Thank you very much
Thank you very much
- - - Updated - - -
Thank you very much
Thank you very much
Finally found the origin of this crap.
Everyone who downloaded this crap should change all his passwords and other stuff.
MSI package (QPST.2.7.422.msi) was embedded/tampered with qualcomm.exe which is a .NET based malware that logs your keystrokes and sends it to attacker's location.
How to delete the actual malware from your system?
Look at the startup from msconfig or CCleaner, there should be file called qualcomm.exe thats configured to start everytime windows starts. Delete both registry and file.
Malware log that includes all your keystrokes.
In XP,
C:\Documents and Settings\Administrator\Application Data\dclogs
there should be file called "2014-01-11-7.dc
if you open that file with Notepad
:: Run (3:01:51 AM)
Script kiddie. NET Based malware, huh?[ESC]
:: Program Manager (3:02:14 AM)
e
:: All Users (3:02:18 AM)
[DOWN]
[DOWN]
[DOWN][DOWN]
:: Documents and Settings (3:02:19 AM)
[UP]
:: Administrator (3:02:28 AM)
[DOWN][DOWN][DOWN][DOWN][DOWN][DOWN][DOWN][DOWN][DOWN][DOWN]
[DOWN][DOWN][DOWN][DOWN][DOWN][DOWN][DOWN][DOWN][DOWN][DOWN][DOWN][DOWN][DOWN]
d
:: (3:02:34 AM)
:: Administrator (3:02:34 AM)
d
:: (3:03:11 AM)
mmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmm
:: [Release] QPST 2.7 BUILD 422 - Download Here - Enjoy - Mozilla Firefox (3:03:57 AM)
crap
How to delete?d
:: Clipboard Change : size = 16 Bytes (3:03:57 AM)
QPST.2.7.422.msi
:: (3:04:23 AM)
cccccc
More info
- - - Updated - - -
It contacts to "qpst.hopto.me" to send keylogger data.
Just read all pages and some people already reported the virus.
Why don't you guys (admins) remove the attachment?
Last edited by rich hathaway; 02-19-2014 at 09:45 PM. Reason: hide thanks added
where is the link ?
Bookmarks