Author Topic: <iframe> tag found, it may be dangerous  (Read 15100 times)

0 Members and 1 Guest are viewing this topic.

1cards

  • Guest
<iframe> tag found, it may be dangerous
« on: June 19, 2009, 10:52:10 PM »
I must have an email infection. Help!


Avast warns me every 15 seconds or something similar to the following:
 
<iframe> tag found, it may be dangerous
There are too many identical e-mails in appointed time


Sender:  invitations AT hi5.com
Recipient:  jeffgordon AT postnet.com
Subject:  Jessica would like to be your friend on hi5!
« Last Edit: June 19, 2009, 11:58:22 PM by 1cards »

1cards

  • Guest
Update Re: <iframe> tag found, it may be dangerous
« Reply #1 on: June 19, 2009, 11:15:24 PM »
Now Avast says:

<iframe> tag found, it may be dangerous
There are too many identical e-mails in appointed time


Sender:  invitations AT hi5 .com
Recipient:  jclions AT hotmail.com
Subject:  Jessica would like to be your friend on hi5!<iframe> tag found, it may be dangerous
There are too many identical e-mails in appointed time


Sender:  invitations AT twitter.com
Recipient:  jclions AT hotmail.com; jclioness AT hotmail.com
Subject:  Your friend invited you to twitter!
« Last Edit: June 19, 2009, 11:57:47 PM by 1cards »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89287
  • No support PMs thanks
Re: <iframe> tag found, it may be dangerous
« Reply #2 on: June 19, 2009, 11:26:30 PM »
The iframe tag is a powerful tool and one usually used on web pages to deliver dynamic content, not normally in emails though and then usually for the delivery of adverts.

It is also the means being used by the latest site hacks to run malicious code when you arrive at a site which has been hacked, so it is easy to do this in an email as well.

This does appear that you have a hidden/unidentified trojan spambot on your system.

If you haven't already got this software (freeware), download, install, update and run it and report the findings (it should product a log file).

 
Don't worry about reported tracking cookies they are a minor issue and not one of securty, allow SAS to deal with them though. - See http://en.wikipedia.org/wiki/HTTP_cookie.

If any files are found infected relating to trojan spambots, etc. before letting these programs deal with them send a copy to the chest and then email to Alwil software as possible undetected malware to help improve detections.

####
Add the file to the User Files (File, Add) section of the avast chest (if it isn't already there) where it can do no harm and send it from there. A copy of the file/s will remain in the original location, so you will need to take further action and can remove/rename that.
 
Send it from the User Files section of the chest (select the file, right click, email to Alwil Software). It will be uploaded (not actually emailed) to avast when the next avast auto (or manual) update is done.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

1cards

  • Guest
Re: <iframe> tag found, it may be dangerous
« Reply #3 on: June 19, 2009, 11:35:19 PM »
DavidR,

Thanks for the info. I have downloadand and started a scan with MalwareBytes. I will post the results.

Cards1

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: <iframe> tag found, it may be dangerous
« Reply #4 on: June 19, 2009, 11:43:32 PM »
Hi 1 cards,

You should not place live links here. Break it in a way it cannot be clicked, for instance:
invitations at hi5 dot com etc.
This is an example: http://securitytracker.com/alerts/2006/Feb/1015665.html
How to remove it from a website: http://mycodings.blogspot.com/2009/05/remove-malwareiframeinf-virus-from-your.html

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

1cards

  • Guest
Re: <iframe> tag found, it may be dangerous
« Reply #5 on: June 20, 2009, 12:00:59 AM »
polonus,

I have edited the so there are no live links. Thanks!

1cards

1cards

  • Guest
Re: <iframe> tag found, it may be dangerous rmoved with MalwareBytes
« Reply #6 on: June 20, 2009, 02:53:58 AM »
I successfully downloaded and removed the spambot with MalewareBytes.

Thanks!

1cards

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89287
  • No support PMs thanks
Re: <iframe> tag found, it may be dangerous
« Reply #7 on: June 20, 2009, 03:47:52 AM »
That's good, though it would have been nice to first have posted the log and if possible saved a copy to send to avast to improve detection of this spambot.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

1cards

  • Guest
Re: <iframe> tag found, it may be dangerous
« Reply #8 on: June 20, 2009, 04:56:04 AM »
It is quarantined. I do not know if I can retrieve it. Log follows:

Malwarebytes' Anti-Malware 1.38
Database version: 2309
Windows 6.0.6001 Service Pack 1

6/19/2009 7:21:53 PM
mbam-log-2009-06-19 (19-21-53).txt

Scan type: Full Scan (C:\|H:\|J:\|)
Objects scanned: 563854
Time elapsed: 2 hour(s), 45 minute(s), 2 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 56

Memory Processes Infected:
C:\Users\admin\AppData\Local\Temp\Temp1_Postcard.zip\document.pdf                                                            .exe (Trojan.Dropper) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\windows audio server (Trojan.Dropper) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Users\admin\AppData\Local\Temp\Temp1_Postcard.zip\document.pdf                                                            .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Users\admin\AppData\Local\Temp\sndmixer32.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Absolute Video Converter 6.2.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Ad-aware 2009.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Adobe Acrobat Reader keygen.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Adobe Photoshop CS4 crack.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Alcohol 120 v1.9.7.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\AnyDVD HD v.6.3.1.8 Beta incl crack.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Avast 4.8 Professional.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\AVS video converter6.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Smart Draw 2008 keygen.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Sony Vegas Pro 8 0b Build 219.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Sophos antivirus updater bypass.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Super Utilities Pro 2009 11.0.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Motorola, nokia, ericsson mobil phone tools.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Myspace theme collection.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Nero 9 9.2.6.0 keygen.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Norton Anti-Virus 2009 Enterprise Crack.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\G-Force Platinum v3.7.5.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Google Earth Pro 4.2. with Maps and crack.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Grand Theft Auto IV (Offline Activation).exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Internet Download Manager V5.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\K-Lite codec pack 3.10 full.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\K-Lite codec pack 4.0 gold.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Total Commander7 license+keygen.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Tuneup Ultilities 2008.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Ultimate ring tones package1 (Beethoven,Bach, Baris Manco,Lambada,Chopin, Greensleves).exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Ultimate ring tones package2 (Lil Wayne - Way Of Life,Khia - My Neck My Back Like My Pussy And My Crack,Mario - Let Me Love You,R. Kelly - The Worlds Greatest).exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Ultimate ring tones package3 (Crazy In Love, U Got It Bad, 50 Cent - P.I.M.P, Jennifer Lopez Feat. Ll Cool J - All I Have, 50 Cent - 21 Question).exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\BitDefender AntiVirus 2009 Keygen.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Opera 9.62 International.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\PDF password remover (works with all acrobat reader).exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Perfect keylogger family edition with crack.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Power ISO v4.2 + keygen axxo.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\CheckPoint ZoneAlarm And AntiSpy.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\CleanMyPC Registry Cleaner v6.02.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Daemon Tools Pro 4.11.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Divx Pro 6.8.0.19 + keymaker.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Download Accelerator Plus v8.7.5.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Download Boost 2.0.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\DVD Tools Nero 9 2 6 0.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Kaspersky Internet Security 2009 keygen.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\LimeWire Pro v4.18.3.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Magic Video Converter 8 0 2 18.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Microsoft Office 2007 Home and Student keygen.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Microsoft Visual Studio 2008 KeyGen.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Microsoft.Windows 7 Beta1 Build 7000 x86.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\VmWare keygen.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Winamp.Pro.v6.53.PowerPack.Portable+installer.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Windows 2008 Enterprise Server VMWare Virtual Machine.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Windows XP PRO Corp SP3 valid-key generator.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Windows2008 keygen and activator.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\WinRAR v3.x keygen RaZoR.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\downloads\Youtube Music Downloader 1.0.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Users\admin\downloads\Setup.exe (Adware.Zango) -> Quarantined and deleted successfully.
c:\Users\admin\AppData\Local\Temp\CD18.tmp (Heuristics.Malware) -> Quarantined and deleted successfully.

micky77

  • Guest
Re: <iframe> tag found, it may be dangerous
« Reply #9 on: June 20, 2009, 07:31:35 AM »
Your MBAM log is full of cracks and keygens. People like you do not deserve help.What is the mentality of a person who ,in order to protect their pc , uses a keygen. In my eyes, you are no better than a common thief. You even have what looks like a crack for Avast ( c:\downloads\Avast 4.8 Professional.exe (Trojan.Dropper) -> Quarantined and deleted successfully. ) Yet you have audacity to come here asking for help.

YoKenny

  • Guest
Re: <iframe> tag found, it may be dangerous
« Reply #10 on: June 20, 2009, 10:43:51 AM »
People that like cracks and keygens deserve all the malware that comes along with them.  ;)

Offline .: L' arc :.

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1780
  • Thinking with Portals
Re: <iframe> tag found, it may be dangerous
« Reply #11 on: June 20, 2009, 01:21:03 PM »
-= By the way, a free version of malwarebytes & avast is available so you wont have the need for cracks.. There are lots of freewares that can act as good as the paid..

-= Those cracked sort of things might cause greater damage so it would be better to uninstall them at once..
Windows 7 (64-bit) Home Premium SP1
avast! 9 RC1

1cards

  • Guest
Re: <iframe> tag found, it may be dangerous
« Reply #12 on: June 24, 2009, 05:57:51 AM »
I do not know what a keygen or crack is. Why would one need a keygen or a crack for Adobe Acrobat Reader? It is free. Are these part of the spam bot? I do not have most of these programs on my computer, Norton Anti-Virus 2009 Enterprise, for example. I dislike Norton that is why I bought Avast Professional. Likewise I have no ringtones. Most of these I do not recoginize. Please explain this to me micky77, YoKenny and -= Fenrir =-
« Last Edit: June 24, 2009, 06:01:49 AM by 1cards »

1cards

  • Guest
Re: <iframe> tag found, it may be dangerous
« Reply #13 on: June 24, 2009, 06:01:20 AM »
I would not post the quarantine log if I were stealing something!

Offline .: L' arc :.

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1780
  • Thinking with Portals
Re: <iframe> tag found, it may be dangerous
« Reply #14 on: June 24, 2009, 07:55:50 AM »
-= The log showed that you actually downloaded lots of cracks & keygens.. Kaspersky, BitDefender, avast, MBAM, etc.. If you are not really sure who/what did this.. Better check installed softwares on your pc.. or see if you have any active torrents or a P2P process.. Still, I doubt it, processes like those are initiated by the user..
Windows 7 (64-bit) Home Premium SP1
avast! 9 RC1