Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

How to Get Rid of VX2-BetterInternet-Look2Me 1

Status
Not open for further replies.

Gabriel714

Programmer
May 19, 2004
2
0
0
US
I got the latest variant of this Look2Me spyware and I couldn't get rid of it. It also goes by the names of VX2.BetterInternet, VX2, NicTech, and some others.
It was found by Ad-Aware and ScanSpyware, but even after removal, on reboot they came coming back. And each time they loaded more parasites onto my system.
I finally found out how the damned thing worked and got removal instructions which absolutely cleaned my system. The cleansing routine is here:
If you've got these variants and their pestulant pop-ups and browser hijacking, the longer you wait to remove them, the more work you'll have to do.
 
Gabriel714

Theres a little more to it than just deleting the file(s).

You still have a reg key under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
called Guardian<something> that will attempt to load a now, non-existent dll file.
Those VX2 files also remove the Administrators group from the local security policy, and denying access to the seDEBUG privilege.
With WinXP Pro or 2K Pro you can re-add the policy using the policy editor/User Rights Assignment
WinXP home users are out of luck.
or
This program will fix it all

Also will repair the seDEBUG policy automatically in any version of NT Windows
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top