Please help, unable to remove VX2.Look2me (WinFixer and other pop-ups)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jazzy, Sep 1, 2005.

  1. jazzy

    jazzy Private E-2

    My symptoms are that in IE I sometimes get the following window:
    http://forums.majorgeeks.com/attachment.php?attachmentid=22690&stc=1

    Also at times I get the following pop-up window which tries to redirect the browser to advertisements. I have attached a graphic of what that page looks like.

    I also get pop-up windows that are for WinFixer.com.

    So I tried everything mentioned in the Basic Spyware, Trojan And Virus Removal thread. Which has led me to believe that VX2.Look2me is causing these issues. Because CWShredder was able to identify that VX2.Look2me is on my machine, but unable to remove it when I tried to have it removed. Also Kill2me could not remove it. No matter if I was in Safe Mode or not it will not go away.

    So I am not stuck and unable to figure out how to remove it. Best I've been able to do so far is prevent the browser hijacks from actually going to a site by restricting the problem domains, but the browser window still pop-up.

    Can someone please help me get rid of VX2.Look2me?
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's see what we can see first. Please follow the below steps exactly:


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).

    Then, just in case you do have a Look2Me VX2 infection, let's look for it by doing the below:

    Download the following tool and save it where you will be able to find it.

    L2MeFix Tool

    Please print out these instructions now or save locally so that you can operate with All Browser Windows CLOSED.

    Exit Browsers now before continuing

    Please move the L2MeFix Tool to your Desktop and DoubleClick l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix Folder on your Desktop. DoubleClick l2mfix.bat and Type 1 and ENTER to select Option #1 for Run Find Log . Allow it as much time as it needs to run until NotePad opens with a log.

    NOTE: Please do not run any other options or files in the l2mfix Folder!

    Now reconnect and come back here and post as an attachment the l2mfix log.
     
  3. jazzy

    jazzy Private E-2

    I have completed both task and both log files are attached.

    Thank you for your help.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have a Virtumundo problem Vundo.B). We are seeing a bunch of these again lately.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.

    On the page that opens, scroll down to CWShredder Service ... right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    CWShredder Service

    Now exit HJT and do not reboot if it asks you to do so. We will be restarting HJT in a few lines.


    Okay let's start by downloading two tools we will need:

    - Process Explorer 9.2

    - Pocket KillBox

    Extract them to there own folder somewhere that you will be able to locate them later.

    Reboot in Safe Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of vtutr.dll once and then click the kill button. After you have killed all of the vtutr.dll's under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of vtutr.dll then click the kill button. Once you have done that click ok again. (If you do not find the dll, just continue on.)

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\system32\vtutr.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O20 - Winlogon Notify: vtutr - C:\WINDOWS\system32\vtutr.dll



    Copy the bold text below to notepad. Save it as fixVundo.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.


    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot.

    C:\WINDOWS\System32\vtutr.dll
    C:\WINDOWS\System32\rtutv.ini2
    C:\WINDOWS\System32\rtutv.bak2
    C:\WINDOWS\System32\rtutv.bak1
    C:\WINDOWS\System32\rtutv.ini
    C:\WINDOWS\System32\rtutv.tmp


    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    After reboot post a new HJT log.
     
  5. jazzy

    jazzy Private E-2

    I have completed those tasks and my latest log is attached.

    Thank you again.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Your log is clean! How are things working?
     
  7. jazzy

    jazzy Private E-2

    Everything appears to be working great :cool: .

    Thank you very much!

    I was starting to think a format C:\ was in my future :D .
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  9. jazzy

    jazzy Private E-2

    Will do. God Bless you and the other good folks here for your good work!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds