Skip to main content

Adware:W32/Look2Me

Classification

Category:

Spyware

Type:

Adware

Aliases:

  • Adware.Look2Me
  • NicTech Networks

Summary

This program delivers advertising content to the user. It is usually annoying but harmless, unless it is combined with spyware or trackware.

Removal

Technical Details

Look2Me is an adware program made by NicTech Networks Inc and may be bundled together with other software, or silently installed by trojans.

The program operates in stealth on machines running Windows 2000, XP and 2003. The name Look2Me references the servers the earlier program versions connected to, though the program nowadays will connect to www.ad-w-a-r-e.com.

The advertisements Look2ME displays are most commonly Internet Explorer pop-up windows, but may also be customized in shape and animation to fit the advertising content.& and displays an excessive amount of pop-up advertisements.& An example of a Look2Me pop-up advertisement is as follows:

Some of the advertisements push the user to install ErrorGuard or WinFixer.

Installation

Look2Me may be silently installed together with other software, or it may be silently installed by a trojan. Look2Me cannot independently replicate itself and must be manually installed onto each system it infects.

The program uses a guardian implementation to prevent removal. It does so by removing Debug privileges from all user accounts, attaching a Notification package to Winlogon and monitoring all user policy rights and system settings. During installation, the Explorer program is restarted and the computer is made to look as though it will shut down. In fact, during this time, the guardian implementation program is being installed on the system.During installation, Look2Me will register itself as a COM component, using a random filename (though it will typically use a DLL extension). The program also creates a randomly named Class ID key (CLSID) to identify itself as a COM component, and a related registry key to approve the CLSID for execution.

Registry Modifications

Creates these keys:

  • HKLM\Software\Windows\CurrentVersion\Shell Extensions\Approved
  • HKLM\Software\Microsoft\Windows NT\Current Version\Winlogon\Notify Asynchronous = 0 DllName = Impersonate = 0 Logon = "Winlogon" Logoff= "WinLogoff" Shutdown = "WinShutdown"

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.