LandzDown Forum

Security => Analysis and Malware Removal => Topic started by: VirusHater on August 21, 2007, 08:34:28 PM

Title: Trojan and loads of spyware Help please! (again)
Post by: VirusHater on August 21, 2007, 08:34:28 PM
oads of warnings and pop ups have taken over my desk top. Warning says that I have Trojan.W32.looksky.

AVG found about 60 tracking cookies (medium risk) My desktop is red w/ a privacy logo and warnging. Spyware everywhere. Please help! Here is my HiJackLOg:

Logfile of HijackThis v1.99.1
Scan saved at 22:27:41, on 2007-08-21
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\Program\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
E:\Program\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
O2 - BHO: MSVPS System - {283A0EE3-2CC1-45AB-8207-B1D7B69C7F83} - C:\WINDOWS\duocore.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program\google\googletoolbar3.dll
O4 - HKLM\..\Run: [KAVPersonal50] C:\Anti Virus Kapersky\AV Temp\Kaspersky Anti-Virus Personal\kav.exe /minimize
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [swg] C:\Program\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: desktop(2)(2).ini
O4 - Startup: desktop(2).ini
O4 - Startup: desktop(3)(2).ini
O4 - Startup: desktop(3).ini
O4 - Startup: desktop(4).ini
O4 - Global Startup: desktop(2)(2).ini
O4 - Global Startup: desktop(2).ini
O4 - Global Startup: desktop(3)(2).ini
O4 - Global Startup: desktop(3).ini
O4 - Global Startup: desktop(4).ini
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .pdf: C:\Program\Internet Explorer\PLUGINS\nppdf32.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\Program\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: wmpenv - {E988D7C9-45D1-433B-991B-127FE1CEB3A4} - C:\WINDOWS\wmpenv.dll
O21 - SSODL: wmpconf - {045864CD-B021-4CC0-99C3-CB60FBF65871} - C:\WINDOWS\wmpconf.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program\ewido anti-malware\ewidoctrl.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Anti Virus Kapersky\AV Temp\Kaspersky Anti-Virus Personal\kavsvc.exe

Thnx!
Title: Re: Trojan and loads of spyware Help please! (again)
Post by: VirusHater on August 21, 2007, 08:49:21 PM
Now the pop ups won´t let me scan with my Kaspersky anti virus program. This will just get worst I´m afraid. Is this the death of my comp?
Title: Re: Trojan and loads of spyware Help please! (again)
Post by: Niecarrah on August 22, 2007, 04:00:53 PM
No, No not the death of your puter!  Have patience and the more learned ones will come to your rescue!
Title: Re: Trojan and loads of spyware Help please! (again)
Post by: Corrine on August 22, 2007, 11:20:50 PM
Tjenare, VirusHater!

It has has not been that long since your last visit.  I sure wish you would stop by just to say "Hi" instead of with such a nasty infection.  We will do our best to help, but then you really need to consider some additional protection and updating for that machine.  Let's see how well what I am suggesting will get the process started. 


MVH,

Corrine

Please print or copy these instructions to your desktop as you will be working from safe mode during much of the time.

Please do the following:  Please then reboot your computer in Safe Mode by doing the following :Run ATF Cleaner[LIST=1]
Open the extracted SDFix folder and double click RunThis.bat to start the script. Run SUPERAntiSpyware Post a reply with the following: