problem with look2me just can't kill it xp pro

Discussion in 'Malware Help (A Specialist Will Reply)' started by Trevor_at_tal, Dec 18, 2005.

  1. Trevor_at_tal

    Trevor_at_tal Private E-2

    HI I've been trying to sort this for 2 days now. PC was infected from a website I think by one of my kids. PC went mad opening lots of pop up windows and my firewall (norton) went made as well.

    System XP Pro version 2002 service pack 2 and all the updates, Petium(R)4 with 199M ram,

    Have run Norton antivirus, Microsofts beta antispyware, CCleaner, ewido several times. ewido keeps killing virus but look2me keeps coming back

    reporting these files and others as infected and says it is deleting them, but when I scan again they just pop back up and are deleted again and again.
    Sirobj.dll Country.exe dropper.Raven kl.exe Logger.Small.dg lh60 Sinwal.a

    But this one is the one that just keeps poping up in memory scans
    mdctf.dll

    I think this is look2me

    I ran l2mfix, oops, followed another thread and wish I had posted this first. I ran report but did not keep copy. Then I ran option 2, left PC for over an hour but nothing seemed to be happening, was very tiered and re booted.
    Now have 2 new logins I did not create, one called Adminstrator and one called l2mfix, l2mfix requires a password to logon which I do not have as did not create.

    Before and after l2mfix I tried running antiviris software from safe mode, but still infected. I have to block traffic with my norton firewall otherwise the pop-ups come so fast I spend all my time deleting them.

    I am writing this from my laptop which I think is clean.

    Where do I go from here - Help please

    Best regards
    Trevor :eek: :eek:
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note: the Administrator login is always there and normally only appears when you boot in safe mode. The l2mfix is created by L2MeFix and it cleans it up after you properly complete running the tool. If it does not complete properly the account may not be cleaned up.
     
    Last edited: Dec 19, 2005
  4. Trevor_at_tal

    Trevor_at_tal Private E-2

    Thanks guys for your help. Silly me about adminstrator on safe mode dahhh.

    I have tried to run spy sweeper but ended up with spydoctor when I followed the link. I ran it and it found 22 problems. I was not able to de-select scanning the registry as it auto ran after down loading updates. It also does not kill problems unless I purchase and does not allow me to copy report.

    I can purchase it if this is the correct product? Tried following 2 links from your post both ended up at the same spydoctor?

    What next??

    Merry Christmas to you guys to
    Thanks
    :confused:
     
  5. Trevor_at_tal

    Trevor_at_tal Private E-2

    I managed to find log and copy to notepad as requested. I have saved as spysweeper and attached. BUT this was Spydoctor!! if it makes a difference

    Thanks again:)
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The link I gave you goes to a procedure for downloading, installing and running Spy Sweeper not Spy Doctor. Spy Doctor is not very useful as you have found. Uninstall SpyDoctor! You do not want it or need it. Click the link I gave you in message # 2 and in it there is another link to click during the procedure to download Spy Sweeper. I'm not sure what you were doing but it works perfectly fine for me.
     
  7. Trevor_at_tal

    Trevor_at_tal Private E-2

    HI down loaded and bought spy sweeper, Have deleted infected files as requested and copied to notepad log file see attached.

    However still have pop ups

    ewido see to sound an alarm when the PC starts up when the personnal setting are loaded!! so I guess this is when look2me loads it's self. Don't know if this helps.

    Now have ewido, norton, spysweeper and MS antispyware running and the little B is still slipping through ahhhhhhh :eek:

    Thanks for the help

    regards
    Trevor
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you run a scan with Ewido? If so please post the log from Ewido and then uninstall Ewido and MS AntiSpyware (since you have purchased Spy Sweeper you do not need them) and reboot. After reboot, follow the steps below:

    Make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis

    .
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It looks to me like you either did not tell Spy Sweeper to fix anything or you ran the scan while you did not own it and it would not fix the problems. You may need to run a new scan and make sure you fix the problems. Lines similar too the below should show in your log:

    09:47: File Sweep Complete, Elapsed Time: 00:32:27
    09:47: Full Sweep has completed. Elapsed time 00:36:47
    09:47: Traces Found: 147
    09:48: Removal process initiated

    things being fixed or quarantined would be listed here.

    09:48: Removal process completed. Elapsed time 00:04:14
     
  10. Trevor_at_tal

    Trevor_at_tal Private E-2

    Hi I ran spy sweeper a again and it seemed to clear all the problems and came up showing clear. I ran it and Ewido after re-booting a couple of times and all seems clear. NO MORE POP UPS
    Thanks very much, I was at my witts end and your help will make xmas a lot less stressful - Thanks again - merry xmas

    I have uninstalled antispyware and will also remove Ewido tonight as suggested. Should I remove Norton anti virus and firewall? it's not my favorate and is asking for me to re-new?? I have a router hw firewall. I do not think spy sweeper is a firewall.

    Really do appreciate the help by the way
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. I would not recommend having multiple full blown active protection tools like Ewido, Spy Sweeper, MS Antispyware running on your system indefinitely. They will use too much of your system horsepower and can also conflict with each other. It is okay to do this as a temporary procedure to get things cleaned up, but it is not recommended for long term.

    If you are going to buy Spy Sweeper, then keep it and remove Ewido and MS AS.
    If you are not going to buy anything, keep only MS AS since it is free.

    You should also work thru the below:

    How to Protect yourself from malware!


    Enjoy the holidays malware free!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds