Tuesday, March 21, 2006

Adware.Look2Me

What is this Adware.Look2Me?
Recently my system was infected by this Trojan/backdoor. How am I going to get rid of this is the riddle and the climax of the post.
Before how to get rid of it let us see what it is in first hand.

A TROJAN is a destructive program that masquerades as a benign application. Unlike viruses, Trojan horses do not replicate themselves but they can be just as destructive. One of the most insidious types of Trojan horse is a program that claims to rid your computer of viruses but instead introduces viruses onto your computer.
The term comes from the a Greek story of the Trojan War, in which the Greeks give a giant wooden horse to their foes, the Trojans, ostensibly as a peace offering. But after the Trojans drag the horse inside their city walls, Greek soldiers sneak out of the horse's hollow belly and open the city gates, allowing their compatriots to pour in and capture Troy.

What happens when this Adware.Look2Me resides in your system? It will start to initiate lots and lots of popup which will pester you. Even for my surprise I saw mozilla firefox was not able to stop the popup. I use Mozilla and IE. In both popups started to shoot out.
Then in the process of getting rid of this one we came across two files which are many times suspected as viruses as alg.exe and svchost.exe. But they are not to know more about them here you can see

alg.exe = Application Layer Gateway Service
svchost.exe = Host process for services

Getting to conclusion that these are not malicious I went into search of some malware remover. In that process I found ewido anti-malware and Ad-Aware personal by lavasoft a freeware. But both found out that there is adware.look2me but both didn't remove it. But I got the clue that it is in guard.tmp file and cookies are affected by it.

Now I am left with google, some clues like guard.tmp, adware.look2me, popups. The default work around was to restore the OS as I am using WIN XP which gives that provision. But I may loose some info during that process. I need some workaround soon even a better fix is welcomed but where it is. Believing that this is not mission impossible and the world in hand(google) I found a forum in which they gave me the solution.

Check out the link l2mfix It was really cool and I am free of popups now.

Later my friend Mr.Jayaraj an Antivirus researcher working for facetime concern gave me the following links which are useful the situations I was.
"
http://x-raypc.com
http://spywareguide.com
http://vmware.com
free anti-spywares...Windows defender.(Microsofts anti-spyware product still in beta), Ad-Aware (lavasoft)
"
Atlast the thought in my mind is let me post this info so that my friends may get benefitted in future.

4 Comments:

Anonymous Anonymous said...

Sounds interesting. You proved to be a good google user. Hats off to google.

Tue Mar 21, 10:29:00 PM PST  
Blogger Krishna Ram Kuttuva Jeyaram said...

i have one workaround for popups. use 8086 multiprocessor kit ;-).. though it will take a day for writing "hello world" program.. ;-)

Mon Apr 10, 01:53:00 AM PDT  
Anonymous Anonymous said...

Splendid blogsite you have here! Very interesting information. Please come and visit adware stopper sometime.

Tue Apr 18, 10:13:00 AM PDT  
Anonymous Anonymous said...

Thanks for posting up the link to the look2me remover. I was going crazy trying to remove it - the programme on your blog worked! Cheers.

Sun Jun 11, 07:00:00 PM PDT  

Post a Comment

<< Home