Anybody else been hit with the Russian spyware attack of VBS:Gamaredon-CM (1 Viewer)

irnbru

LIFE MEMBER
Jun 27, 2013
13,515
31,144
Glasgow
Funster No
26,684
MH
Benimar 264
Exp
11 yrs
Both our pc's at home have been attacked with this Russian malware.
Our AVG anti-virus caught it, but it has quarantined all my Thunderbird email accounts and a few other parts of our system.
How would we know? Does something pop up on the screen?
 
Nov 5, 2019
902
1,761
Arkley, Barnet, UK
Funster No
66,632
MH
Corinium Duo
Exp
Relative newbie
Yep AVG caught it for me. Thunderbird email, prefs.js. Could also impact Firefox browser and other Mozzilla based apps.

Yikes!!!

Subscribers  do not see these advertisements

 
Nov 5, 2019
902
1,761
Arkley, Barnet, UK
Funster No
66,632
MH
Corinium Duo
Exp
Relative newbie
AVG have definition and program updates this evening, worthwhile installing them of course.
 
Last edited:

icantremember

LIFE MEMBER
Sep 2, 2010
8,343
17,567
Near to Watton in Norfolk
Funster No
13,512
MH
Hymer T-SL668
Exp
since 2005
Both our pc's at home have been attacked with this Russian malware.
Our AVG anti-virus caught it, but it has quarantined all my Thunderbird email accounts and a few other parts of our system.
Yes, it was picked up and quarantined by AVG.(y)

I only installed AVG about 10 days ago after I removed Kaspersky having been warned it could be a problem.
 

Gellyneck

LIFE MEMBER
Jun 5, 2014
9,272
18,425
Scotland
Funster No
31,836
MH
C Class
Exp
More than toes wet now!
What are Thunderbird emails ?

Same as Outlook or Gmail ?
In simple terms Thunderbird is an email client for managing your email accounts.
Instead of having to log into multiple GMail \ Outlook \ etc email accounts you can link them all to Thunderbird and view \ use all your accounts in one screen \ desktop.
I've got about a dozen email accounts linked to Thunderbird so one login \ password instead of twelve! One of these accounts has 100's of masked accounts associated with it.
 
Feb 27, 2011
14,778
76,366
UK
Funster No
15,452
MH
Self Build
Exp
Since 2005
AFter doing more research on this I am inclined to believe that this is a false positive.

VBS is for visual basic script... .js files are javascript and are nothing to do with VBS.
Gamaredon are a spear fishing outfit who target the people they want to attack. Usually organisations. They do not do widespread attacks like this appears to be.

Due to this and the widespread nature of the reports that happened right after a signature file was updated I believe this is a false positive and I wouldn't worry about it.
 

Join us or log in to post a reply.

To join in you must be a member of MotorhomeFun

Join MotorhomeFun

Join us, it quick and easy!

Log in

Already a member? Log in here.

Latest journal entries

Funsters who are viewing this thread

Back
Top