Please help me!

  1. #1
    paulch is offline Newbie

    Please help me!

    who can help me to kill the virus of "Win32.Troj.Look2Me.g.237191"? i have been exhausted by it, i have used all of the methods to kill it, but all of them is unuseful.
    thank you very much!

    i am waiting online.


  2. #2
    paulch is offline Newbie
    Following is the log of Hijackthis , any help will be appreciated


    Logfile of HijackThis v1.99.1
    Scan saved at 15:06:02, on 2006-5-11
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    d:\program files\rising\rfw\rfwsrv.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\WINNT\System32\svchost.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINNT\system32\nvsvc32.exe
    C:\PROGRA~1\HBNETCOM\HBPPPOE\app\pppoeservice.exe
    C:\WINNT\System32\snmp.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\System32\inetsrv\inetinfo.exe
    C:\WINNT\Explorer.EXE
    d:\program files\rising\rfw\RfwMain.exe
    C:\PROGRA~1\HBNETCOM\HBPPPOE\app\EnterNet.exe
    D:\Program Files\Kingsoft\Powerword 2003\xdict.exe
    E:\hijackthis\HijackThis.exe

    O3 - Toolbar: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [RfwMain] "d:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
    O4 - HKLM\..\Run: [KAVRUN] C:\KAV5\KAVRUN.EXE
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\Tencent\qq\AddToNetDisk.htm
    O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\Tencent\qq\AddPanel.htm
    O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\qq\AddEmotion.htm
    O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\Tencent\qq\SendMMS.htm
    O11 - Options group: [!CNS] 网络实名
    O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com.cn/webscann...an_unicode.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (趋势科技在线扫毒程序) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
    O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/regist...new/OL2006.cab
    O18 - Protocol: dic - {C21F5C32-F57A-4A0D-8E0A-B672691C52D0} - d:\PROGRA~1\Kingsoft\POWERW~1\XDictExB.dll
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    O20 - Winlogon Notify: RunOnceEx - C:\WINNT\system32\hr4805hue.dll
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
    O23 - Service: GIGABYTE/NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
    O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - C:\PROGRA~1\HBNETCOM\HBPPPOE\app\pppoeservice.exe
    O23 - Service: Rising Proxy Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - d:\program files\rising\rfw\rfwproxy.exe
    O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - d:\program files\rising\rfw\rfwsrv.exe

  3. #3
    VopThis is offline Senior Member (Canada)
    Please download the latest version of Look2Me-Remover.exe to your desktop.
    http://www.atribune.org/ccount/click.php?id=7

    * Close all windows before continuing.
    * Double-click Look2Me-Remover.exe to run it.
    * Put a check next to Run this program as a task.
    * You will receive a message saying Look2Me-Remover will close and re-open in approximately 10 seconds. Click OK
    * When Look2Me-Remover re-opens, click the Scan for L2M button, your desktop icons will disappear, this is normal.
    * Once it's done scanning, click the Remove L2M button.
    * You will receive a Done Scanning message, click OK.
    * When completed, you will receive this message: Done removing infected files! Look2Me-Remover will now shutdown your computer, click OK.
    * Your computer will then shutdown.
    * Turn your computer back on.
    * Please post the contents of C:\Look2Me-Remover.txt and a new HiJackThis log.

    If you receive a message from your firewall about this program accessing the Internet please allow it.



    If you receive a runtime error '339' please download MSWINSCK.OCX from the link below and place it in your C:\Windows\System32 Directory.
    http://www.ascentive.com/support/new...b/MSWINSCK.OCX

  4. #4
    paulch is offline Newbie
    Thank you for your help, but after it is closed, it can't reopen automatically, what's wrong with it?

  5. #5
    VopThis is offline Senior Member (Canada)
    Please download, install, update and scan your system with the free (trial) version of Ewido TROJAN scanner
    [Developed for Windows 2000 and XP]:
    1. When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
    2. When you run ewido for the first time, you will get a warning "Database could not be found!". Click OK. We will fix this in a moment.
    3. From the main ewido screen, click on update in the left menu, then click the Start update button.
    4. After the update finishes (the status bar at the bottom will display "Update successful"), click on the Scanner button in the left menu, then click on the Start button. This scan can take quite a while to run, so time to go get a drink and a snack....
    5. If ewido finds anything, it will pop up a notification. You can select "clean" and check the boxes "Perform action with all infections" and "Create encrypted backup" before clicking on OK.
    6. When the scan finishes, click on "Save Report". This will create a text file. Please then paste the contents of the text file to this thread.
    Note: Ewido is a free trial product for 14 days. Since Ewido is a trial version, the realtime guard and automatic update will stop functioning after 14 days. We are not installing the guard because it might interfere with the cleanup or the malware removal process. You can use Ewido as an on-demand scanner (recommended) but you will have to manually update the definition file each time you scan. If you decide to purchase Ewido, you can enable the 'Realtime Protect' and 'Automatic Update' functions by clicking on the 'Status' bar (Top left) and clicking on both items under "Your Security Status".

    REBOOT.




    Try Look2Me-Remover.exe again.




    If there are still problems,

    Download L2mfix from one of these two locations:

    http://www.atribune.org/downloads/l2mfix.exe
    http://www.downloads.subratam.org/l2mfix.exe



    Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, NOTEPAD will open with a log. Copy the contents of that log and paste it into this thread.

    IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!

    If you receive, while running option #1, an error similar like: ''C:\windows\system32\cmd.exe
    C:\windows\system32\autoexec.nt the system file is not suitable for running ms-dos and Microsoft windows applications. Choose close to terminate the application.."...then please use option 5 or the web page link in the l2mfix folder to solve this error condition. Do not run the fix portion without fixing this first.

  6. #6
    paulch is offline Newbie
    Before running look2me, whether the Task Scheduler service must be start-up? i found it wasn't start-up in the services of Management console, and prompted "error 1721: resource is not enough to complete this operation" how can i fix it? thank you very much!

  7. #7
    VopThis is offline Senior Member (Canada)
    Save 20% on AVG Internet Security 2012 Suite!
    Before running look2me, whether the Task Scheduler service must be start-up? i found it wasn't start-up in the services of Management console, and prompted "error 1721: resource is not enough to complete this operation" how can i fix it? thank you very much!
    See if these links help resolve the above issues (try re-searching on exact error message in quotes, if needed):

    http://www.google.ca/search?hl=en&q=...G=Search&meta=

    It would appear that something may be attacking or impacting your antivirus tool (Kaspersky?). We have already seen that Look2Me-Remover is not working properly under current circumstances.



    Try running the L2mfix, instead, if necessary.

+ Reply to Thread