Unable to get rid of VX2. Look2Me spyware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Alekz, Nov 3, 2005.

  1. Alekz

    Alekz Private E-2

    Hi,

    I don't know how to get rid of VX2.Look2me spyware, CWShredder detects it and removes but after reboot it appears again.
    I also tried Ad-aware, Spybot, Ewido, but they don't help. I post my Hijackthis and l2mfix logs. Please help!
     

    Attached Files:

  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Welcome to MajorGeeks.com, please follow the steps below:

    [​IMG] Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    • Make sure you check version numbers and get all updates.
    [​IMG] Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

    [​IMG]After doing ALL of the above and you still have a problem, make sure you have booted to normal mode and run the steps in the below thread to properly use HijackThis and attach the log:

    [​IMG] Downloading, Installing, and Running HijackThis
     
  3. Alekz

    Alekz Private E-2


    I've already done all the steps that u mentioned before posting this thread:
    1) Disabled system restore.
    2) Downloaded latest programs and updates (Adaware, Spybot, etc).
    3) Scanned my comp in safe mode with LAN cable unplugged. With Ad-aware, MS Anti-spyware, Spybot, Ewido, CCcleaner, CWSshredder and Kiil2me.
    4) Did online tests with Kaspersky and bit Defender.

    CWShredder finds VX2.Look2me and removes it, but after every restart it appears again. So after all this I posted my Hijackthis and l2mfix logs.
    That's why I hope u can help me.
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    - Download, install and update Spy Sweeper Run it once while you are in normal boot mode.

    - The boot in safe mode from and run SpySweeper one more time.

    Now reboot in normal mode.

    Save and attach the logs from both runs along with a fresh HJT log from normal mode.
     
  5. Alekz

    Alekz Private E-2

    I did like you said, but it seems like I have problems with Spy Sweper. When I start scanning, it works properly but at some point it crashes and gives error message (check attachment pic). It happens both in safe and normal boot moode. So, is there any other solution? :confused:
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    If you close the program and re-open it does it still do it? If so, uninstall Spy Sweeper, reboot and then download a fresh copy and reinstall it. Try a scan once more, if it still does it stop it after it finds a few things, remove those and scan again to see if it will go a little further.
     
  7. Alekz

    Alekz Private E-2

    I tried to scan several times, but it happened again. So I reinstalled it, but It still crashes after scanning about 105 000 files. :eek: I don't know what's going on, it seems like Spy Sweeper doesn't work for me :(
     

    Attached Files:

  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Go ahead and attach a current HJT log, we will worry about this later.
     
  9. Alekz

    Alekz Private E-2

    Ok, here is my HJT log.
     

    Attached Files:

  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your Operating System and Internet Explorer versions are WAY out of date and represent a major security risk. After we fix your current problems, you must get updated. You need to install Service Pack 2 for security purposes.


    Now scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)

    O16 - DPF: {27DE8550-C471-4378-87E3-EFE4CDA22174} (Installer Class) - http://www.id.ee/installer/InstallerExec.cab
    O16 - DPF: {2BD3E3A2-8D92-4438-B335-C1F3F75F83D6} (diskFile Class) - http://www.id.ee/installer/fileInfoUtil.cab
    O16 - DPF: {7C360B4D-3C03-44CA-9C05-A5AB6E029887} (Detect Class) - http://www.id.ee/installer/IDInstaller.cab

    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)

    O20 - Winlogon Notify: Shell Extensions - C:\WINDOWS\system32\enp2l17o1.dll (file missing)

    Again, make sure All Browser Windows are Closed when you Click FIX.

    NEXT:
    Run CCleaner to clean up cookies and temp files.

    Run full scans with Ad-Aware SE & Spybot S&D and have both programs fix what they find.
    Note: Remember to get all updates before doing the scans.


    After you complete the above REBOOT and attach a fresh HJT log.
     
  11. Alekz

    Alekz Private E-2

    Ok, here is my fresh HJT log. Seems like my PC is clean now.
    Thanx, bjgarrick, once again you helped me! Respect! :)
     

    Attached Files:

  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your HJT log is clean, you must now get updated. You need to install Service Pack 2 for many reasons.

    After you have updated your OS to SP2, you must then get all critical updates.

    After you have been completely update, reboot a few times and let me know how things are running.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds