Look2Me is killing me!! Help with Removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by tkolde00, Sep 7, 2005.

  1. tkolde00

    tkolde00 Private E-2

    I followed the general removal guidelines posted in this forum to a T. When running CWS shredder I constantly get the VX2.Look2Me popping up into my system. No matter how often I remove it still comes back. Please look at my HJT log and my l2mfix log included in this post. Any help would be useful! I've been at this for days :-(

    Thanks,
    tkolde00
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please disable Spybot's Teatimer as it can get in the way of fixing things.

    To disable TeaTimer, run Spybot and click Mode and select Advanced Mode. Then click Tools and select Resident. Now in the right window pane, uncheck TeaTimer.
    Also while this is open, in the left column now select IE Tweaks and then in the right pane make sure all the Miscellaneous locks are unchecked.
    Now quit Spybot!

    Then run L2MeFix again and choose option 2 this time instead of option 1. Post the log from L2MeFix again.

    Now also post a new HJT log (make sure you are in normal boot mode this time). You have more problems we need to fix.
     
  3. tkolde00

    tkolde00 Private E-2

    Tea Timer is disabled and I ran both HJT and L2MeFix and posted the logs.

    Thanks for you help...
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must ony use one antivirus application. You appear to be using both Symantec and AV Personal. Pick the one you prefer and uninstall the other. Do this before continuing.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O4 - HKCU\..\Run: [Aaou] C:\Program Files\ipee\othb.exe
    O4 - HKCU\..\Run: [Cgvr] C:\WINDOWS\System32\w?auboot.exe
    O4 - HKCU\..\Run: [Pywyv] C:\WINDOWS\system32\??stem32\msconfig.exe
    O4 - HKCU\..\Run: [Tbsa] C:\Program Files\trus\astr.exe
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\ipee <--- the whole folder
    C:\Program Files\trus <--- the whole folder
    C:\WINDOWS\System32\w?auboot.exe
    C:\WINDOWS\system32\??stem32 <--- the whole folder! Be careful!!!! Do not delete c:\windows\system32!!!! You are looking for another subfolder within the c:\windows\system32 folder named ??stem32. The ?? could be anything. When you find the correct subfolder you should see msconfig.exe in it and probably very few other files. If you are not sure, don't delete it! Just come back and tell me what you found.

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. tkolde00

    tkolde00 Private E-2

    Here is what I did...

    1. Removed Symantec
    2. Double checked that system restore is disabled (still is).
    3. Double checked that view all (hidden included) files and folders is on (still is).
    4. Ran HJT and fixed all listed problems.
    5. Could not find c:\Program Files\ipee
    6. Deleted: c:\Program Files\truss
    7. Could not find c:\WINDOWS\System32\w?auboot.exe (I cannot find anything that contains w*auboot.exe or *auboot.exe)
    8. Deleted: c:\WINDOWS\System32\??stem32 (the actual folder was c:\WINDOWS\System32\system32)
    9. Ran Ccleaner
    10. Cleaned out c:\windows\Prefetch

    I also realized that I was running msconfig and selective startup; I've since disabled this and now load everything. This was done before I posted this HJT log.

    Thanks for the help so far, this is going a lot smoother than expected! You guys are great!

    ~tkolde00
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well your log is clean now! How are things working?

    However you still have some Symantec stuff:

    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

    Are you sure you uninstalled ALL of it? You may need to give this a run: Norton Removal Tool (SymNRT)

    If that does not work we may need to do it manually.
     
  7. tkolde00

    tkolde00 Private E-2

    THANK YOU!

    I was able to remove the additional Symantec stuff and have had zero problems all day. The machine is much faster and I have yet to have a pop-up or anything inadvertantly try to load.

    I appreciate the help.

    ~tkolde00
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds