Remove Look2Me. Description and removal instructions

 
Title: Look2Me

Type: Spyware
Severity scale:Look2Me severity is 51  (51 / 100)
 
Look2Me is a spyware parasite that tracks user Internet activity, logs web sites visited, user actions taken and sends gathered information to a predetermined remote server. It also secretly downloads from the Internet and installs other spyware and adware threats. Look2Me injects malicious code to the Windows Explorer process and other active tasks in order to complicate its removal. The parasite is able to silently update itself via the Internet. It automatically runs on every Windows startup.


Look2Me properties:
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Look2Me removal:

remover for Look2Me

Look2Me manual removal:

Kill processes:
inetfuel.exe, installer[X].exe, hp.exe, nictech_bundle[X].exe, rh.exe, se.exe, sed.exe, updinstall.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SESync
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\HP.Hopper
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\HP.Hopper.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SP.SmartPops
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SP.SmartPops.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\hp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{C81CFF28-6DF1-402F-B78C-D9493EF59882}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0421701D-CF13-4E70-ADF0-45A953E7CB8B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A7CD5137-D2D6-4E2F-8279-4E7631159712}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DDFFA75A-E81D-4454-89FC-B9FD0631E726}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E79061BA-B6E7-4A9D-A07C-C3CB561013B4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1423903E-86CC-4470-8AB0-257C10D77D45}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4DEA7CA1-3372-4204-937C-2DD4A6ED6562}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A42DC659-33B5-409E-A433-650AC42ECCA4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A8516F49-8046-4295-8EE9-C59D5041C9E2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FB82CCD5-174B-4379-BC37-72D9B5ADAEDA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{47350D97-09E9-4590-864E-3431DA53BF37}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FA777197-4BF7-4AA9-A088-A0D803198DE0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0421701D-CF13-4E70-ADF0-45A953E7CB8B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellExtensions\Approved\{DDFFA-E81D-4454-89FC-B9FD0631E726}
HKEY_CURRENT_USER\Software\Look2Me
HKEY_CURRENT_USER\Software\Hopper
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Recommended Hotfix - 421701D
Delete files:
inetfuel.exe, installer[X].exe, hp.exe, nictech_bundle[X].exe, rh.exe, se.exe, sed.exe, updinstall.exe, nsdtmp09.dll, rh.dll
Delete directories:
C:\Program Files\SED
C:\Program Files\Recommended Hotfix - 421701D
Misc:
[X] is a certain digit.

Look2Me uses numerous randomly named files and registry entries.

Exact file location:
inetfuel.exe, updinstall.exe - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
rh.exe, rh.dll - C:\Program Files\Recommended Hotfix - 421701D\[XVS]
se.exe, sed.exe - C:\Program Files\SED
nsdtmp09.dll - C:\Windows\Temp or C:\Winnt\Temp

[XVS] is the version number

Other programs to remove Look2Me:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 29/09/05
Information updated: 06/06/06

Additional resources related to Look2Me:

Attention: If you know or you have a website or page about Look2Me removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Look2Me parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Related news:
Similar parasites:
Related articles:
Related discussions: