CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

epostcards scam query

 
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Hecky

Cadet
Cadet


Joined: Jul 29, 2007
Posts: 4
Location: UK

PostPosted: Sun Jul 29, 2007 5:50 pm    Post subject: epostcards scam query
Reply with quote

Hi, I`ve just registered so am a newbie – as such I`m not too sure where to post my query if indeed I can – no doubt some kind soul will point me in the right direction. My query concerns the epostcards scam (Storm Trojan?) I fell prey to this the other day (not the email with attachment, but the one that directs you to a web page). I`m usually careful about such emails but this particular one led me to believe it was real (long story so won`t bother you with it) so I opened it and clicked on the web link – it came up as ‘Page not Displayed’. I tried again with the same result, then gave up. I since found out that it`s a scam to get you to go to a certain website where a Trojan (or some such equally nasty) gets downloaded to your pc. I cannot find out anything much about this or even get to know how I may find out whether my pc has been infected. An Ad-Aware scan and my AVG (free) scan both reveal nothing. AVG scans my pc every day. I use ZA Firewall (free). My OS is Windows XP Service Pack 2 and all critical patches are up to date. I`ve not noticed anything untoward with my pc (so far). Any views/advice/help would be gratefully received. Cheers. Hecky.

Back to top
View users profile Send private message
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1813
Location: Japan
Premium

PostPosted: Mon Jul 30, 2007 3:36 am    Post subject:
Reply with quote

Welcome to the CC forum.

I think your question fits the title of this forum well, so it's quite OK to post it here.

Most browsers will ask you to confirm a download and prompt you to either execute the download, or save it to a location you specify. If that hasn't happen in your case, chances are that you aren't infected.

However, we better don't take any chances and make sure that you are clean (your computer, of course).

First, go to the Malware Removal and Prevention section at the CC Wiki, by clicking this link http://wiki.castlecops.com/MRP. Follow the instructions carefully, but skip what you have already done.

If you are still suspicious that your system may be infected, download and run HijackThis, then post the resulting log in this forum CastleCops Link/f67-Hijackthis_Spyware_Viruses_Worms_Trojans_Oh_My.html

Please read this post before actually posting the HJT log CastleCops Link/t102301-Hijackthis_Guidelines_Read_Before_Posting.html - make sure that your read and follow this part of the post

Quote:
DO NOT FIX ANYTHING YOURSELF NOW. JUST WAIT FOR QUALIFIED STAFF TO HAVE A LOOK AT YOUR LOG. MOST OF THE LISTED ENTRIES ARE NEEDED; REMOVING THEM CAN CAUSE SERIOUS DAMAGE.

Back to top
View users profile Send private message Visit posters website
Hecky

Cadet
Cadet


Joined: Jul 29, 2007
Posts: 4
Location: UK

PostPosted: Mon Jul 30, 2007 5:44 pm    Post subject:
Reply with quote

Hey, thanks for this. Feeling more positive now.

Hecky

Back to top
View users profile Send private message
honeypotspamtrap

Cadet
Cadet


Joined: Aug 12, 2007
Posts: 1
Location: USA

PostPosted: Sun Aug 12, 2007 4:25 pm    Post subject:
Reply with quote

wrote:
Hey, thanks for this. Feeling more positive now.

Hecky
You may want to try f-prot blacklight root toolkit remover. It is free and certainly can not hurt at this point.

http://www.f-secure.com/blacklight

/http://www.f-secure.com/blacklight/


_________________
honeypot.honeypot@gmail.com
Back to top
View users profile Send private message Visit posters website
Spockish

Captain
Captain


Joined: May 19, 2006
Posts: 334


PostPosted: Tue Aug 14, 2007 1:57 pm    Post subject:
Reply with quote

If you got a "page cannot be displayed" error, then you are not infected.

If the link to the malware works, you will see a page with a windows media player window embedded in it and you will be promoted to download a .exe file.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer