JAque
10-08-2004, 02:46 AM
Today, I got hit by this nasty ADWARE that none of the standard removal tool was able to handle. 180Search is a Comparison Alternative Shopping Engine developed by 180Solutions. It appears to be installed via an ActiveX drive-by download or bundled with several file sharing programs and a few others. It will cause pop-up advertisements, can add shortcut items to the Startup or Desktop, and update itself.
As I was browsing 2+2 today, I noticed a PartyPoker adv window opened every time.
I was able to remove it manually but most of the help available in the web has old information as far of the name of the executable. The critter hides as described below in the registry with the a new name saab.exe.
There is also a folder with the word search in the installation area
How do I Remove NCase/180search?
1) Because several files may be in use currently when NCase has infected your system, you should first start Windows in Safe Mode, generally by pressing F8 when the computer restarts and choosing Safe Mode for the list of choices.
2) Remove the Startup Entry in the Registry
Click on Start, Run, Type REGEDIT and Click OK
Click the pluses(+) next to the following items
o HKEY_LOCAL_MACHINE
o Software
o Microsoft
o Windows
o CurrentVersion
o Run
Right-Click on the file MSBB and click DELETE
Check for any randomly named entries pointing to an EXE file of the same name in the Windows directory
(this can be part of the NCASE infection as well)
Click the pluses(+) next to the following items
o HKEY_LOCAL_MACHINE
o Software
o Microsoft
o Windows
o CurrentVersion
o Uninstall
Right-click and Delete the following folders
o nCase
o msbb
Click the pluses(+) next to the following items
o HKEY_Current_User
o Software
Right-click and Delete the folder called 180solutions
Standard WARNING: As usual, back up your registry before doing this.
JAQue
As I was browsing 2+2 today, I noticed a PartyPoker adv window opened every time.
I was able to remove it manually but most of the help available in the web has old information as far of the name of the executable. The critter hides as described below in the registry with the a new name saab.exe.
There is also a folder with the word search in the installation area
How do I Remove NCase/180search?
1) Because several files may be in use currently when NCase has infected your system, you should first start Windows in Safe Mode, generally by pressing F8 when the computer restarts and choosing Safe Mode for the list of choices.
2) Remove the Startup Entry in the Registry
Click on Start, Run, Type REGEDIT and Click OK
Click the pluses(+) next to the following items
o HKEY_LOCAL_MACHINE
o Software
o Microsoft
o Windows
o CurrentVersion
o Run
Right-Click on the file MSBB and click DELETE
Check for any randomly named entries pointing to an EXE file of the same name in the Windows directory
(this can be part of the NCASE infection as well)
Click the pluses(+) next to the following items
o HKEY_LOCAL_MACHINE
o Software
o Microsoft
o Windows
o CurrentVersion
o Uninstall
Right-click and Delete the following folders
o nCase
o msbb
Click the pluses(+) next to the following items
o HKEY_Current_User
o Software
Right-click and Delete the folder called 180solutions
Standard WARNING: As usual, back up your registry before doing this.
JAQue