|
|
|
|
Look2Me Spyware/Adware Definition
| Name: |
Look2Me |
| Category: |
Spyware |
| Alias: |
Spyware.Look2Me, ZestyFind |
| Advice: |
Remove |
| Risk: |
Elevated Risk
Elevated threats are usually threats that fall into the range of adware in which data about a user's habits are tracked and sent back to a server for analysis without your consent or knowledge. |
| Description:
|
Look2Me monitors the web sites you visit and sends the log to the vendor's server. Look2Me will also open pop-up windows.
Look2Me is implemented as a shell extension, which makes it tightly coupled with Explorer. If you try to remove Look2Me while Explorer is running, Look2Me will notice this and reinstall itself, which makes it hard to remove. The trick is to shut down Explorer before deleting the registry entries associated with spyware, reboot, and then delete the .dll file. It is also possible to remove Look2Me by booting up on start-up disks and delete the .dll file.
Look2Me's signs of infection range from pop-up windows, the msg-ish dlls in System directory, ICMP messages coming from www.look2me.com or your firewall warning about connections to www.look2me.com. Look2Me runs inside Windows Explorer not making any appearance in the Task Manager, neither in the Application List nor in the Process list. Look2Me might also connect to the Internet without your firewall warning you about it.
|
| Signatures:
|
process: no.exe: MD5 Hash: 630d95850577a34c6a4...
process: n20050308.exe: MD5 Hash: 619506373684cc4672b...
process: ffinst.exe: MD5 Hash: ee6ecc6abae5f4456fb...
process: n20050308.exe: MD5 Hash: bde4a9cbad8eca6a0d1...
process: wrapperouter.exe: MD5 Hash: 2c4c8410d034f41cf71...
process: n20050308.exe: MD5 Hash: e926054a6dd6009f2f0...
process: updinst.exe: MD5 Hash: af3f47df22f674143a7...
process: updinst.exe: MD5 Hash: af3f47df22f674143a7...
process: upd208.exe: MD5 Hash: e7fcb5921582681c5eb...
process: n20050308.exe: MD5 Hash: e926054a6dd6009f2f0...
process: icont.exe: MD5 Hash: a0c1f7715364718a0a7...
process: installer.exe: MD5 Hash: 42a20bae9cf9cb816a4...
process: installer.exe: MD5 Hash: 43acaff556b9ed7941e...
process: installer.exe: MD5 Hash: 42a20bae9cf9cb816a4.. |
| Type: |
Spyware - Spyware's primary purpose is to collect demographic and usage information from your computer, usually for advertising purposes. Spyware usually that 'sneaks' onto a system or performs other activities hidden to the user. Spyware programs are usually bundled as a hidden component and downloaded from the Internet. These modules are almost always installed on the system secretively and try to run secretively as well. |
|
Top Spyware Visited Pages:
007.2Search
007.msnnames
00Sub7_20
Advanced Email Monitoring
AlwaysUpdateNews
ATLEvents.BHO
ATPartners
Aureate
Axexx CHM
Banker.TU
Bridge/WinFavorites
Brodcast DSSAGENT
C2.Lop
CommonSearch VCatch
Conducent
|
|