Hi I need help as well. Hijackthis has detected these... I don't seem to find the part that explains why www.lookfor.cc appears...
Logfile of HijackThis v1.97.7
Scan saved at 09:02:22, on 25.03.2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Your system isseriously hosed. You left yourself wide open to this, since you are way behind on your patches. You need the XP Service Pack 1 (XP-SP1) and all the security patches for Internet Explorer as soon as this is cleaned up. You may even find that a full format and reinstall are required!
Before you try to fix the following, you need to run an up-to-date virus checker and adware/spyware tool against your system. I see Trend Micro's online checker Housecall recommended here a lot. Important: this list is for information only right now, until you run some tools! The list of tools wil be at the end, along with some of the problems.
O2 - BHO: (no name) - {00000EF1-0786-4633-87C6-1AA7A44296DA} -
C:\WINDOWS\System32\calsdr.dll
O2 - BHO: . - {587DBF2D-9145-4c9e-92C2-1F953DA73773} - C:\Documents and
Settings\Christian Sugiono\Application Data\windi\windi.dll
O2 - BHO: (no name) - {7F0208C6-31B8-98CB-55E4-5072CEA2DEB4} - (no file)
O2 - BHO: ShowSearch module - {E2DDF680-9905-4dee-8C64-0A5DE7FE133C} -
C:\Documents and Settings\Christian Sugiono\Application
Data\windi\mssearch.dll
O2 - BHO: (no name) - {FD9BC004-8331-4457-B830-4759FF704C22} -
C:\Documents and Settings\Christian Sugiono\Application Data\windi\msiesh.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
O4 - HKLM\..\Run: [nsvdr] c:\program files\dialers\nsvdr\nsvdr.exe /noconnect
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [sncntr] c:\windows\system32\sncntr.exe /nocomm
O4 - HKLM\..\Run: [Image] rundll32 C:\WINDOWS\image.dll,Install
O4 - HKLM\..\Run: [msbb] C:\WINDOWS\System32\msbb.exe
O4 - HKLM\..\Run: [SAHAgent] C:\WINDOWS\System32\SahAgent.exe
O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe
O4 - HKCU\..\Run: [System Update] C:\WINDOWS\System\webcheck.exe
O4 - HKCU\..\RunServices: [Image] rundll32 C:\WINDOWS\image.dll,Install
The following malware is on your system: Trojan Win32.Dluca, BugBear virus, CoolWebSearch, ShopAtHome, a porn dialer, and OfferOptimizer. There may be others, as well.
Start with the online virus scan, then run CWShredder , then Ad-Aware . Make sure your data file is up-to-date before running Ad-Aware.
Once your infestation is under control, you may need to run fixer software to get your internet connection back. We'll cross that bridge when we come to it. Once you have performed the above steps, re-run HijackThis, post the new results, and we will finish the cleanup.
For future reference, the following items are superfluous and can be deleted later:
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: PCSuiteForNokia7650 Detect.lnk = ?
O4 - Global Startup: PCSuiteForNokia7650 TS.lnk = ?
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://software-dl.real.com/229b509722f6ea246802/netzip/RdxIE601_de.cab