Adw_fuel.o

Discussion in 'Malware Help (A Specialist Will Reply)' started by lana3867, Oct 19, 2006.

  1. lana3867

    lana3867 Private E-2

    I have this on my computer and it keeps giving me annoying pop ups and was wondering how do I get rid of it?
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Welcome to Majorgeeks!



    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. lana3867

    lana3867 Private E-2

    I have ran all my scans and would like to know now if I can do a clean system restore? Can you tell me where do I need to go from here?
     

    Attached Files:

  4. lana3867

    lana3867 Private E-2

    the rest of my log files
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not follow the directions in step 7 of the READ ME. You must follow them and install HijackThis properly and rename it as requested. You are running it directly from inside the ZIP file as the below line shows:

    C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\Temporary Directory 1 for majorgeekfix analysis.zip\HijackThis.exe

    Also, you did not follow the directions for running GetRunKey and ShowNew properly. You did not extract all the files from the ZIP file and then run the two .bat files as requested from a Windows Explorer sessions. As a result, your logs are incomplete. You must follow the directions in the download page and then attach new logs.

    Is your copy of Spyware Doctor a paid version or a free trial version? If free, uninstall it.
    If Spyware Doctor is a paid version, keep it and uninstall Windows Defender.

    Did you knowingly install the below stuff? And did you install it this way????
    C:\Program Files\Consumer Input Rewarded with MyPoints, Consumer Input\ConsumerInputRewardedwithMyPoints,ConsumerInput.exe
    C:\Program Files\Consumer Input Rewarded with MyPoints, Consumer Input\ConsumerInputRewardedwithMyPoints,ConsumerInputUa.exe

    Also do you know what the below is for?
    O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c

    What application/scanner is reporting Adw_fuel.o
    Do you have a log from it?
     
  6. lana3867

    lana3867 Private E-2

    Re: new files

    I have removed all the things that you told me. It seems I have more problems to get rid of, that just appeared today, a www.2-winantispy web page keeps coming up and also I think I have been attacked by a worm and trojan and virus. I have gone thru the read me first again and am attaching my new logs. PLEASE HELP!
     

    Attached Files:

  7. lana3867

    lana3867 Private E-2

    Re: Adw_fuel.o - 2nd files

    Spyware doctor is a paid version and updated. I can't figure out how to delete the quarantined files from there though. I just downloaded the windows defender in the read me first log.

    The 04-HKCU\..\Run [Magnetic] is a screensaver and wallpaper program, it is verified thru miscrosoft to be safe, It comes with incredimail.

    I hope you can tell me what is going on now, cause it seems my computer is getting worse every day.

    I appreciate all the help you do give!!!!!
     

    Attached Files:

  8. lana3867

    lana3867 Private E-2

    Re: vundo trojan

    I ran a scan thru spynomore while I was awaiting a response to my logs and it said I had the vundo trojan and lots of dll problems so i ran the program to remove it and it said it didn't find anything.


    Then i ran a scan from fix-errors.com and it found 1326 errors
    30 Com/activeX, 1 uninstall, 1 shared dll entry, 1 application path entry, 1 help file info, 10 windows startup items, 816 file path references, 447 empty registry item, 22 program shortcut, I have not done a thing about them but would like your advice if I should tell it to fix problems.....I will just do another scan when i hear from you if I need to let it fix the errors found

    I also have a little gray box down in my icon trya that says its windows security center but when you click it it comes up to www.2-antispyware and I believe it is a hoax, how do I remove this icon? I can't right click it and close it either.......

    Boy i think my computer is really messed up now, what should I do? I have not changed anthing since my HJT log was posted prior, I have downloaded the 2 programs from your site - spynomore and regcure...

    Please help
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: vundo trojan

    You need to stop running or doing anything that we do not ask you to do as it could only complicate matters (which is what appears to be happening). Please just be patient and wait for us to get back to you. I will try to look at your logs and post something later today.

    You did not answer one of my questions:

    You can also do the below while waiting!

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 7

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    I also see the below on your PC! These P2P programs are bundled with malware, you need to uninstall and not use them anymore and you need to delete the below folders and one html file:

    C:\Program Files\Blubster
    C:\Program Files\Blubster Toolbar
    C:\Program Files\iMesh Applications
    C:\Program Files\Morpheus
    C:\Program Files\MorpheusBar
    C:\Program Files\popcorn Terms.html
     
    Last edited: Oct 27, 2006
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: vundo trojan

    Uninstall Windows Defender if you still have it installed. It showed in your HJT log but not in the newfiles.txt log so I don't know whether you uninstalled it in between making both logs.

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of audmgr.dll once and then click the kill button. After you have killed all of the audmgr.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    dsseds32.dll

    Next double click on explorer.exe and again click once on each instance of audmgr.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    dsseds32.dll

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O4 - HKCU\..\Run: [sys32] C:\WINDOWS\system32\hbcyjpsdsc.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
    O20 - Winlogon Notify: audmgr - C:\WINDOWS\SYSTEM32\audmgr32.dll
    O20 - Winlogon Notify: dsseds32 - C:\WINDOWS\system32\dsseds32.dll (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\msupdate.exe
    C:\WINDOWS\system32\audconf.exe
    C:\WINDOWS\system32\audperf.exe
    C:\WINDOWS\system32\dsseds32.exe
    C:\WINDOWS\system32\hbcyjpsdsc.exe
    C:\WINDOWS\system32\mgmtmtxc.exe
    C:\WINDOWS\system32\audmgr32.dll
    C:\WINDOWS\system32\audprf32.dll
    C:\WINDOWS\system32\audstat.dll
    C:\WINDOWS\system32\confaud.dll
    C:\WINDOWS\system32\deskmcd3.dll
    C:\WINDOWS\system32\dsseds32.dll
    C:\WINDOWS\system32\e1.dll
    C:\WINDOWS\system32\vsxmpgpc.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.
    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\HP_Owner\Local Settings\Temp

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT

    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  11. lana3867

    lana3867 Private E-2

    I Have followed all the steps for the reply. i have removed the programs suggested. and ran all programs. i deleted the consumer input rewarded files. ran process explorer but had to download the debugging for windows 32 bit to get it to work.

    I tried to remove the windows defender program but can't find it anymore. I also removed the spynomore program and am not sure if I got rid of all of it - I used add/remove programs beacuse it wont let me do an unistall. I have chosen to use the AVG free antivirus software so should I remove my spydoctor? Does spydoctor even help?

    Attached are my new logs. the problem with my ie home page change has gone away, along with the little gray box in the icon try that said windows security center. Which I think is a good thing.?
     

    Attached Files:

    Last edited: Oct 28, 2006
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You mean Spyware Doctor. Becareful what names you use? SpyDoctor was a rogue non-useful tool whereas Spyware Doctor is a useful antispyware program! AVG does not perform the same functon as Spyware Doctor. AVG is an antivirus program and Spyware Doctor is an antispyware program. You need both of them.

    You have two more things to do:

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run HJT and fix the below line:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file://C:\WINDOWS\system32\secure32.html

    If Spyware Doctor pops up a warning about your start page being changed make sure you allow/accept the change.

    Reboot and attach a new HJT log.

    How is everything working now?
     
  13. lana3867

    lana3867 Private E-2

    I think that when I changed my internet home start page back to earthlink in the tools windows of my webpage, it made the line I was supposed to have hjt fix go away, I did not find it when I ran the scan and logfile.

    When I reboot, the regcure still thinks it needs to run, how do I get rid of this? I am just going to keep the spyware doctor program and the avg antivirus programs as my security methods. Are these appropriate ones to keep me safe?

    My computer sems to be running slower than normal, but I do not have the popups or the ie home page problem anymore.

    Thanks for all your help so far!!!!

    So can I now do a clean system restore? Also can you tell me why I tried to do a system restore from 8/9/06 when I cleaned my computer last of the trojan I had and it said I couldn't do a system restore, was that due to the virus or trojan or worm---whatever it was I had?
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is regcure? Do mean something else again? Do you mean the below which you said you removed? Obviously it did not uninstall properly. Have HJT fix the below line:
    O4 - HKLM\..\Run: [SNM] C:\Documents and Settings\HP_Owner\My Documents\trying to fix 102506\SpyNoMore\SNM.exe /startup

    You need to do everything in the below procedure. It also covers toggling System Restore.

    It possible that all the malware you had cause this problem.


    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    7. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  15. lana3867

    lana3867 Private E-2

    Thanks for responding so quickly, however last night something must have happened to my computer because when i got up this morning to receive your email, it came thru and I went to HJT and removed the spynomore line and then proceeded to do the remaining steps you said----- I got to the pockest killbox and there was a file hbcyjpsdsc.exe, I clicked it and that stupid antispyware website came up again and then I got the little gray box back in the iccon tray. My start page came up about:blank. So I have tried to go back and repeat the procedures from Post #10 but can't remember how I pasted to the clipboard. And can not find where the killbox program went to to get back into it. At this point I am totally confused because yesterday all my problems were gone. And they all came back when I opened what I thought was the killbox program.

    Can you please help me to get this back to a clean status????

    THANKS a million.

    I have attached my all the logs again from Post #10 but just ran them.
     

    Attached Files:

  16. lana3867

    lana3867 Private E-2

    SORRY --- I decided to do a system restore to the point yesterday when I was clean. I now have no problems again but only went as far as the removeing the 04 line in HJT. I am attaching new logs. I removed killbox from my computer because of the gray shield in the file folder, is it the program? Do I need to download it again? Can you please direct me from here? I will NOT do anything else until I hear back from you, then maybe just maybe everything will be okay.

    Thanks again.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why did you click any files? My directions simply said to
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to delete the below folder:
    C:\Documents and Settings\HP_Owner\Application Data\iMesh

    Then you need to finish ALL of the steps I gave to you in message # 14. If you already deleted the C:\!Killbox folder then you can skip the first step.
     
  19. lana3867

    lana3867 Private E-2

    I did not know how to make pocket killbox run. I though it was the program file. I will once again attach my files and can you tell me where I need to go from Here?

    I will not do anything til I here back from you. At this point I have not had any of the problems I originally had---popups or crazy home pages.

    Thanks again
     

    Attached Files:

  20. lana3867

    lana3867 Private E-2

    I did delete the folder imesh, I guess I was typing a reply when you sent the second response.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    ????? How did you run it the first time? Run it the same way. If you deleted it, you will need to download it again or could have deleted the backup folder created by Killbox. The folder was C:\!Killbox but it looks to me like you already delete the folder. So as I a said in my previous message, you MUST complete ALL the other steps in message # 14.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds