Trojan.W32.Looksky

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by kiwiabroad, Sep 21, 2007.

  1. kiwiabroad

    kiwiabroad Private First Class

    Hi

    I'm back again!

    Number 1 son has again managed to download something inadvertently. He was on MSN and MySpace when security alerts popped up saying they had detected this virus, attempts made to change IE, etc and usually comes thru emails or Active-X and that someone could be trying to access and our emails, passwords, etc. Both he and my daughter assure me they have not opened any emails etc from anybody they don't know - they have been deleted nor have they downloaded anything new. Don't know if this is of any relevance anyway.

    Windows Internet boxes keep popping up, internet slow at best (won't use it as worried about consequences), keep getting security alerts and the following:

    SpywareGuard repeatedly says a BHO has been added:
    60D3EC53-56A8-46A8-9D011-IAB64410665C
    C:\Windows/nsduo.dll
    (Despite repeated attempts at removing the BHO and restoring the IE homepage, it keeps repeating the same information)
    Trying to change the IE homepage from Google to:
    http://softwarereferral.com/jump.php?wmid=6010mid=Mj160jg5lid=2

    Can't run AntiVirus as the above seems to slow it right down and it just doesn't seem to be working as normal.

    I have Windows XP Home, IE 7, have AntiVirus, SpywareGuard, SpyBot, SpywareBlaster, and Sygate Firewall.

    Please, please help.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please follow the instructions in the Read and Run First sticky and attach the requested logs.
     
  3. kiwiabroad

    kiwiabroad Private First Class

    P.S
    Forgot to say also have Adware 2007.
    Thanks
     
  4. kiwiabroad

    kiwiabroad Private First Class

    Thanks for your prompt answer. Please excuse my ignorance and point me to the 'Read and Run First' sticky?
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  6. kiwiabroad

    kiwiabroad Private First Class

    Thanks for link, remembered where to find it just after I posted my reply! Will work thru and post results.
     
  7. kiwiabroad

    kiwiabroad Private First Class

    Hi again

    Currently in process of defragmenting C drive with IObit. I have clicked by G drive (external hard drive back up) to defrag as well - is this ok or should it only have been C drive?
     
  8. kiwiabroad

    kiwiabroad Private First Class

    I am having all sorts of problems doing the counterspy. It is running ok, but took 1 hour to download and 7 hours to scan (found 16 items with 98 traces) and then proceeded to ignore the whole lot! Do I have to run the scan again? And why is it taking so long? Can I try the AVG one instead now I have already run Counterspy? I can't any anyway of retrieving those items and deleting them - am I missing something obvious here? I have had to use a neighbour's computer to post this thread as the internet is taking so long. Please help
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    AVG Anti-spyware will be fine .....i don't know why you had no option to have Counterspy quarantine what it found.

    Do all that you can and post the logs.
     
  10. kiwiabroad

    kiwiabroad Private First Class

    Hi
    Firstly, was my mistake with counterspy - I was running it in normal mode - I wasn't too impressed with myself when I realised!! Have run it again in safe mode along with CCleaner and Spybot. Can't run my broadband connection in Safe Mode with Networking Support, and almost impossible for me to get on the internet in normal mode as everything is so slow and lots of windows keep popping up (again I am posting this from a neighbour's computer) so I don't think I will be able to access BitDefender and Panda Active Scan let alone run them as they will take forever. Is the GetRunKey.Zip and NewRunKey.Zip plus a log of Counterspy enough for you to go on at present? I will also attempt to a HijackThis log.

    Is it possible to download these logs/zips on to a memory stick and then attach them from another computer?

    This seems a lot worse than my previous problems and I am spending an awful lot of time trying to sort it. Would I be better off reinstalling my operating system and applications or just buying a new computer??!!
     
  11. kiwiabroad

    kiwiabroad Private First Class

    P.S. can I download the various programs onto a memory stick and then run them from that on my computer without connecting to the internet?
     
  12. kiwiabroad

    kiwiabroad Private First Class

    Runkeys and newfiles attached
    Will endeavour to send Counterspy reports and do HijackThis

    Couldn't download Java so haven't been able to run BitDefender or Panda Scan - too many windows opening and pop-ups are slowing my internet connection to a snails pace - unless I can get this to stop any online scan would take about a week!
     

    Attached Files:

  13. kiwiabroad

    kiwiabroad Private First Class

    Counterspy.txt attached
    Note - this is the one I did in normal mode by mistake but found the most problems. I will send the one done in safe mode separately as Counterspy.txt - it only found one problem.
     

    Attached Files:

  14. kiwiabroad

    kiwiabroad Private First Class

    as per previous post second counterspy scan attached
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We will work you through this so you don't have to reformat.:)

    Yes, you can download to a different computer and save to a thumb drive and then extract to your desktop to run.


    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    IMPORTANT: Do NOT run any other options until you are asked to do so!
    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. BUT Reboot in Safe Mode.

    The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.

    Now reboot into normal mode and attach this new rapport.txt log here.
    Now attach new logs from:

    * GetRunKey
    * ShowNew
    * HJT

    How are things working now?
     
  16. kiwiabroad

    kiwiabroad Private First Class

    Thanks for your prompt response. Can I just clarify one thing please - do you still want me to run HijackThis before these procedures or now at the end of them. I have downloaded the program but not run it yet.
    Thank
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run them after you do the smitfraud fix!:)
     
  18. kiwiabroad

    kiwiabroad Private First Class

    The link to SmitfraudFix doesn't work - I have tried on my work computer as well, just comes up with page cannot be displayed. I have tried searching for a download separately on your website but can't find one. Please advise.
     
  19. kiwiabroad

    kiwiabroad Private First Class

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am sorry about that ....yes, that is the download. Do follow the instructions regarding saving the report before running the second set of instructions.
     
  21. kiwiabroad

    kiwiabroad Private First Class

    First smitfraud log attached as requested.

    Question before continuing with next sequence please - you've said to attach new GetRunKey and ShowNew logs. Will the new logs overwrite the previous ones I did for you so I just have to attach the runkey.txt and newfiles.txt as per the instructions in Read & Run Me First?
     

    Attached Files:

  22. kiwiabroad

    kiwiabroad Private First Class

    Hi again

    Second Smitfraud log in safe mode attached. Waiting on your reply to my earlier question before re-doing GetRunKey and ShowNew.

    Already internet is running much faster, the desktop icons for Error Cleaner, Privacy Protector and Spyware & Malware Protection have been removed. Just one thing - when I connect to the internet, it always comes up as working offline even though I am actually online. I have to open up a second tab to get to the website I want (you guys!) ??
     

    Attached Files:

  23. kiwiabroad

    kiwiabroad Private First Class

    Ok - forget the offline thing in previous post, appears to be working ok now. Following things noticed:

    When I am logged in:

    1. Desktop wallpaper has disappeared - no big deal, just wondered why?
    2. IObit Smart Defrag Ending Program window when logging off
    3. Windows-No Disk window when logging off which says:
    Exception Processing Message c0000013 Parameters 75b6bf9c 4 75b6bfc 75b6bfc

    When hubby is logged in:
    Same problems as 2 and 3 above

    When daughter is logged in:
    1. Same problems as 2 and 3 above, plus:
    2. Open File-Security Warning, Publisher could not be verified
    Name: TOMBRA 1.EXE
    Type: Application
    From: C:\DOWNLO 1
    3. msrr.exe-entry point not found. The procedure entry point ?CreateGraphic@Value@DirectUI@@SGPAV12@PB_WEIGGPAUHINSTANCE_@@_N2@Z could not be located in the dynamic link library MSNcore.dll

    When son is logged in:
    1. Same problems as 2 and 3 for me
    2. Same problem as 3 for daughter, plus
    3. Steam Error - Unable to connect to Steam Network because no Steam login information stored on this computer. Check status on http://steampowered.com/status (I think this is an old 'leftover' from some game he used to play many moons ago but not anymore - just gives an OK box, no 'X' to click)

    In addition, I have had Sygate Firewall with message:
    Client Server Runtime Process (crsse.exe) is trying to broadcast to 224.0.0.22 - allow? I clicked no but didn't click remember my answer as yet.

    I hope this all makes sense!
     
  24. kiwiabroad

    kiwiabroad Private First Class

    I went on the assumption that the runkeys.txt and newfiles.txt would be overwritten (like the Smitfraud) so have attached the re-runs plus HijackThis log. Hope this is all ok.

    Computer running much better and faster, no annoying windows popping up whether online or not. No other apparent problems other than ones listed in previous post.

    Will not do anything more on computer until receive further instructions from you.

    Thanks
     

    Attached Files:

  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    Sunbelt Counterspy
    LiveReg (Symantec Corporation)
    LiveUpdate 2.6 (Symantec Corporation)

    Also, uninstall and re-install Windows Live Messenger

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Click remember my answer.

    Then do a search for the (crsse.exe) and see if it isn't a leftover from NOrton...if found, just delete it.

    Tell me how things are running now.
     
  26. kiwiabroad

    kiwiabroad Private First Class

    Ok - latest instructions done. Following noticed

    When I am logged in:

    1. Desktop wallpaper has disappeared - no big deal, just wondered why?

    Still the same

    2. IObit Smart Defrag Ending Program window when logging off
    3. Windows-No Disk window when logging off which says:
    Exception Processing Message c0000013 Parameters 75b6bf9c 4 75b6bfc 75b6bfc

    All gone now

    When hubby is logged in:

    everything ok

    When daughter is logged in:
    1. Same problems as 2 and 3 above, plus:

    Gone now

    2. Open File-Security Warning, Publisher could not be verified
    Name: TOMBRA 1.EXE
    Type: Application
    From: C:\DOWNLO 1
    3. msrr.exe-entry point not found. The procedure entry point ?CreateGraphic@Value@DirectUI@@SGPAV12@PB_WEIGGPAUHINSTANCE_@@_N2@Z could not be located in the dynamic link library MSNcore.dll

    Both these still there

    When son is logged in:
    1. Same problems as 2 and 3 for me

    Gone now


    2. Same problem as 3 for daughter, plus
    3. Steam Error - Unable to connect to Steam Network because no Steam login information stored on this computer. Check status on http://steampowered.com/status (I think this is an old 'leftover' from some game he used to play many moons ago but not anymore - just gives an OK box, no 'X' to click)

    Still there

    In addition, I have had Sygate Firewall with message:
    Client Server Runtime Process (crsse.exe) is trying to broadcast to 224.0.0.22 - allow? I clicked no but didn't click remember my answer as yet.

    This hasn't happened again, and I couldn't find crsse.exe on a search

    Other points:

    1. My son still has the 3 icons on his desktop for Error Cleaner/Privacy Protector/Spyware & Malware but they have gone from my desktop??

    2. When re-installing Windows Live Messenger, Sygate Firewall came up with a prompt to a 'Driver Package Installer' trying to connect. I clicked no, but not remember my answer as wasn't sure what this was. Is this correct?
     
  27. kiwiabroad

    kiwiabroad Private First Class

    Just reviewed my message and haven't done the quotes properly. I have written under the problems what has changed or not. Hope it makes sense.

    Thank you!
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to run smitfraud on your son's log in account ...I'm assuming that it was not run on the administrator account....

    Run CCleaner on each account ...first run the cleaner to remove temp files. Then run the issues scan (making sure you do the backup!).

    Now tell me exactly what is still occurring and if error messages...the exact message.
     
  29. kiwiabroad

    kiwiabroad Private First Class

    No I didn't run it in the administrator a/c as I didn't realise I had to ...

    I have attached the first rapport.txt after running it logged on to my son's a/c - didn't know whether you needed this or not.

    I will now run the smitfraud clean in safe mode and then attach that.
     

    Attached Files:

  30. kiwiabroad

    kiwiabroad Private First Class

    rapport.txt from safe mode logged into son's a/c attached.

    His desktop wallpaper has disappeared too so obviously a thing with running smitfraud.

    My husband and daughter's log in a/cs do not show these 3 icons on the desktop. I am assuming this is because they have not logged on to the internet whilst infected with this virus. Is this correct? Do I need to run smitfraud on their a/cs anyway or should I do it again as administrator? In addition, the other logs attached were all from my login a/c. Does that mean I should do them all again as administrator?

    I am sorry - I'm not a computer expert and need step by step instructions as you have given but I didn't see anywhere telling me to log in as administrator. Did I miss something?

    Thanks
     

    Attached Files:

  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    When you reinstall windows live messenger...let it install the driver package...

    Run CCleaner on each account ...(or from the administrator account).

    It would be a good idea to let me see the following logs from your son's account:
    ShowNew
    GetRun
    HJT

    Right click your desktop / properties / web ---> tell me what is there
    (yours and your sons).

    Now tell me exactly what is still occurring and if error messages...the exact message.
     
  32. kiwiabroad

    kiwiabroad Private First Class

    Can I access the GetRun, ShowNew and HJT from my son's a/c or I need to download them to him as well? (I downloaded them whilst logged on as me)
     
  33. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should find them in the same place as you ran it from in your log in...
    C:\Majorgeek Downloads\GetRunKey.bat
    same for Shownew
    C:\Program Files\HijackThis
     
  34. kiwiabroad

    kiwiabroad Private First Class

    ShowNew, GetRun and HJT files attached from son's login a/c
     

    Attached Files:

  35. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Uninstall ---> Steam

    Install:
    Java Runtime 6

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run CCleaner ..then reboot and tell me how his account is running.
     
  36. kiwiabroad

    kiwiabroad Private First Class

    CCleaner run in administrator a/c - backup done to desktop.

    The driver package prompt happened when I had already just re-installed Windows Live Messenger - should I uninstall and reinstall again to get the same prompt from the firewall and click yes this time?

    When right clicking on Desktop/Properties there was no option for Web - only tabs for Themes/Desktop/Screen Saver/Appearance/Settings - have I misunderstood your instructions?

    Daughter is still getting the Tombra and msrr.exe windows as previously listed. She also got a End Program -sgtray.exe window when logging out.

    My son is getting the msrr.exe window and Steam one as previously listed.

    I have tried to attach the exact message boxes but they are too big.
     
  37. kiwiabroad

    kiwiabroad Private First Class

    Our messages have crossed - just to double check you want me to do the Steam uninstall, Java, run HJT etc logged on to my son's a/c?
     
  38. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you run the issues section of CCleaner...on all accounts? The backup should have been an listed to go into my documents ....

    "sgtray.exe --Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring."
    Is this till installed?

    Sorry ...desktop tab / customize / then web tab ...what is there?

    Yes to your last post.
     
  39. kiwiabroad

    kiwiabroad Private First Class

    No I didn't run the CCleaner issues on each a/c - I did the issues on the administrator a/c only (per your instructions "Run CCleaner on each account ... OR from the administrator account"). Should I just do a CCleaner run + issues on each a/c with a backup saved in my documents each time?

    I have no idea what the sgtray.exe is or if it's still installed - how do I check?

    Desktop tab instructions show nothing in web pages box for both of us.
     
  40. kiwiabroad

    kiwiabroad Private First Class

    Further update for you:

    On son's login a/c -
    1. Steam issue fixed
    2. Still getting the following window on desktop after login:
    msrr.exe-entry point not found. The procedure entry point ?CreateGraphic@Value@DirectUI@@SGPAV12@PB_WEIGGPAUHINSTANCE_@@_N2@Z could not be located in the dynamic link library MSNcore.dll

    On daughter's login a/c -
    1. getting the same msrr.exe as above
    2. Still getting the Tombra window as well:

    Open File-Security Warning, Publisher could not be verified
    Name: TOMBRA 1.EXE
    Type: Application
    From: C:\DOWNLO 1

    Other 2 login a/cs are fine. Internet working fine on all users and at normal speed again.

    CCleaner has been run on every user, cleaning and issues, with a backup done to My Documents for each user. The Administrator backup I have left on the desktop for now.

    Java Runtime downloaded; HJT run and the two lines fixed; fixME.reg done - all on son's login a/c.

    Will wait on further instructions.

    Thanks
     
  41. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run HJT in both accounts and have it fix this line:
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msrr.exe" /background

    Then manually use windows explorer to see if it is still there ...delete it if it is.

    Was MSN messenger removed at one point?

    The other item refers, I believe to Tomb Raiders ....was that program also removed?
     
  42. kiwiabroad

    kiwiabroad Private First Class

    Yes, both MSN messenger has been removed in the past and reinstalled and Tomb Raiders was removed ages ago.

    Will do the HJT on both a/cs and let you know how things are working.

    What about the driver package with Windows Live Messenger? Should I uninstall and reinstall WLM again as the Sygate message hasn't reappeared again? Kids aren't using computer at moment until you say it is ready to go so they are not on MSN and I don't use MSN so I don't know if it is working properly.
     
  43. kiwiabroad

    kiwiabroad Private First Class

    Ok - HJT has fixed the msrr.exe problem in both a/cs!!

    I noticed in Emma's a/c after the HJT scan that there was an O4-HKCU line for Tomb Raider. Should I run it again and fix this line as well and see if this fixes the problem?
     
  44. kiwiabroad

    kiwiabroad Private First Class

    I've done the Windows explorer on both a/cs and can't find the msrr.exe .....however, noticed some 'interesting' things:

    In Andy's My Documents there are icons for IMesh 5 Shortcut and IMesh V5, Steam Install and one that says funrecent.fmp ???? In his My Music there is also an IMesh folder. I know IMesh shouldn't be on the computer. Should I get rid of these and how please?

    On Emma's desktop there is an icon for msjavax86 - any ideas what this is?

    Thanks
     
  45. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes!

    imesh is to download and listen to music ...it's up to you as to removing it.

    msjavax86 ---> virtual machine java for some archetictual CAD programs ...if it is just on the desktop ..you could remove it...if it i needed for one of her programs, it can be re-downloaded if ness.

    Now how are things?:)
     
  46. kiwiabroad

    kiwiabroad Private First Class

    Bingo! Everything appears to running smoothly - thank you so much.

    My login is a bit slow loading up - there are quite a few things in the system tray but I know how to deal with that thru msconfig and the start-up tab.

    I realise that a computer can't be 100% protected against this stuff but I have everything you guys have suggested on your guides and past threads; given strict instructions to my kids about what not to download, don't do if your not sure etc (or you won't live to your next birthday!); I update all the programs regularly, clean, immunize etc etc. and still this has happened. Can I do anything better? Is it better to say take the subscription to the AntiVir program - will this give me better automatic real-time protection? Is there a better firewall I could use?

    And one more quick question - I regularly back up (using Microsoft SyncToy) to an external hard drive (my last back-up was before this infection). When I run all these programs I have, do they check the exteranl drive as well or do I have to check that separately?

    I have read all the support guides on majorgeeks but would really appreciate your advice on the above matters - if for nothing else, so I don't have to bother you again!

    Look forward to your reply.
     
  47. kiwiabroad

    kiwiabroad Private First Class

    P.S. can I delete the SmitFraud folders, fixME.reg, HJT, GetRunKey and ShowNew?
     
  48. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your backup drive will not be scanned unless you tell the program to do so ...and if you backed up when you were infected, I would suggest that you reformat that drive and then do a backup now that you are clean.
    Don't use msconfig to control your start up ..it is really for diagnostics. If you want, use a startup program such as:
    Startup Manager

    It is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  49. kiwiabroad

    kiwiabroad Private First Class

    Ok thanks - will do all the removals etc.

    I downloaded the Startup Manager but exited after download to deal with later - where do I find it again? Can't see it on the desktop or in Programs??

    I did NOT do an external back-up whilst infected - the last back up was a week before this infection - so that would mean I don't have to reformat that drive but just scan it anyway as a safety measure?
     
  50. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes to the backup disc ...just scan it with your AV program.

    Startup Manager should have downloaded to your desktop ....unless you choose a different place ...do a search for it ...it is a stand alone program ...you just click the exe and it will open.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds