Trojan.W32.Looksky

Discussion in 'Malware Help (A Specialist Will Reply)' started by kiwiabroad, Sep 21, 2007.

  1. kiwiabroad

    kiwiabroad Private First Class

    This is a bit strange with Startup Manager - I can't find it anywhere. When I download it, it doesn't ask me for a location, it just goes straight into the Start Up Tool - any thoughts?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. kiwiabroad

    kiwiabroad Private First Class

    Should I just right click and delete these Imesh icons/folders then or do I have do do something more in depth?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Look in add/remove programs and uninstall from there ....or use the tool in CCleaner to remove it. Then do a search for Imesh and (yes) right click any that are found and delete.

    Did you find the Startup Manager? (you could always start a new download and note where the download destination is ---> then you should find it.):)
     
  5. kiwiabroad

    kiwiabroad Private First Class

    No, I didn't and I did a new download and it did exactly the same thing with no download destination and I still can't find it (incidentally, I unticked what I didn't want and it still worked). I will try downloading from a different site and see if that works.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It should just ask you if you want to save the file..you click yes and it goes straight to your desktop .....I'm at a loss as to what is happening with it on your system.
     
  7. kiwiabroad

    kiwiabroad Private First Class

    Sometimes if I had a brain cell I'd be a plant!! I was clicking run on the startup manager instead of save!! Doing it too late at night and too tired to realise what I was doing.

    I have removed the iMesh stuff and the Steam Install.

    Just one more quick question - I went into the Control Panel to adjust the User A/cs and noticed a user (n addition to the four of us and Guest a/c) called:

    ASP.NET Machine A..

    Do you know what this is please??
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The aspnet_wp or ASP.NET Machine Account is created when the Microsoft .Net Framework 1.1 is installed onto a Windows XP computer. The user is created to run the asp.net worker process used in Microsoft's Internet Information Services, which allows ASP.net to run on your local web server (This is pretty much its only use, it is not used to run normal .net managed executables). There is not a need to worry about this user's presence; it was not created in malicious way.

    More Here.
     
  9. kiwiabroad

    kiwiabroad Private First Class

    I have uninstalled AntiVir and installed Avast! Home Edition instead. This did a scan before loading windows and found some adware and some trojans. The first couple of adwares I deleted, the other 6 I moved to the chest .

    3 of these came up with an 'are you sure message' about moving because they were in a windows folder. They were:

    C:\Windows\context.exe (infected by Win32:Trojano-1481)
    C:\Windows\SYSYEM32\4lxRes.dll.bak (infected by Win32:Spyware-gen)
    C:\Windows\specialoffers.exe (infected by Win32:Trojano-1481)

    The other 3 I moved just let me move them without an 'are you sure' message. These were:

    A0000184.exe (infected with Win32:Adware-gen)
    A0000184.exe (as above)
    A0000186.exe (infected with Win32:Trojan-gen)

    Have I done the right thing in moving these to the chest?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes.....and this is why we say that no anti-virus will detect all threats. It's good to have a checkup using different tools every once in a while!

    And be cautious of where you go and what you click on...;)
     
  11. kiwiabroad

    kiwiabroad Private First Class

    I am extremely cautious. After speaking to my son as to exactly what happened (he is 17 after all and is aware of the do's and don'ts), he did what he thought was the right thing - he got an apparent security alert that looked like it was coming from our antivirus software, saying a trojan had been detected, that it was serious, and yes or no to clean. I wasn't home, he clicked yes and that started the problem. He now knows just to exit the window and tell me what has happened and I will deal with it .... hopefully!!!!

    I would like to say thank you very much for your help and skill in removing this ... once again majorgeeks (and their experts!) has been an invaluable asset. And to all you 'first-timers' out there with problems, I cannot recommend these guys highly enough, they know what they are doing and just be patient and don't panic ... it may take a few days, a week, or more (with the time difference!) but they will fix it!!!

    Thanks again
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome....safe surfing (and register the child here so he can learn also!!;))
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds