Forum     

Go Back   Digit Technology Discussion Forum > Portables, Peripherals and Electronics > QnA (read only)
Register FAQ Calendar Mark Forums Read

QnA (read only) Mods please help transfer the contents of this forum to proper sections. :)


 
 
LinkBack Thread Tools Search this Thread Display Modes
Old 24-03-2006, 07:05 PM   #1 (permalink)
Alpha Geek
 
Join Date: Jan 2005
Location: earth
Posts: 804
Default infected by look2me adware


my pc is infected by look2me adware, flash animations, popups keep appearing, i have tried every software available in net but none of them helped me. i have tried following softwares, webroot spysweeper, adaware SE, spybotSand D, microsoft antispyware, norton antivirus, mcafee antivirus and antispyware,norton look2me removal tool

although every software detects it but none of them is able 2 remove it, they remove it temporarily but after restarting it appears again, webroot is somewhat effective as it stops the popups but adware is still there?

pls help me, is formatting is the only option??
__________________
signature??? :???: Let Me Think About It!!!:-D
paul_007 is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 24-03-2006, 07:29 PM   #2 (permalink)
Alpha Geek
 
Join Date: Mar 2005
Posts: 517
Default

try this link

http://www.pchell.com/support/look2me.shtml
__________________
\" I Do not like to repeat success , i like to move on to other things \"
mako_123 is offline  
Old 24-03-2006, 07:57 PM   #3 (permalink)
Alpha Geek
 
Join Date: Jan 2005
Location: earth
Posts: 804
Default

no it is not working, tried the automatic method it says look2me not detected in r pc and i also tried manual method, the registries entries which they r asking me 2 delete is not present in my registry

thnx 4 help
__________________
signature??? :???: Let Me Think About It!!!:-D
paul_007 is offline  
Old 25-03-2006, 12:31 AM   #4 (permalink)
Alpha Geek
 
Join Date: Mar 2005
Posts: 517
Default

Try googling for the help , you will get a lot of sites .
__________________
\" I Do not like to repeat success , i like to move on to other things \"
mako_123 is offline  
Old 25-03-2006, 01:32 AM   #5 (permalink)
Wise Old Owl
 
Join Date: Dec 2004
Location: South Side Crater, Mars
Posts: 1,038
Default

format your PC....backup your data and format it..

since you have tried almost all of the known spyware detection tools,and they are unable to remove it.you can though try hijackthis
grinning_devil is offline  
Old 25-03-2006, 02:17 AM   #6 (permalink)
18 Till I Die............
 
Join Date: Jul 2004
Location: India, Mumbai, Marine Lines
Posts: 5,792
Default

Have you tried running the anti-spwares in safe mode? It has worked in the past for me.
__________________
http://www.bash.org/?258908
mehulved is offline  
Old 25-03-2006, 08:55 AM   #7 (permalink)
Broken In
 
Join Date: Feb 2006
Location: C:\Windows\System.....
Posts: 156
Default

install windowz Again...
Chindi_Chor is offline  
Old 25-03-2006, 09:51 AM   #8 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default

Quote:
Originally Posted by tech_your_future
Have you tried running the anti-spwares in safe mode? It has worked in the past for me.
do this. run ur ant-spys in safe mode, or schedule boot-time scans, ver posbl.
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
anandk is offline  
Old 25-03-2006, 03:15 PM   #9 (permalink)
Alpha Geek
 
Join Date: Jan 2005
Location: earth
Posts: 804
Default

OK i'll try in safe mode
__________________
signature??? :???: Let Me Think About It!!!:-D
paul_007 is offline  
Old 25-03-2006, 05:26 PM   #10 (permalink)
Alpha Geek
 
Join Date: Jan 2005
Location: earth
Posts: 804
Default

yeah this has worked quite a lot

but popups still appear but very rarely , once in every 2 hours

thnx everyone
__________________
signature??? :???: Let Me Think About It!!!:-D
paul_007 is offline  
Old 25-03-2006, 05:46 PM   #11 (permalink)
18 Till I Die............
 
Join Date: Jul 2004
Location: India, Mumbai, Marine Lines
Posts: 5,792
Default

Still that is not good enough. Have you tried out different anti-spywares or just one? If not, do a thorough scan with different anti-spywares and check out the results.
If this fails too, you can run hijackthis and post the results onwww.hijackthis.de for analysis. And remove the malware detected.
__________________
http://www.bash.org/?258908
mehulved is offline  
Old 25-03-2006, 05:56 PM   #12 (permalink)
Alpha Geek
 
__Virus__'s Avatar
 
Join Date: Sep 2005
Location: Hyderabad
Posts: 560
Default

Quote:
Originally Posted by paul_007
yeah this has worked quite a lot

but popups still appear but very rarely , once in every 2 hours

thnx everyone
naaaah still not guud....scan in safe mode again and probably post ur hijackthis log so that someone can analyze and help u out.
__Virus__ is offline  
Old 25-03-2006, 06:49 PM   #13 (permalink)
Wandering in time...
 
Ankur Gupta's Avatar
 
Join Date: Nov 2004
Location: Delhi,India
Posts: 1,293
Default

well the best thing is to format ur pc and install windows again if the adware is not being removed by the antivirus or anti-adware software.
and remember to backup!
Ankur Gupta is offline  
Old 25-03-2006, 09:59 PM   #14 (permalink)
Alpha Geek
 
Join Date: Jan 2005
Location: earth
Posts: 804
Default

here is my hijack log

Logfile of HijackThis v1.99.1
Scan saved at 9:58:32 PM, on 3/25/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\Hummbird\inetd32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Sify Broadband\BBImpSec.exe
C:\Program Files\Sify Broadband\BBClient.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
D:\softwares\HijackThis.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sify.com
F2 - REG:system.ini: UserInit=userinit.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: &Save Flash - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files\Save Flash\SaveFlash.dll
O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [SifyBB] C:\Program Files\Sify Broadband\BBImpSec.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download All Links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Download with NetPumper - C:\Program Files\NetPumper\AddUrl.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{548F1E1C-2F42-4AFF-966A-ABD5E203F2F5}: NameServer = 202.144.50.4,202.144.13.50
O20 - Winlogon Notify: BITS - C:\WINDOWS\system32\m2julc191f.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Hummingbird Inetd (HCLInetd) - Hummingbird Communications Ltd. - C:\WINDOWS\System32\Hummbird\inetd32.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
__________________
signature??? :???: Let Me Think About It!!!:-D
paul_007 is offline  
Old 25-03-2006, 10:17 PM   #15 (permalink)
Commander in Chief
 
QwertyManiac's Avatar
 
Join Date: Jul 2005
Posts: 6,658
Default

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
O8 - Extra context menu item: Download with NetPumper - C:\Program Files\NetPumper\AddUrl.htm
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

Remove NetPumper from yr sis and for best results use only one D/l-Manager

and perhaps these too...
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

W8 for more hlp
__________________
Harsh J
www.harshj.com
QwertyManiac is offline  
Old 26-03-2006, 11:23 AM   #16 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default

yes u need to remove the default search url : searchbar.
eif u use ms anti-spy, u can use it to restore all ie browsers default urls/pages, easily.

posting ur hijackthis logfile at www.hijackthis.de will give u a detailed analysis.
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
anandk is offline  
Old 26-03-2006, 11:27 AM   #17 (permalink)
Alpha Geek
 
Join Date: Jan 2005
Location: earth
Posts: 804
Default

hijack this is not able to remove these

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

it says use spybot to remove them and when i use spybot , although it removes them but after restarting these files appear again
__________________
signature??? :???: Let Me Think About It!!!:-D
paul_007 is offline  
Old 26-03-2006, 06:39 PM   #18 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default

idmmbc.dll could b a legit file or a malware. it cud b a part of 'Internet Download Manager' software. Idmmbc.dll is the LSP DLL. so check its properties first. http://www.spywaredata.com/spyware/m...idmmbc.dll.php

if u feel ur winsock lsp has been damaged see this
http://www.download.com/LSP-Fix/3000...-10417025.html

schedule boottime scan of spybot and restart pc, and c what happens. there is such an option in spybots settings. hope 4 d best !
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
anandk is offline  
Old 27-03-2006, 06:41 PM   #19 (permalink)
Alpha Geek
 
Join Date: Jan 2005
Location: earth
Posts: 804
Default

Quote:
idmmbc.dll could b a legit file or a malware. it cud b a part of 'Internet Download Manager' software. Idmmbc.dll is the LSP DLL. so check its properties first. http://www.spywaredata.com/spyware/m...idmmbc.dll.php

if u feel ur winsock lsp has been damaged see this
http://www.download.com/LSP-Fix/3000...-10417025.html

schedule boottime scan of spybot and restart pc, and c what happens. there is such an option in spybots settings. hope 4 d best ! Smile
thnx , thnx , thnx a lot finally this has worked 4 me

now no popups r appearing

the file idmmbc.dll was the cause and i removed it using winsock lsp fix but i think this was not a part of Internet Download Manager cause i am usin this since 4 months and it havnt creatd any problem 4 me, the problem started when i installed a software frm a warez site.
__________________
signature??? :???: Let Me Think About It!!!:-D
paul_007 is offline  
 

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 
Latest Threads
- by Tenida
- by clinton
- by gohan89
- by icebags

Advertisement




All times are GMT +5.5. The time now is 08:10 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2