Author Topic: I got a suspicious email, and i might be infected  (Read 4106 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
I got a suspicious email, and i might be infected
« on: August 01, 2015, 07:37:25 AM »
I got a suspicious email yesterday, the name of the email was AUTOCAD 2016 products ( I am selling CAD/CAM )PTC ,Solidworks & Bentley Products ,PCB ,ADOBE ,CORLE ,,Electronic ,Architecture. I have never used Autocad, so it looks suspicious to me. The email hadn't gone into trash, so it got opened automatically when i opened the Windows 8.1 outlook. When the email opened my hard drive activated for two seconds. I think i might maybe infected. I ran a startup scan, but avast found nothing.
« Last Edit: August 01, 2015, 07:42:54 AM by Jojo4 »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: I got a suspicious email, and i might be infected
« Reply #1 on: August 01, 2015, 07:39:58 AM »
Attach your basic diagnostic logs. (MBAM, FRST and aswMBR)
Instructions: https://forum.avast.com/index.php?topic=53253.0
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: I got a suspicious email, and i might be infected
« Reply #2 on: August 01, 2015, 08:48:21 AM »
Hello, here are the logs you asked for.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: I got a suspicious email, and i might be infected
« Reply #3 on: August 01, 2015, 09:04:00 AM »
OK, now you've to wait a bit...
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: I got a suspicious email, and i might be infected
« Reply #4 on: August 01, 2015, 12:52:14 PM »

Could you let me know of any problems you are experiencing

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
2015-07-24 19:00 - 2014-11-22 14:29 - 00000000 __SHD C:\Users\joonas\AppData\Local\EmieBrowserModeList
2015-07-24 19:00 - 2014-09-14 18:39 - 00000000 __SHD C:\Users\joonas\AppData\Local\EmieUserList
2015-07-24 19:00 - 2014-09-14 18:39 - 00000000 __SHD C:\Users\joonas\AppData\Local\EmieSiteList
2015-07-04 09:34 - 2014-09-24 15:38 - 00000000 ____D C:\ProgramData\boost_interprocess
AppInit_DLLs-x32: �ȃ睁摎ԃ㶹库圗ﮘﺧ�뉰ﺨ�놀ﺨ�direȃ睁摎Փ㶹库圗Default Rule => "�ȃ睁摎ԃ㶹库圗ﮘﺧ�뉰ﺨ�놀ﺨ�direȃ睁摎Փ㶹库圗Default Rule" File not found
IFEO\SppExtComObj.exe: [Debugger] C:\Windows\SECOH-QAD.exe
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

REDACTED

  • Guest
Re: I got a suspicious email, and i might be infected
« Reply #5 on: August 01, 2015, 05:27:19 PM »
I have not been experiencing anything yet. I thought i might be infected. Is it possible to forward the email to some avast scanning lab, so they could check it for viruses?
Here is the fixlog:
« Last Edit: August 01, 2015, 05:30:02 PM by Jojo4 »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: I got a suspicious email, and i might be infected
« Reply #6 on: August 01, 2015, 05:42:29 PM »
Did it come with a attachment?

If so you can save attachment (dont open it) and upload here    www.virustotal.com   /   www.metascan-online.com
If tested before, click rescan for a fresh result
If detected, delete mail and attachment ...... if suspicious and from somone you dont know, delete even if not detected

You can test mail here   http://info.contactology.com/check-mqs
« Last Edit: August 01, 2015, 05:44:26 PM by Pondus »

REDACTED

  • Guest
Re: I got a suspicious email, and i might be infected
« Reply #7 on: August 01, 2015, 05:43:27 PM »
No, the message was completely empty... No text or aything. Maybe code can't be seen.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: I got a suspicious email, and i might be infected
« Reply #8 on: August 01, 2015, 06:17:45 PM »
Nothing evident that I could see

REDACTED

  • Guest
Re: I got a suspicious email, and i might be infected
« Reply #9 on: August 01, 2015, 06:28:35 PM »
Maybe it's a new type of virus... But i swear, that when it opened something copied on to my computer.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: I got a suspicious email, and i might be infected
« Reply #10 on: August 01, 2015, 07:39:35 PM »
Based on time stamps nothing unknown was installed or copied to the computer

REDACTED

  • Guest
Re: I got a suspicious email, and i might be infected
« Reply #11 on: August 10, 2015, 05:53:21 PM »
Ok, turns out i had a virus... I kept an encrypted file with the passwords of my website on it, and my website just got hacked...

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: I got a suspicious email, and i might be infected
« Reply #12 on: August 10, 2015, 06:24:53 PM »
If the key was encrypted then the only way it can be copied is when you decrypt it....  Are you sure the website was not hacked in another way ? 

Is your website security stronger than this  http://www.bbc.co.uk/news/uk-33837040

REDACTED

  • Guest
Re: I got a suspicious email, and i might be infected
« Reply #13 on: August 10, 2015, 06:50:42 PM »
I i am the creator of a cooperative called Dynavio, and someone accessed the domain hosting control panel. I have my site hosted at shellit, and the guy changed the nameservers from shellit to domaincontrol.com

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: I got a suspicious email, and i might be infected
« Reply #14 on: August 10, 2015, 06:58:30 PM »
maybe you should consider help from these guys  https://sucuri.net

it is not free   https://sucuri.net/website-antivirus/signup