Help please. 180search removal.

Discussion in 'Malware Help (A Specialist Will Reply)' started by pvmike1, Aug 27, 2005.

  1. pvmike1

    pvmike1 Private E-2

    I'm running XP, Norton Antivirus. I tried all the basic removal tools recommended in the sticky, but I'm unable to remove these items below (Norton cannot remove):

    Adware.180Search
    Adware.ZangoSearch
    Adware.PowerScan

    Please help! I can post my HijackThis log if necessary.

    TIA,

    Mike
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps below exactly as written:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. pvmike1

    pvmike1 Private E-2

    chaslang,

    I've attached my HT log file.

    Thanks!

    Mike
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No signs of them in your log.

    Although I don't personally like crud like:

    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe

    What program is reporting the stuff? Is it reported by Norton? Post a log of exactly what and where it is reporting the stuff. Have you run Norton in Safe Mode?
     
  5. pvmike1

    pvmike1 Private E-2

    chaslang,

    The last time I had spyware I couldn't get rid of was a little over a year ago. You helped me clean my computer back then also. You're truly a credit to this site!

    Norton AV is picking up these things, and it's telling me that it can't delete it. After running AV, I'm unable to copy and paste the log and locations of these items. I'll write them down by hand next time if there's no other way...

    Oh, and I did try to run Norton AV in safe mode, but the result was the same: unable to delete.

    Mike
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It could be just left over registry keys that it is find. See if you can write them down and post the info.

    You can also give the below a run (perhaps it may help).


    - run CCleaner again before doing the below

    Download this trial version of Ewido Security Suite
    • Install ewido security suite
    • Launch ewido, there should be an icon on your desktop double-click it.
    • The program will have a window come up. One of the buttons on the left is to Update. Click the Update button.and then Start the Update. The update will start and a progress bar will show the updates being installed.
    • After it completes the update, click the Scanner button

    Now exit Ewido. Now print the below instructions or save them locally because I want you do have no browsers opened and also have no connection to the internet (unplug your cable) while doing the below.

    Okay, reboot into safe mode and follow the steps below. (If you have any problems at all trying to get into safe mode to complete these steps, just run them in normal boot mode and make sure you tell me when you come back.)

    Open up Ewido and do the following:

    • Click on Scanner
    • Then click Settings
    • Under What to Scan? Select Scan every file
    • Then click OK
    • Click on Complete System Scan and the scan will start.
    • Let the program scan the machine
    While the scan is in progress you will be prompted to clean files that are infected. Leave the defaults selections (to Remove and backup) and click OK. To save yourself some time, you can select Perform action with all infections and then click OK. With the option to scan every file, a lot of cookies will be removed.

    Once the scan has completed, there will be a button located on the bottom of the screen named Save report

    • Click Save report
    • Save the report to your desktop or anyplace you will be able to find it to upload here.
    Reboot into normal mode and reconnect to the internet.

    Come back here and post the Ewido Scan Report .
     
    Last edited: Aug 28, 2005
  7. pvmike1

    pvmike1 Private E-2

    chaslang,

    This is not good.

    I installed ewido, allowed it to auto-update, then tried to launch it after restarting my laptop. Immediately after launching, the program would close. I restarted in safe mode, and ewido launched and stayed open. I started the scan, and then left for a few hours. Upon my return, I found that ewido identified 82,691 "infections", and was attempting to clean them. I decided to let the darn thing run and left my laptop on for the night. After 24 hours, it had cleaned 30,000 or so infections, but it was running at an unbelievably slow speed, and it would probably take a week for it to finish.

    I restarted my computer and deleted ewido, and then reinstalled it. It closes again after launching. I don't want to try to run another scan.

    I'm going to try running Norton AV, then I'll write down the locations of the found viruses. Hopefully, this will give you a better idea of what is going on.

    Do you have any other suggestions? I'm stumped.

    Mike
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But what was it that Ewido was find so much of. Was it really a virus/trojan problem or was it just loads of cookies and MRU type things? You can save and view the logs even when you cancel the scan. You could also try setting Ewido up to scan with less detail. Instead of scanning all files, select Choose files by extension and just leave whatever they have by default. Also uncheck the Scan for tracking-cookies selection. Then also back on the scanning screen just use the Fast System Scan option.


    If you truly have that many infected virus/trojan type files on your system, you could be better off with an FDISK, format and reinstall. Depends on what the infections were and if they are truly cleanable. I need more info on what was being found.
     
    Last edited: Aug 31, 2005
  9. pvmike1

    pvmike1 Private E-2

    chaslang,

    It probably was a bunch of cookies and MRU type things. I ran Norton AV again in safe mode and it came up with 10 things - no viruses, only adware threats:

    C:\RECYCLER\NPROTECT\00063456.cab (Threat name: Adware.180Search)
    C:\RECYCLER\NPROTECT\00063457.dll (Threat name: Adware.180Search)
    C:\RECYCLER\NPROTECT\00063458.dll (Threat name: Adware.ZangoSearch)
    C:\RECYCLER\NPROTECT\00063497.exe (Threat name: Adware.180Search)
    C:\RECYCLER\NPROTECT\00063501.dll (Threat name: Adware.180Search)
    C:\RECYCLER\NPROTECT\00063506.exe (Threat name: Adware.ZangoSearch)
    C:\RECYCLER\NPROTECT\00063506.exe (Threat name: Adware.180Search)
    C:\RECYCLER\NPROTECT\00063510.EXE (Threat name: Adware.PowerScan)
    C:\RECYCLER\NPROTECT\00063511.EXE (Threat name: Adware.PowerScan)
    The compressed file clientax.dll within C:\RECYCLER\NPROTECT\00063456.cab (Threat name: Adware.180Search)

    This doesn't look bad at all. How do I delete these files, since Norton will not let me?

    I'll try Ewido again also.

    Thanks!

    Mike
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to disable Norton's feature that is protecting the Recycle bin. I believe it is named as indicated, Nprotect. They must have info in your program that tells you how to do this. There must be some kind of control panel that allows you to empty the Recycle bin. I find this feature to be more of an annoyance then a help. Especially in the malware world.


    See: http://service1.symantec.com/SUPPORT/nsw.nsf/0f75ab1a9982283d88256c250066dc94/831aa5c6ef0d750685256c370048ad89?OpenDocument&src=bar_sch_nam
     
    Last edited: Aug 31, 2005
  11. pvmike1

    pvmike1 Private E-2

    chaslang,

    Thanks! I think that took care of it. As always, your help is much appreciated!

    Mike
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds