Pad Lookuups 180 search assistant

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by hackley, Jun 27, 2005.

  1. hackley

    hackley Private E-2

    Hi Thanks for your help with my last problem.

    I have followed all of the steps in the basic removal section. I wasn't able
    to get an internet connection when I booted into safe mode so i ran the online checks in normal mode and all the rest in safe mode

    I have Troj dropper (uncleanable) but eveything else seems fine.

    This Pad lookup 180 search assistant cannot be removed by using addd/remove programs. I get a message telling me it cannot be removed unless i am connected to the internet and if i am to click ok. I do this and the screen flickers but the program is still there.

    Is this program a nasty one and if so can you please help me remove it.

    Thank you in advance
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    At the end of your previous thread ( http://forums.majorgeeks.com/showthread.php?t=63642 ) I posted something for you to do. Specifically the How to Protect yourself from malware! thread. Did you do those steps at that time?


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. hackley

    hackley Private E-2

    Hi Chaslang
    thankyou for replying. I did follow the recommended steps. The problem was that I let some idiot use my computer and he recons he's some kind of computer wizz, messed up all of my settings, and then was downloading from god knows where :mad:

    Anyway here's my HJT log and thanx a million :)
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not completely from what I can see. You never installed a firewall for one thing and that is probably the second most important thing to do (some may say it's the most important).

    First look in Add/Remove programs for the below and uninstall if found:
    n-case
    Search-Assistant
    180 Solutions

    Then continue with the below to make sure we get rid of them.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O4 - HKLM\..\Run: [msbb] c:\program files\n-case\msbb.exe
    O4 - HKCU\..\Run: [180ClientStubInstall] "C:\Program Files\Search-Assistant\stubinstaller.exe"

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    c:\program files\n-case <--- the whole folder
    C:\Program Files\Search-Assistant <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

     
  5. hackley

    hackley Private E-2

    Hi Chaslang

    Thanks for your reply. My mistake I thought I'd followed all of the steps :eek: . I now have a firewall but it seems to be having a bit of trouble. The error message that it has encountered problems and needs to close.

    Anyway I really did follow all of the instructions this time :D . In my add and remove programs I still have:

    Interstitial Ad Delivery by 180 Search Assistant and PAD Lookups by Search Assistant but they have no sizes (e.g 0.36Mb) next to them.


    I have attached a new HJT log as requested and thanks again. You guys are the best.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you try using Add/Remove programs to uninstall:

    Interstitial Ad Delivery
    PAD Lookups

    If the above does not work, try the below (and not I'm assuming that the names you gave me are how the programs appear in the registry):

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixunst.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixunst.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes


    Did you disable the Windows XP SP2 built-in firewall? You need to do that after you install a real firewall like Sygate. (Note: the SP2 firewall is not good enough to use only it and you must not use multiple software firewalls.)
     
  7. hackley

    hackley Private E-2

    Hi Chaslang

    The problem's gone now and everything looks fine. Thank you! thank you! thankyou! Just one more question, how do I disable the firewall on XP SP2?

    This site is the best. I've told eveyone I know with a PC about it. What you guys do is great! Without peolple like you people like me would be buying a new PC every year!

    Nikki X
     
  8. Anon-068c403e2d

    Anon-068c403e2d Anonymized

    Nice one chaslang :)
    hackley,
    Control panel>(security center)>windows firewall>off.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  10. hackley

    hackley Private E-2

    Hi Chaslang

    Thank you again. I'm getting repetative strain syndrome :) . When I looked in my programs in add/remove I had Zonealarm Free firewall so I uninstalled it because I installed the other one. Because of the problems I've ben having is it possible that it would just stop running on its own or would someone have to turn it off? If the latter is reason it is off someone in this house is in serious trouble!!

    Nikki x
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your previous logs showed no signs of Zone Alarm so I'm not sure when you mean you uninstalled it. See your HJT log in message # 3. There was no ZoneAlarm. That is why I told you to get a firewall.
     
  12. hackley

    hackley Private E-2

    I don't understand it either. I went into add/remove and there it was at the end of the list of programs!?!. I uninstalled the usual way because you said I couldn't have two firewalls and I had already downloaded Sygate.

    Anyway, no matter eveything seems fine. Thanks for your time and patience it's much appreciated,

    Nikki x
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  14. hackley

    hackley Private E-2

    Hi Chaslang

    I have no idea what's going on. It seems as I fix something another problem arises. My firewall won't work now. On startup I get an error message saying that it has encountered problems and needs to close and today IE has started doing the same thing. I also got the same message from something called "Dr Watson Postmortem Debugger", does this crap ever end?

    Is there a way I can stop guest users of my PC from giong onto these dodgy websites and messing up my baby?

    I await your reply with absolute dread!!

    Thanx for your help in advance

    Nikki
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Delete the Guest account. It is not safe anyway. It has long been know to be a major security whole. Do not let other people use your PC? If you do then you will have to place restrictions on the account. Do not allow downloads, do not allow installs, etc. Make sure it is not an account that has administrator priviledges. NEVER let them use your account but the best advice is still Do not let other people use your PC!

    Did you complete ALL the steps in the How to protect thread?
    Did you install Spybot and use the Immunize feature?
    Did you install SpywareBlaster and use all of its protections?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds