall v5.6.2808
Outpost Firewall Pro v2.5.375.374
- Finally, make sure that your version of Windows is up to date by going to Microsoft's Update Microsoft Windows Update Page
These steps should make your system squeaky clean!
OJ
|
|
| Back to top |
|
 |
DreamingFox
Major
 Premium Member
 Joined: Aug 29, 2004 Posts: 1067
|
Posted: Sat Feb 19, 2005 3:41 am Post subject: |
|
|
OJ's advice is good.
Regarding whether or not you were being phished, I think there are three reasons why it is NOT a phish: first is because it opens a command prompt that runs an executable (but you haven't told us exactly what it DOES).
Second, because nothing in the code looks like it is requesting or prompting you for any kind of personal info.
And third, the numerical address points to: Registrant Organization of Internet Assigned Numbers Authority.
So I really don't think it's a phish. But what it IS, might be some kind of redirect, which could possibly be a pharming attempt gone awry and the self-renewing dd.exe could be a trojan.
Last edited by DreamingFox on Sat Feb 19, 2005 4:50 am, edited 1 time in total |
|
| Back to top |
|
 |
Oldfrog
Special Response Team
 Joined: Jun 27, 2004 Posts: 8576 Location: Deep in the Heart of Texas
|
Posted: Sat Feb 19, 2005 4:09 am Post subject: |
|
|
DreamingFox has hit this one on the head. No, it was not a phish for all of the reasons that she stated.
It does, however, look like some sort of hijack attempt that may have been malformed. I say this because the file keeps appearing even after it has been deleted.
In order to help you we need a HiJackThis log.
You will be posting the HiJackThis log in the HiJackThis forum: http://castlecops.com/f67-Trend_Micro_HijackThis_Logs.html
Read the HJT forum posting rules: http://castlecops.com/postt8864.html
Download HiJackThis from : http://castlecops.com/downloads-cat-14.html
Create a folder and unzip the HiJackThis download to the folder. Do not unzip the HiJackThis download to your Desktop or a Temp folder as it creates backup files for your protection and we do not want to run the risk of losing them.
Doubleclick "HijackThis.exe". First, update HiJackThis by pressing the "Config" button, then press "Misc Tools", followed by "Check for update online". If you downloaded an updated HJT, click "Yes" at the "Open the file?" prompt. If you did not update, press the "Back" button .
Press "Scan".When the scan is finished, use "Save Log" button and save the log as a text file. Its best to save your text file in the same folder as where you put HiJackThis.
DO NOT FIX ANYTHING YOURSELF UNTIL INSTRUCTED TO DO SO ONLY BY A CCSP EXPERT. MOST OF THE HJT LOG ENTRIES ARE NEEDED TO RUN YOUR COMPUTER. REMOVING THE NEEDED ENTRIES CAN CAUSE SERIOUS DAMAGE TO YOUR COMPUTER.
Post your log in the HiJackThis forum : http://castlecops.com/f67-Trend_Micro_HijackThis_Logs.html. Click "NewTopic" and simply copy/paste the HJT log into the textbox. Include the information requested in the HJT forum posting rules: http://castlecops.com/postt8864.html
Make sure your HJT log is posted only in the HiJackThis forum: http://castlecops.com/f67-Trend_Micro_HijackThis_Logs.html. _________________
MS MVP Security 2006-2008
|
|
| Back to top |
|
 |
|
|
|
You can post new topics in this forum You can reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You can attach files in this forum You can download files in this forum
|
Powered by phpBB © 2001 phpBB Group
|