View Single Post
Old 06-27-2009, 09:32 PM   #2 (permalink)
mas_pogi
Analyst, Security Team
 
mas_pogi's Avatar
 
Join Date: Apr 2008
Location: Tokyo, JP
Posts: 1,476
OS: Vista, Linux Mint


Re: Overclick.cn Spyware

hi.

Seems you already ran Combofix.

Quote:
Originally Posted by Ried View Post
Why we don't ask you to run ComboFix from the onset

As stated by the author of ComboFix:

ComboFix is a very powerful tool which when improperly used may render your machine to a doorstop.

We first need to verify if there's any rootkits present and how they could affect our tools. DDS & GMER are preliminary scans. We use their logs to map our strategy for attack.

With these logs we can determine the infections present & decide whether to deploy ComboFix.

We need to have gmer log first before we start fixing your
computer. Something must be stopping gmer to complete its scans.

If you have the gmer.exe now, delete it please.

Redownload GMER from here:
http://www.gmer.net/files.php

Unzip it to the desktop.

---------------------------------
Open Notepad and copy/paste the contents in the code box below, into Notepad.
Code:
@copy /y gmer.exe gamer.exe
@Start gamer.exe -protect
Save this as bio.bat Choose to "Save type as - All Files"

It should look like this:

Place the batch next to gmer & double click bio.bat to launch it.

--------------------------------------------------------------------------


When the program opens and click on the Rootkit tab.
Make sure all the boxes on the right of the screen are checked, EXCEPT for 'Show All'.
Click on Scan.
Once done click on the [Save..] button, and in the File name area, type in "ark.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop.
Attach that ARK.txt in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries


Mark
__________________
To accomplish great things, we must not only act, but also dream; not only plan, but also believe.
If I have been helping you and do not reply within 24 hours, please send me a message.
I'm a member of U.N.I.T.E and A.S.A.P
mas_pogi is offline