View Single Post
Old 06-29-2009, 09:50 AM   #6 (permalink)
mas_pogi
Analyst, Security Team
 
mas_pogi's Avatar
 
Join Date: Apr 2008
Location: Tokyo, JP
Posts: 1,476
OS: Vista, Linux Mint


Re: Overclick.cn Spyware

hi.

Quote:
I guess I'm lucky. I don't use this computer for financial transactions, and as a matter of policy I don't own a credit card. I think that trojan was the thing that was hijacking my gmail for spamming people. I deleted that account, and I thought I got it with Malwarebytes.

Guess I was wrong, huh?
Kinda

Malwarebytes is also effective, like any other antispyware or Antivirus, they depend on the signature for them to recognize that file is malicious. So update your protection always.
Quote:
Anyway, again, thank you for being so speedy.

OK, I submitted [4]-Submit_2009-06-29_01.07.28 with this topic's address
.Thank you for the submission.

continuation...
-------------------------------------------------------------------------
Copy and paste the following text into Notepad:

Quote:
REGEDIT4

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\drivers\\svchost.exe"=-
Save this as "fixme.reg" . Choose to save as *all files and place it on your Desktop. It looks like this
Double-click fixme.reg
-------------------------------------------------------------------------

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2
  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    Code:
    :filefind
    *QQ.exe*
    *QQexternal.exe*
    *QQGame.exe*
    *QQPetDazzle.exe*
    *svchost.exe*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found at on your Desktop entitled SystemLook.txt

-------------------------------------------------------------------------

Please uninstall the following. Using windows ADD/REMOVE program at the control panel.

P2P program ( Perils of P2P File Sharing )

µTorrent
LimeWire PRO 4.16.6

Outdated java runtimes: (Older versions have vulnerabilities that malicious sites can use to exploit and infect your system)

J2SE Runtime Environment 5.0 Update 5

After you uninstall you outdated java, please download the Java(TM) 6 Update 14 here. Install it.

------------------------------------------------------------------------
I didn't see any antivirus installed, any reasons why? This is an open invitation for infection.

It can take as little as eight seconds to infect an unprotected computer.

Install this FREE AntiVirus program, update it, and run a full system scan.

Avira AntiVir Personal

When the scan is complete, click on the Report button. A log file will open. Save it in your desktop as Avira.txt. Please attach it in your next reply.

Do not install more than one antivirus program because they will conflict with each other. It is imperative that you update your antivirus software at least once a week (even more if you wish). If you do not update your antivirus software then it will not be able to catch new malware that may have come
out.


In your reply, please post


Systemlook.txt
Avira.txt <--attached


Mark
__________________
To accomplish great things, we must not only act, but also dream; not only plan, but also believe.
If I have been helping you and do not reply within 24 hours, please send me a message.
I'm a member of U.N.I.T.E and A.S.A.P

Last edited by mas_pogi; 06-29-2009 at 09:53 AM.
mas_pogi is offline