We stand with Ukraine to help keep people safe. Join us

Look2Me

Look2Me is a family of malware, mostly consisting of adware and spyware, that’s typically bundled with seemingly legitimate software. It collects sensitive user data or displays advertisements. Look2Me is particularly prevalent on Windows, but one of our users found similar spyware on Android and was able to find it with Clario Anti Spy’s Spyware scan. If you use iOS, check your device is safe with Device system check.

Table of contents

What is Look2Me?

Look2Me is a sophisticated class of adware and spyware linked to the VX2 virus that displays intrusive pop-up ads and steals valuable personal information. It generally makes its way onto a computer via a trojan or it comes bundled with other supposedly innocent software. Primarily affecting Windows systems, Look2Me spyware is carefully hidden away and difficult to find and remove once in place.

How Look2Me works

Like many other adware and malware examples that typically infect Windows, the Look2Me family of infections injects itself into processes for legitimate programs so that it doesn’t show up in Task Manager and is more difficult to detect using antivirus tools. Look2Me also changes system registry files, giving it greater control of your computer.

 

One of the most concerning aspects of Look2Me spyware is that it uses a network of hidden DLL files to revive itself over and over again. Even if you’re able to kill part of the virus, another will spring into action to bring it back to life, and this cycle will continue to keep the infection alive unless you simultaneously eliminate all traces of Look2Me.

Signs of Look2Me infection

The most obvious sign of a Look2Me infection is frequent pop-up ads that typically appear when browsing the web. They may also show inside other apps, in the Windows notifications panel, and on your desktop. Other signs can include:

  • Browser redirects to suspicious webpages
  • Changes to your default homepage or search engine
  • Slower system performance and crashes.

Although Look2Me is predominantly a Windows virus, modern spyware like this is found on a wide range of platforms, including Android and iOS, all the time. One Clario Anti Spy user became wary of an infection on their Android phone after noticing their spouse was aware of their private conversations and whereabouts. With the help of our support agent Fane, they used Clario Anti Spy’s Spyware scan to identify and remove potentially dangerous apps from their device. Here’s how you can do the same:

  1. Install the Clario Anti Spy app.
  2. Open the Anti Spy app, then under Spyware scan, tap Fix.
  3. Once the scan is complete, you’ll see a list of suspicious apps with access to device features and permissions. Tap Let’s fix it to deal with them all.
Clario Anti Spy's Spyware scan feature on Android. If you're worried about spyware like Look2Me, use Spyware scan to find suspicious apps and fix permissions access.
Tap Fix under Spyware scan, then choose Let's fix it

After going through these steps, our concerned client found several apps on their device that they didn’t recognize, and our support agent, Fane, provided guidance on how to remove them. We also helped the user increase their privacy protections by adjusting their location settings to revoke access to apps that don’t need GPS.

 

If you have an iPhone, you can instead use Clario Anti Spy’s Device system check to determine if your device is up to date or is jailbroken. If a jailbreak is detected, this is a sign that someone has hacked your iPhone to install unauthorized apps like spyware. Try this:

  1. Download Clario Anti Spy.
  2. Open the app, then under Device system check, select Scan.
  3. You’ll now see whether your device is up to date or if it’s jailbroken. Update your iPhone if necessary or reset it to remove a jailbreak and unauthorized apps.
Clario Anti Spy's Device system check tool on iOS. If you're worried about spyware like Look2Me on your iPhone, use Device system check to see if your phone is out of date or jailbroken, which could signal the presence of unauthorized apps.
Tap Scan under Device system check, then check the results

How to remove Look2Me from your browser

Look2Me spyware commonly identifies itself as an extension and will take over your web browser once it makes its way onto your device. You’ll need a dedicated malware removal tool or antivirus program to completely remove all traces of the Look2Me infection from your system. Still, you can first fix your browser to download these tools by removing any suspicious and unrecognized extensions and checking your browser’s settings.

 

Here’s how to remove Look2Me from your browser:

  1. How to delete Look2Me from Google Chrome
  2. How to get rid of Look2Me from Mozilla Firefox
  3. How to remove Look2Me from Safari
  4. How to delete Look2Me from Microsoft Edge

1. How to delete Look2Me from Google Chrome

To delete Look2Me spyware from Google Chrome, first open the browser and then follow these steps:

  1. Open the Chrome menu, then select Extensions > Manage Extensions.
  2. Click the Remove button to delete any extensions you don’t recognize.
  3. Return to the Chrome menu, then choose Settings.
  4. Click Reset settings > Restore settings to their original defaults.
  5. Select Reset settings to confirm.
The Google Chrome browser menu on Mac. To remove Look2Me from Chrome, first go to the Extensions section and remove any extensions you didn't install yourself.
Step 1. In the Chrome menu, go to Extensions > Manage Extenions
The Extensions section in Google Chrome on Mac. If you need to remove Look2Me from Google Chrome, go to the Extensions menu and get rid of any extensions you don't recognize or use.
Step 2. Remove any extensions you don't recognize or use
The Settings option in the Google Chrome menu on Mac. If you're concerned about a Look2Me infection in Google Chrome, go into the Settings menu to reset your browser's settings.
Step 3. In the Chrome menu, click Settings
The Restore settings option inside Google Chrome's settings menu on Mac. You can use this to reset all browser settings when you need to remove Look2Me spyware from Google Chrome.
Step 4. Go to Reset settings > Restore settings
The Reset settings confirmation prompt in Google Chrome on Mac. Reset all your browser settings to revert changes made by the Look2Me malware on in Google Chrome.
Step 5. Click Reset settings to confirm

This process will remove any infected files and extensions from Chrome, and eliminate any redirects and malicious homepages that Look2Me has set. I also recommend that you learn how to block pop-up ads on Chrome in case you run into adware in the future.

2. How to get rid of Look2Me from Mozilla Firefox

If you use Firefox and want to get rid of Look2Me, try this:

  1. Open the Firefox menu, then choose Add-ons and themes.
  2. Go through the list of extensions and select the three dots, then Remove next to any you don’t recognize.
  3. Return to the Firefox menu, then click Help.
  4. Select More troubleshooting information.
  5. Under Give Firefox a tune up, select Refresh Firefox.
  6. Click Refresh Firefox to confirm.
The Add-ons and themes option in the Firefox menu on Mac. In this menu, you can remove suspicious extensions when you suspect a Look2Me infection in Firefox on Mac.
Step 1. In the Firefox menu, select Add-ons and themes
The Extensions menu in Firefox on Mac. Remove unrecognized and unused extensions from here when you suspect a Look2Me infection in Firefox.
Step 2. Remove any unrecognized extensions
The Help option in the Firefox menu on Mac. Go into the help menu to reset Firefox when the browser has been infected by Look2Me spyware on Mac.
Step 3. In the Firefox menu, choose Help
The More troubleshooting information option in the Firefox menu on Mac. You can reset Firefox from within this menu when you suspect the browser has been infected by Look2Me spyware.
Step 4. Select More troubleshooting information
The Reset Firefox confirmation prompt on Mac. Use this to reset all Firefox settings when your browser has been infected by Look2Me malware.
Step 5. Click Refresh Firefox > Refresh Firefox to confirm

3. How to remove Look2Me from Safari

If you use a Mac and suspect Look2Me is present in Safari, you can remove it like so:

  1. Go to Safari > Settings in the menu bar.
  2. Select Extensions.
  3. Click any extensions you didn’t install yourself, then choose Uninstall.
  4. Select the Advanced tab, then check the box next to Show features for web developers.
  5. In the menu bar, then click Empty Caches to clear damaged browser files.
The Settings option inside the Safari menu on Mac. You can go into Safari's settings menu to Remove extensions you don't recognize when you suspect you have been infected by Look2Me spyware.
Step 1. Go to Safari > Settings
The Extensions tab in the Safari settings menu on Mac. Select and remove unrecognized and unused extensions when you suspect your computer has been infected by Look2Me spyware.
Step 2. In Extensions, Uninstall unrecognized extensions
The Advanced tab inside Safari's settings menu on Mac. Check the box to Show features for web developers so that you can clear Safari's caches when you have a Look2Me infection.
Step 3. In Advanced, enable Show features for web developers
The Empty Caches option in Safari's Develop menu on Mac. Empty Caches to remove potentially dangerous files from Safari after it's been infected by Look2Me.
Step 4. Go to Develop > Empty Caches

4. How to delete Look2Me from Microsoft Edge

Microsoft Edge users can remove Look2Me adware by following these steps:

  1. Open the Microsoft Edge menu, then click Extensions.
  2. Click Remove under any unrecognized extensions.
  3. Return to the Edge menu, then select Settings.
  4. Choose Reset settings, then select all items.
  5. Confirm by clicking Restore settings to their default values > Reset.
The Extensions option in the Microsoft Edge menu on Mac. If you think Edge has been infected by Look2Me spyware, first remove any suspicious extensions you don't recognize.
Step 1. In the Edge menu, choose Extensions
The Extensions menu inside Microsoft Edge on Mac. Remove all suspicious and unused extensions from Edge if you think the browser has been infected by the Look2Me malware.
Step 2. Click Remove to get rid of suspicious extensions
The Settings option inside the Microsoft Edge menu on Mac. Go into settings to reset Edge after the browser has been infected by Look2Me adware.
Step 3. In the Edge menu, click Settings
The Restore settings to their default values option in Microsoft Edge on Mac. Use this to reset Microsoft Edge when you believe the browser has been affected by Look2Me spyware.
Step 4. Select Reset settings > Restore settings
The Reset settings confirmation prompt inside Microsoft Edge on Mac. If Edge has been infected by Look2Me malware, you'll need to reset all settings as part of the removal process.
Step 5. Click Reset to confirm

How to prevent Look2Me infection

It’s usually difficult to tell where a spyware infection came from, but the best way to avoid running into Look2Me is by employing safe browsing practices such as avoiding untrusted websites, not clicking suspicious links, only downloading from reliable sources, and keeping your browser and OS up to date. It’s also a good idea to use a good antivirus program to block malicious software and remove adware from Android as soon as it’s detected.

Conclusion

Look2Me is a serious malware infection that not only displays annoying popup ads, but also steals your data—which hackers can use for all kinds of nefarious activities. You can remove Look2Me spyware from your browser using the instructions outlined above, but you’ll need an antivirus or malware remover to completely rid your system of an infection.

 

To avoid similar spyware on your smartphone, try Clario Anti Spy. Its Spyware scan on Android weeds out potentially dangerous apps that are accessing device permissions, while on iOS, its Device system check helps you ensure your iPhone is up to date and free from unauthorized software.

Keep reading

Use Clario Anti Spy to find and remove spyware like Look2Me.

Get started