180ax.exe Adware

I have a computer that is infected with 180ax.exe that keeps popping up ads and slowing down the computer.
The files reside in C:\windows 180ax.exe, 180 log files and a 180 dll file.

Windows will not let me remove the files.

If I boot from a floppy I can probably manually remove them but will this take care of the problem or will it just resurface again.

Thanks
Les
lesfazekasAsked:
Who is Participating?
 
sunray_2003Connect With a Mentor Commented:
Hi lesfazekas,

To start with do this
Login to windows in normal mode
http://windowsxp.mvps.org/Startup.htm
Check the above link and navigate to all registry entries and disable that exe file if present.

Then according to what shehary has said log to safe mode and try to delete that file.
The above startup would prevent the exe file from running at the first place..

If you cannot remove it then use these tools

**********
PLEASE GET THE SPYWARE REMOVAL TOOLS FROM THE BELOW WEBSITE. THAT PAQ IS CREATED SO THAT ALL THE TOOLS ARE NOT GUMMED UP IN THIS THREAD.

Some of the experts here have helped in compiling all the important spyware tools and they are listed in this thread
http://www.experts-exchange.com/Web/Browser_Issues/Q_20975384.html

My recommendation would be to start with Spybot ,Ad-ware ,CWshredder.After installing them, First Update them and then run

Once running all the above tools and others given in that thread, download and run Hijackthis.
Download Hijacthis from here http://www.softpedia.com/public/cat/10/17/10-17-69.shtml.
Get the log from Hijackthis and save the log and paste it here http://hijackthis.de/index.php?langselect=english to analyze it. The analyser site is used so that you donot gum up the thread with the entire log.

Remove the bad ones that the site reports. If it says unknown process, then use a search engine to check if those are bad ones. If bad remove them , if you still cannot find then post those files alone here.


Remove temporary internet files, folders and cookies
Also remove windows Temp files going to

1) Start --> run --> typein:  %systemroot%/temp
2) Start  --> run --> typein: %temp%

***************************
SR..
0
 
SheharyaarSaahilCommented:
Hello lesfazekas =)

>> Windows will not let me remove the files.
What the problem, have u tried deleting them in Safemode ??

do u get Access Denied Error. if yes then take their ownership,

HOW TO: Take Ownership of a File or Folder in Windows XP:
http://support.microsoft.com/?kbid=308421

How do I take ownership of objects in Windows 2000?
http://www.jsiinc.com/SUBG/TIP3400/rh3494.htm
0
 
SheharyaarSaahilCommented:
>> but will this take care of the problem or will it just resurface again.

No guesses.... depends on How much strong is the infection,,, if u are using WinXP, rmemebr to disable system restore before cleaning the system !!
Run all ur spwyare removal tools in safemode and then manually remove the remainent files and registries !!
Now check back if same problem ??
0
SMB Security Just Got a Layer Stronger

WatchGuard acquires Percipient Networks to extend protection to the DNS layer, further increasing the value of Total Security Suite.  Learn more about what this means for you and how you can improve your security with WatchGuard today!

 
SheharyaarSaahilCommented:
BTW 180ax.exe comes in the catogary of 180Solutions malware..... may be u shud read this article to get some idea how to kick this nasty out of ur system :)

Uninstall 180 Search Assistant
http://www.sawtoothdistortion.com/Articles/Uninstall180Search.html
0
 
jvuzCommented:
Also do a check with stinger:

http://vil.nai.com/vil/stinger/
0
All Courses

From novice to tech pro — start learning today.