Anybody else been hit with the Russian spyware attack of VBS:Gamaredon-CM

Both our pc's at home have been attacked with this Russian malware.
Our AVG anti-virus caught it, but it has quarantined all my Thunderbird email accounts and a few other parts of our system.
How would we know? Does something pop up on the screen?
 
Yep AVG caught it for me. Thunderbird email, prefs.js. Could also impact Firefox browser and other Mozzilla based apps.

Yikes!!!

Subscribers  do not see these advertisements

 
AVG have definition and program updates this evening, worthwhile installing them of course.
 
Last edited:
Both our pc's at home have been attacked with this Russian malware.
Our AVG anti-virus caught it, but it has quarantined all my Thunderbird email accounts and a few other parts of our system.
Yes, it was picked up and quarantined by AVG.(y)

I only installed AVG about 10 days ago after I removed Kaspersky having been warned it could be a problem.
 
What are Thunderbird emails ?

Same as Outlook or Gmail ?
In simple terms Thunderbird is an email client for managing your email accounts.
Instead of having to log into multiple GMail \ Outlook \ etc email accounts you can link them all to Thunderbird and view \ use all your accounts in one screen \ desktop.
I've got about a dozen email accounts linked to Thunderbird so one login \ password instead of twelve! One of these accounts has 100's of masked accounts associated with it.
 
VBS:Gamaredon-CM was secured by AVG yesterday when I accessed Facebook! It happened twice then I guess Facebook got rid of it off their systems.
 
AFter doing more research on this I am inclined to believe that this is a false positive.

VBS is for visual basic script... .js files are javascript and are nothing to do with VBS.
Gamaredon are a spear fishing outfit who target the people they want to attack. Usually organisations. They do not do widespread attacks like this appears to be.

Due to this and the widespread nature of the reports that happened right after a signature file was updated I believe this is a false positive and I wouldn't worry about it.
 

Join us or log in to post a reply.

To join in you must be a member of MotorhomeFun

Join MotorhomeFun

Join us, it quick and easy!

Log in

Already a member? Log in here.

Latest journal entries

Back
Top