xymon
+ Reply to Thread
Results 1 to 11 of 11

Thread: Please Decript

Hybrid View

  1. #1
    Join Date
    Jan 2005
    Posts
    623

    Please Decript

    Someone downloaded NetSky.Q (Wonderful little thing) and its emailing the following URL:

    mhtml:mid://000000*8/!cid:0**40*Mfdab4$*f*dL7807**870*8@57W8*fa70Re

    Can someone break down the different parts of this URL?
    [url=http://www.syntax******.info/tools/services.php]Speed Up Windows XP[/url]
    [url=http://www.syntax******.info/tools/ip.php]Get An Ip Address[/url]
    [url=http://www.syntax******.info/tools/base_converter.php]Base Converter[/url]
    --------------------------------
    [URL=http://www.boninroad.com/syntax******/]Old Site[/URL]
    [URL=http://www.syntax******.info]Comming Soon[/URL]

  2. #2
    Join Date
    Jan 2005
    Posts
    58
    That isn't a url

  3. #3
    Join Date
    Jul 2006
    Posts
    1
    Quote Originally Posted by SyntaX******
    Someone downloaded NetSky.Q (Wonderful little thing) and its emailing the following URL:

    mhtml:mid://000000*8/!cid:0**40*Mfdab4$*f*dL7807**870*8@57W8*fa70Re

    Can someone break down the different parts of this URL?

    SyntaX******:is it possible for you to email me? I have a question for you.

  4. #4
    Join Date
    Jan 2005
    Posts
    58
    That Last Link Is A Viurs!!!! It Downloades Several Viruses>>>do Not Open It Under Any Circumstances!!!!!!!!

    You Have Been Warned!

  5. #5
    Join Date
    May 2006
    Posts
    7
    Quote Originally Posted by *2*456
    That Last Link Is A Viurs!!!! It Downloades Several Viruses>>>do Not Open It Under Any Circumstances!!!!!!!!

    You Have Been Warned!
    What makes the link a virus? Are you referring to my post? Please explain.

  6. #6
    Join Date
    Jan 2005
    Posts
    58
    NetSky.P ring any bells to you? As well as other exploits it downloads.

    Take my advice do not open the link!

  7. #7
    Join Date
    May 2006
    Posts
    7
    Ok. Tested on another machine and you're right. Sorry for all the questions.

    I'm running Firefox on this machine. Makes sense that Trend wouldn't detect.

    Running a scan with Trend and still no instance. Deleted posts above just to be safe for everyone else.

    I guess what I'm looking at is the output from a spam filter that includes the email one would get. Amazing part is grinding through Google to arrive at that link.

    On the other system, Trend popped up with the detection in the Temp Internet files.
    Last edited by disregardme; 07-13-2006 at 04:18 PM.

+ Reply to Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts