Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Computer problems and/or questions
#25
zango.exe : 180Solutions/N-Case adware variant
From above URL Wrote:Removal

nCase/msbb and rnd may include two uninstallers (if any), named ‘Insterstitial ad delivery by n-Case’ and ‘PAD lookups by n-Case’. Both have to be used before the software is removed; both require internet access and simply attempt to download further uninstallers which also require internet access, and sometimes still don’t work. Manual removal will probably be faster than this rigmarole.

The other variants have at most one installer, ‘Uninstall 180Search Assistant’ or ‘Zango’. This also requires internet access, and requires several stages of confirmation pages fetched from 180solutions’s site, but does remove the software without a further download.

All uninstallers leave the nCase/Inst control in place, allowing nCase to be reinstalled without prompting. To remove this, open the Downloaded Program Files folder (inside the Windows folder) and delete the entry ‘nCaseInstaller Class’ (nCase/Inst/nc variant), ‘180SAInstaller Class’ (nCase/Inst/180SA variant) or ‘ZangoInstaller Class’ (nCase/Inst/Zango variant).
Manual removal

Open the registry (click ‘Start’, choose ‘Run’ and enter ‘regedit’), select the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, and right-click the entry on the right with the name ‘msbb’ (nc and msbb variants), ‘saie’, ‘saie’, ‘sais’, ‘salm’, ‘saap’, ‘sain’, ‘180ax’, ‘180adsolution’, ‘zango’, or in the case of the rnd variant, a random name 3-9 lower-case letters long pointing at a .exe file of the same name.

Delete this entry, noting the filename it was pointed at. nCase can be installed in any location on the hard disc, depending on the whim of the installer. Common locations include in a folder in Program Files named ‘nCase’, ‘n-Case’, ‘MSBB’, ‘180Solutions’ and ‘180Search Assistant’, along with the System32 folder (inside the Windows folder; called just ‘System’ on Windows 95/98/Me), the Temp folder (inside the user profile Local Settings folder in Documents and Settings, or directly in the Windows folder in Windows 95/98/Me) and the Application Data folder (inside the user profile folder or the Windows folder in 95/98/Me). It can also often be found inside the Program Files folder of another program that installed it.

For the Alert variant, also check the Run key for an entry with a random upper-case name 3-6 letters long pointing to a .exe file of the same name in the Windows folder. Note the name and delete the entry if there is one.

Restart the computer and you should be able to delete the files whose names you noted. You can also remove files using the names in the table above, stored in the same folders as the main executable, and the empty temporary folder named ‘FLEOK’, along with any icon (.ico) files nCase has downloaded to put onto the desktop.

To clean up, you can also delete the registry keys in HKEY_CURRENT_USER\Software and HKEY_LOCAL_MACHINE\Software with the name ‘msbb’ (nc, rnd, msbb variants), ‘saie’, ‘sais’, ‘salm’, ‘saap’, ‘sain’, ‘180solutions’ or ‘zango’ and, if present, the uninstall key in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall called ‘nCASE’, ‘msbb’ or ‘zango’.

block-checker.exe http://forum.mess.be/index.php?showtopic=10889 you decide.

ac16059d153.exe also very suspicious looking, I cant find any info on it though.

hyandex.exe NTROOTKIT Trojan or 'WareOut'
http://www.doxdesk.com/parasite/WareOut.html
Quote: Use the entry in the Control Panel’s Add/Remove Programs list to remove the software, then restart the computer, open the Windows folder and delete the file wotmp.tmp or wotmp11.tmp, then open the System32 folder (inside the Windows folder, called just ‘System’ on Windows 95/98/Me) and delete the file wosys.dll or wosysdll.dll.

To clean up the fake spyware traces WareOut installs, open the registry (click ‘Start’, choose ‘Run’, enter ‘regedit’) and select the keys HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run. For each, look at the entry list on the right and delete entries using the names/filenames above. Then select the key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks and delete the randomly-numbered entries on the right except the default search hook {CFBFAE00-17A6-11D0-99CB-00C04FD64497}.
NTROOTKIT:
http://vil.nai.com/vil/content/v_135403.htm
http://vil.nai.com/vil/content/v_134117.htm

KeywordFinder.exe Trojan - Part of wareout.
http://www.doxdesk.com/parasite/WareOut.html

WareOut.exe - See above.

WhatsNewBot.exe - See above.

Bogobot.exe - See above.

UserSp1.exe - See above. anyone else tired of this...

Q678341.exe
Quote:# Determination: Bad


# This program has a file name of Q678341.EXE. It has a file size of 3,493 bytes and is found in the folder [%PROGRAMFILES%\WINDOWS MEDIA PLAYER\].


# We do not currently have any Vendor or Product Information about this program.


# This program has been run as part of a download process.


# This program was first seen by our users on Jul 9 2005. Only one user has seen this specific version of this program on their PC. This program has only been seen in operation once within our user base. We have only seen this one version of this program in use within our user base.


# This program is malware and is not considered safe, it is part of a Malware group sometimes referred to as Win32/Suspicious_M.gen. It should be Jailed
Just quarantine it.

Hope that helps.
"An eye for an eye makes whole world blind" - Gandhi
[Image: 1142118JykvC.png]
Reply


Messages In This Thread
Computer problems and/or questions - by Serpent7 - 14-06-2005, 05:28 PM
Computer problems and/or questions - by Ivan - 15-06-2005, 03:45 AM
Computer problems and/or questions - by Serpent7 - 15-06-2005, 11:04 AM
Computer problems and/or questions - by Ivan - 15-06-2005, 05:38 PM
Computer problems and/or questions - by Serpent7 - 15-06-2005, 08:47 PM
Computer problems and/or questions - by jarl - 18-07-2005, 09:31 PM
Computer problems and/or questions - by ~Buddah~ - 18-07-2005, 11:49 PM
Computer problems and/or questions - by Faulkie - 13-08-2005, 10:33 AM
Computer problems and/or questions - by Lee-yoshi - 13-08-2005, 11:06 AM
Computer problems and/or questions - by A.S. - 13-08-2005, 11:28 AM
Computer problems and/or questions - by Serpent7 - 13-08-2005, 01:55 PM
Computer problems and/or questions - by Faulkie - 13-08-2005, 04:30 PM
Computer problems and/or questions - by Serpent7 - 16-08-2005, 04:12 PM
Computer problems and/or questions - by Faulkie - 16-08-2005, 06:44 PM
Computer problems and/or questions - by Serpent7 - 17-08-2005, 10:44 AM
Computer problems and/or questions - by Archer - 22-08-2005, 03:56 AM
Computer problems and/or questions - by Kashima - 22-08-2005, 05:16 AM
Computer problems and/or questions - by Archer - 22-08-2005, 08:50 PM
Computer problems and/or questions - by Faulkie - 22-08-2005, 11:27 PM
Computer problems and/or questions - by Faulkie - 22-08-2005, 11:53 PM
Computer problems and/or questions - by Phantom_RAcast - 23-08-2005, 12:25 AM
Computer problems and/or questions - by Serpent7 - 27-08-2005, 07:17 PM
Computer problems and/or questions - by Faulkie - 28-08-2005, 11:27 PM
Computer problems and/or questions - by Serpent7 - 29-08-2005, 10:33 AM
Computer problems and/or questions - by pink - 29-08-2005, 03:16 PM
Computer problems and/or questions - by Serpent7 - 30-08-2005, 09:03 AM
Computer problems and/or questions - by pink - 30-08-2005, 09:10 AM
Computer problems and/or questions - by Serpent7 - 30-08-2005, 10:52 AM
Computer problems and/or questions - by Faulkie - 30-08-2005, 11:20 AM
Computer problems and/or questions - by Serpent7 - 31-08-2005, 11:38 AM
Computer problems and/or questions - by Hayami - 31-08-2005, 04:48 PM
Computer problems and/or questions - by Serpent7 - 31-08-2005, 07:13 PM
Computer problems and/or questions - by jarl - 31-12-2005, 07:43 PM
Computer problems and/or questions - by Serpent7 - 03-01-2006, 02:16 PM
Computer problems and/or questions - by jarl - 03-01-2006, 02:38 PM
Computer problems and/or questions - by Serpent7 - 04-01-2006, 04:52 PM
Computer problems and/or questions - by jarl - 04-01-2006, 05:44 PM
Computer problems and/or questions - by Serpent7 - 05-01-2006, 01:28 PM
Computer problems and/or questions - by jarl - 06-01-2006, 07:03 PM
Computer problems and/or questions - by Serpent7 - 07-01-2006, 11:17 AM
Computer problems and/or questions - by jarl - 07-01-2006, 12:30 PM
Computer problems and/or questions - by jarl - 07-01-2006, 02:59 PM
Computer problems and/or questions - by Serpent7 - 08-01-2006, 03:27 PM
Computer problems and/or questions - by Sd28 - 08-01-2006, 08:33 PM
Computer problems and/or questions - by jarl - 14-01-2006, 01:40 PM
Computer problems and/or questions - by Serpent7 - 15-01-2006, 01:37 PM
Computer problems and/or questions - by Jimbo1990 - 15-01-2006, 04:11 PM
Computer problems and/or questions - by nomercy - 09-12-2007, 02:46 PM
Computer problems and/or questions - by pso king - 30-12-2008, 06:43 PM
Computer problems and/or questions - by pso king - 30-12-2008, 07:10 PM
Computer problems and/or questions - by Rena - 30-12-2008, 07:21 PM
Computer problems and/or questions - by pso king - 31-12-2008, 02:41 AM
Computer problems and/or questions - by Rena - 31-12-2008, 10:29 AM
Computer problems and/or questions - by Lance813 - 31-12-2008, 06:24 PM
Computer problems and/or questions - by Rena - 31-12-2008, 06:26 PM
Computer problems and/or questions - by Lance813 - 31-12-2008, 06:40 PM
Computer problems and/or questions - by pso king - 01-01-2009, 12:24 AM
Computer problems and/or questions - by Rena - 01-01-2009, 12:30 AM
Computer problems and/or questions - by pso king - 01-01-2009, 12:50 AM
Computer problems and/or questions - by Rena - 01-01-2009, 12:55 AM
Computer problems and/or questions - by pso king - 01-01-2009, 12:56 AM
Computer problems and/or questions - by pso king - 03-01-2009, 09:22 AM
Computer problems and/or questions - by pso king - 03-01-2009, 03:17 PM
Computer problems and/or questions - by pso king - 06-01-2009, 06:07 AM
Computer problems and/or questions - by Rena - 06-01-2009, 07:29 PM
Computer problems and/or questions - by pso king - 06-01-2009, 08:31 PM
Computer problems and/or questions - by pso king - 23-01-2009, 05:12 AM
Computer problems and/or questions - by demeiz - 23-01-2009, 10:29 AM
Computer problems and/or questions - by Rena - 23-01-2009, 10:43 AM
Computer problems and/or questions - by pso king - 23-01-2009, 06:44 PM
Computer problems and/or questions - by demeiz - 23-01-2009, 06:49 PM
Computer problems and/or questions - by pso king - 23-01-2009, 09:05 PM
Computer problems and/or questions - by demeiz - 23-01-2009, 11:29 PM
Computer problems and/or questions - by pso king - 23-01-2009, 11:47 PM
Computer problems and/or questions - by demeiz - 24-01-2009, 12:08 AM
Computer problems and/or questions - by Serpent7 - 04-02-2009, 07:02 AM
Computer problems and/or questions - by Beat X500 - 04-02-2009, 03:28 PM
Computer problems and/or questions - by Serpent7 - 05-02-2009, 03:27 AM
Computer problems and/or questions - by Beat X500 - 05-02-2009, 02:54 PM
Computer problems and/or questions - by demeiz - 03-05-2009, 12:16 AM

Possibly Related Threads…
Thread Author Replies Views Last Post
  Your Custom Computer Zer0 1 1,394 09-11-2010, 05:57 AM
Last Post: Phantom_RAcast
  something is wrong with yahoo on my computer pso king 5 630 25-03-2009, 07:29 PM
Last Post: pso king
  ISP problems again Poo Fly 6 548 15-12-2006, 03:14 AM
Last Post: Poo Fly
  Computer Upgrades. Phantom_RAcast 0 438 17-10-2005, 04:58 AM
Last Post: Phantom_RAcast
  computer geeks please read jarl 24 1,369 17-09-2005, 11:23 PM
Last Post: jarl

Forum Jump:


Users browsing this thread: 1 Guest(s)