How to remove Look2Me etc

G

Guest

Would greatly appreciate if anyone could help. MS AntiSpyware (in safe mode)
found th following:

1. Look2Me by NicTech Networks
2. Transponder.VX2.A by Mindset Interactive/Direct Revenue/ABetterInternet
3. ABetterInternet by A Better Internet/ Direct-Revenue

When I reboot and scan again, these 'scum' are stil there. Also tried
ad-adware se, ewido security, spybot-s&d and ccleaner altogether in safe mode
but to no avail... Can anyone help?
 
D

Dave M

Variant 42: CWS.Look2Me
Approx date first sighted:
Symptoms: AdDestroyer and Virtual Bouncer adware that keeps coming back after
being removed. Hosts file redirections that keep coming back after being
deleted.
Cleverness: 9/10
Manual removal difficulty: Very Difficult

Hijacks numerous pages through HOSTS file redirections. Remains resident and
downloads adware to the pc while connected to the internet. Look2Me has several
redundant files that monitor for partial removal and replace missing components.
In order to elude detection and removal this variant changes its signature with
each restart of the system and removes security rights from administrative
users.



Download CWShreader here:

http://cwshredder.net/cwshredder/cwschronicles.html
 
G

Guest

Go with Dave M's Advise but also check this:

This is a AndyM or Ron Kinner case beacuse I cannot find any good advice
within any forum without using HijackThis and to be carefully guided.

Get HijackThis.exe from
http://tomcoyote.org/hjt/hjt199//HijackThis.exe
http://computercops.biz/HijackThis.html

Save it to C:\hjt (new folder) then Open it and select Scan and Save Log.

Note where you saved the log then send it to him as an attachment.

Put Hijack in the subject so he'll know it's not spªm.

Alternatively you can post it on the Dell Forum ªt:

http://forums.us.dell.com/supportforums/board?board.id=si_hijack

(if it wraps you can go tº:

http://tinyurl.com/ckuzq instead.)

Put Ron in the subject so he will see it.

You do not need to have a Dell to post but you will need to register.

Ron Kinner
Microsoft MVP 2004 & 2005
(e-mail address removed)

Let us know how it works ºut.

Good luck

Engel
 
G

Guest

As Engel said it hard to deal with this without using Hiajck This but first
try CWShredder as Dave suggested and also Add SpySweeper as that will perform
well with Look2me, For ABetterInternet you could try Ad-Aware's VX2 cleaner
Plugin which you install and then access through the Add-Ons button in
Ad-Awares main menu. Failing that use Hijack This :)

Download CWShredder from the link Dave post or from here:

http://www.trendmicro.com/ftp/products/online-tools/cwshredder.exe

Install then exit

Download Ad-Aware's VX2 Cleaner Add-On

http://updates.ls-servers.com/vx2cleaner.zip

extract and run to install the Plugin, After installing exit for now and use
it abit later in safe mode.

Please download WebRoot SpySweeper from HERE

http://www.webroot.com/downloads/

(It's a 2 week trial):
Click the Free Trial link on the right - next to "SpySweeper for Home
Computers" to download the program.
Install it.
Once the program is installed, it will open.
It will prompt you to update to the latest definitions, click Yes.
Once the definitions are installed, close SpySweeper for now.

Reboot to safe mode.

Reboot and tap F8 then choose safe mode from the list

For additional help in booting into Safe Mode, see the following site:

http://www.pchell.com/support/safemode.shtml

Open SpySweeper again, click Sweep Now on the left side.
Click the Start button.
When it's done scanning, click the Next button.

Make sure everything has a check next to it, then click the Next button.

Open Adaware and from the main menu choose add-ons then left click the VX2
cleaner and choose run then follow the prompts on screen

Finally Run CWShredder and press Fix

Some of these may require you to reboot to finish the cleaning , If that
happens then run the others when the system restarts.

All The Best

Andy
 
G

Guest

Thanks for ur advice and it worked!

Followed th procedure tht u suggestd and all th spyware remover incl
CWShredder found positive traces but added in MS Antispyware after th
CWShredder. Funny thing is tht I stil find all th 3 spy/adware which I
started out when I run MS... MS prompted me to restart windows and I did,
only this time in safe mode (I hav always restarted in normal mode).

Anyway, when I run MS again, only th Look2Me is stil around and it is gone
 
G

Guest

CW Poh said:
I also tried to remove it manually via regedit but when i tried to delete th
following:

HKEY_LOCAL_MACHINE
\SOFTWARE\Classes\CLSID\{DDFFA75A-E81D-4454-89FC-B9FD0631E726}

access was denied.. headache!


i have the same thing same clsid too
i just downloaded the new defender and it says it deleted it
ran it again it doesnt come back up
have been trying to get rid of this for a long time now lol i hope it is gone
i am goona run spybot and adaware to see if it really gone
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top