F-Secure: Be Sure
Main
F-Secure Logo - Be Sure
Select local site


Privacy Policy
Contact Us

F-Secure Spyware Information Pages : Look2Me

[ Summary ] | [ Disinfection ] | [ Detailed Description ]

Name:Look2Me
Alias:Adware.Look2Me, NicTech Networks
Type:Adware
Category:Spyware
Platform:Win32
Author:NicTech Networks Inc.
Website:http://nictechnetworks.com/

Summary

Look2Me adware operates in stealth and displays an excessive amount of pop-up advertisements. Most common are IE pop-up windows, but some pop-ups are tailored by shape and animation. Some of the advertisements push the user to install ErrorGuard or WinFixer. Look2Me requires a special removal tool to disinfect. Look2Me only infects Windows 2000, XP and 2003.

Disinfection

Use F-Look2Me to remove Look2Me.

  1. Download f-look2me.zip (last updated April 11th, 2006)

    www.f-secure.com/tools/f-look2me.zip

  2. Unzip f-look2me.zip
  3. Run f-look2me.exe
  4. Reboot the machine

F-Look2Me loads itself as a service to gain system privileges. The service renames infected files and patches the adware in memory. It also restores Debug Privileges for group Administrators. F-Look2Me requires administrator rights to run.


Back to the Top


Detailed Description

Look2Me adware is made by NicTech Networks Inc. The name Look2Me originates from the servers that the earlier versions connected to. Today, Look2Me adware connects to www.ad-w-a-r-e.com.

The image below is an example of one of the many pop-ups Look2Me produces:



Look2Me is installed in stealth by trojans. During the install process, Explorer is restarted and it initially looks like the computer will shutdown. It does not shutdown but instead installs the guardian to the system.

Look2Me uses a guardian implementation to prevent removal. The guardian implementation attaches a Notification package to Winlogon and monitors users policy rights and system settings. Look2Me removes Debug Privileges from all user accounts. Look2Me does not implement any rootkit techniques and will therefore not be detected by BlackLight.


Back to the Top


Write-up: Stefan Lundstrom, April 11, 2006

Technical Details: Stefan Lundstrom, April 11, 2006

F-Secure Corporation