Avenue A, Inc & FunWebProducts

Discussion in 'Malware Help (A Specialist Will Reply)' started by Dragonball82, Feb 23, 2005.

  1. Dragonball82

    Dragonball82 Private E-2

    Hi,

    I have read your How to's and downloaded, installed & run all your Spyware removals (except Hijack this) - bloody good stuff. Well done to the programmers. Plus MG for sharing it :D

    However I still have FunWebProducts in the Spybot-S&D - it says it cannot remove it.

    Also I keep getting message boxes with this message:
    'Spybot-S&D reports you want to download "Avenue A, Inc.". This is a known threat. Do you want to BLOCK this download.'

    Each time I click Yes - but I still get the message again.

    Could anyone help pls I feel a bit like a small fish in a BIG pond... :eek:

    Oh yeah run WinXP SP2
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.


    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99.1 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT


    We are very busy here at MajorGeeks.Com PhilliePhan, Chaslang or myself with check back when time permits.!
     
  3. Dragonball82

    Dragonball82 Private E-2

    Hi bjgarrick plus any others watching :)

    I have run all the Spyware you suggested in Safe Mode, with Sys Restore disabled.
    No viruses were found from any of those listed by MG- Adaware did find some Non virus stuff which has been Quarantined.
    Have also run CCleaner

    I still get the message pop-ups from SpybotS&D

    I also noted that the Sbybot S&D message about Avenue A, Inc, appears most frequently when I am logged on to MG website!
    I have not run Hijack this yet...should I ?

    Thanks - I understand your busy.
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Yes, Go ahead and run HJT and post me a log. Attach it to your post.
     
  5. Dragonball82

    Dragonball82 Private E-2

    BJGarrick.
    Please find attached log - hope I did it right - excuse me if not....
    like I said small fish BIG pond, just starting out :)

    One more thing, when the message frm Spybot comes up + I click 'yes' to BLOCK Avenue A, Inc.... I need to refresh my web page as it freezes when loading.

    Thanks
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Now scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.


    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://adserv.internetfuel.com/cgi-bin/omnidirect.cgi?SID=82&PID=2&LID=3

    O4 - Startup: Thumbs.db

    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/

    O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} (AccountTracking Profile Manager Class) - https://moneymanager.egg.com/Pinsafe/accounttracking.cab

    O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.ofoto.co.uk/downloads/BUM/BUM_WIN_IE_1/axofupld.cab


    Again make sure All Browser Windows are Closed when you Click FIX.


    NEXT:
    Run CCleaner and Spybot S&D and have Spybot fix what it finds.
    Note: Dont forget to update Spybot S&D by selecting "Search For Updates"



    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.


    Reboot, Scan with HijackThis and attach the new log.
    Let me know of any problems you may have encountered with the above instructions and how your computer is running now.

    Good Luck
     
  7. Dragonball82

    Dragonball82 Private E-2

    HI,

    Back again - quick swig of T whilst all that went on. Did all as u asked
    OK so I could not delete

    O4 - Startup: Thumbs.db..... something about Start up

    and running Spybot - FunWebProducts was back. S&D could not delete, again something about Start Up.

    Have attached my new log
     

    Attached Files:

  8. Dragonball82

    Dragonball82 Private E-2

    Oooh sorry mean't to add.

    I do not appear to get the messages from S&D, fingers crossed.
    Also u got me to remove:

    O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} (AccountTracking Profile Manager Class) - https://moneymanager.egg.com/Pinsaf...unttracking.cab

    Can my wife still use money manager ? Or will she have to create it again?

    Thanks
     
  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your log is clean!

    Are you currently experiencing any problems?
     
  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    This is where you installed the software from there website. When you access the site again it will prompt you to install again, no biggie!
     
  11. Dragonball82

    Dragonball82 Private E-2

    No problems - so far. Will contact MG if I do :D
    Although S&D could not remove FunWebProducts.
    and I could not delete the 'O4' HJT key.

    Presume I needn't worry any further then :)
    Thanks
     
  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    What does Spybot do when removing FunWebProducts?
     
  13. Dragonball82

    Dragonball82 Private E-2

    It comes up with a message box - cannot fully remeber what it says, will run it again and post the message to you.
    But from what I can remember it cannot delete it due to something to do with Start up.
     
  14. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Ok, Let me know so we can get this removed. Also look in Add\Remove Programs for anything relating to this. Sometimes it will be in there.
     
  15. Dragonball82

    Dragonball82 Private E-2

    It says:
    'Some problems couldn't be fixed; the reason could be that the associated files are still in use (in memory). This could be fixed after restart. May S&D run on restart?'

    Sorry my mistake about Start up ! However I have clikcked YES to this, but still same response after restart.
     
  16. Dragonball82

    Dragonball82 Private E-2

    Oh looked in Add/Remove Progs - nothing suspicious their.
     
  17. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    What is it finding? Is it files or registry entries?
     
  18. Dragonball82

    Dragonball82 Private E-2

    Looks like registry entries.
    HKEY_USERS\S-1-5-19\Software\FunWebProducts
     
  19. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Let's try this before we start with .reg files.

    First:

    Download Ad-Aware SE

    Second:

    Select "Check For Updates" download the available udapte.

    Third:

    Click Start, Choose Full System Scan.

    Remove all found infections.

    Do you have either of these in add/remove?

    Let me know if this fixes it.
     

    Attached Files:

    • 1.gif
      1.gif
      File size:
      3.3 KB
      Views:
      8
    • 2.gif
      2.gif
      File size:
      4.2 KB
      Views:
      7
  20. Dragonball82

    Dragonball82 Private E-2

    I have neither of the programs you listed in the .gif files

    I have been using Adaware SE Personal with regular updates - this finds nothing. Am downloading the new version now and will run that. Will reply with answer soon.
    Thanks

    Do you guys ever sleep - aren't you in USofA is it night there?
    I applaud your assistance :) and persistance :cool:
     
  21. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Its 11:18 AM here right now.
     
  22. Dragonball82

    Dragonball82 Private E-2

    Oh I see ~23hrs ahead.
    Still scanning Adaware

    Can I ask how you guys get your tags (e.g you are First Sergeant) Is there an order - there seem to be many different varietys
     
  23. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    They are determined by post count. Your title will be "Private First Class" when you reach 30 post.
     
  24. Dragonball82

    Dragonball82 Private E-2

    Oh nothing to do with cleverness in PC (or Mac) land !! :) Only joking :)

    Anyhoot back to it Adaware done nothing found.
     
  25. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download SpySweeper (30 Day Trial)

    Update your definitions then do a full sweep of drive c:\


    Let me know how this works :)
     
  26. Dragonball82

    Dragonball82 Private E-2

    OK as long as I don't keep getting asked to pay after 30days !
     
  27. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    You wont be able to update after the 30 days is up. This is a fully functional trial so it will remove everything, no limitations.
     
  28. Dragonball82

    Dragonball82 Private E-2

    Cool its from MG - I kinda trust it then :cool:

    Tis running now - will reply with its answer.....maybe some time.
    Black coffee time :D

    So what do you do - job wise?
    I am currently trying to get into to IT field (just left metal pretreatment job), looking at MCDST exam soon, am learning as I go.
     
  29. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I am currently in school for Electrical & Computer Engr. Master's. Got a while left lol
     
  30. Dragonball82

    Dragonball82 Private E-2

    Thats a tad different to what I thought.... is that PC build software type or hardware/motherboard etc?

    SpySweeper still going :rolleyes:
     
  31. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    When I am complete, I hope to be able to do it all. :D
     
  32. Dragonball82

    Dragonball82 Private E-2

    When you do can you create a PC with self destruct mode ! :D

    SpySweeper done - removed alot 138 traces 16 items, however 4 ignored traces... mean anything ?
     
  33. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    :D , What was the 4 ignored products?
     
  34. Dragonball82

    Dragonball82 Private E-2

    Ran Spybot S&D again..... removed DSOExploit, however CoolWWWSearch.Googlems + FunWebProducts could not be.

    Now I have 2 unremovables in S&D, what is going on.
     
  35. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  36. Dragonball82

    Dragonball82 Private E-2

    Not sure how to view ignored traces in SpySweeper
     
  37. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Make sure you update SpyBot S&D by clicking on "Search For Updates" and download all available updates. Just in case you havnt :p
     
  38. Dragonball82

    Dragonball82 Private E-2

    Scanning now - although have already done this.
    Will be back
     
  39. Dragonball82

    Dragonball82 Private E-2

    Ok now its getting wierd... CoolWWWSearch.Googlems was NOT present using CWShredder, but was in S&D.
    Just run S&D again, NO CoolWWWSearch.Googlems? - however still got FunWebProducts

    What is going on ??
     
  40. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    This is weird, post me another HJT log to make sure everything there is still ok.
     
  41. Dragonball82

    Dragonball82 Private E-2

    HJT log as requsted.
    What a cuffuffle :)
     

    Attached Files:

  42. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Have HJT fix this entry,

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (file missing)

    Other than this, everything looks ok. I will have Chaslang or PP check this out to be sure. Im sure they will think of something.
    Hang in there until one of them arrives.
     
  43. Dragonball82

    Dragonball82 Private E-2

    Have deleted the entry....

    'Other than this, everything looks ok. I will have Chaslang or PP check this out to be sure. Im sure they will think of something.
    Hang in there until one of them arrives.'

    OK will wait for Chaslang or PhilliePhan - hope there not too long :)

    Cheers for your help BJGarrick
     
  44. Dragonball82

    Dragonball82 Private E-2

    Will be back 2morrow..... it is now 22:41 GMT

    Hope to speak/annoy someone with my probs then ! :p :)
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually this means you need to reinstall Spybot or download the SDHelper.dll file from Merijn's to replace what was possibly deleted. Some malware like CWS does this.

    Another problem I see in the HJT log is the use of two antivirus programs. You must only have one AV program installed. You have Symantec and AVG. Choose one and uninstall the other.

    Post your Spybot log so we can see what entries it finds and is not fixing. It probably just needs a direct registry edit to fix.
     
  46. Dragonball82

    Dragonball82 Private E-2

    Hi I reinstalled Sbybot + got rid of the older version - same for adaware.
    Ran them both this morning (in safe mode, Sys Restore still off) and I appear to be clean !
    How do I create a log file for Spybot ?

    As for AVG + Symantec, symantec came with Norton (I think :confused: ).
    Why should I only have one installed, isn't it better to be doubly protected :D
     
  47. Dragonball82

    Dragonball82 Private E-2

    Please ignore my inability to find the log !
    I have attached it for you.... hope its the right one.
    I did a separate scan a 2nd time 'not in Safe Mode' and FunWebProducts is back :confused:

    Now I am well confused as to what is going on.
    In your opinion if I have to get rid of 1 AV should it be Symantec (which I cannot update & if I do uninstall it would I have to get rid of Norton) or AVG ?

    Thanks
     

    Attached Files:

  48. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Just found some interesting reading on this. The registry keys are just leftovers and are not dangerous. SpyBot and other tools cannot fix the entries in "HKEY_USERS" like the ones you have. For complete removal, you need to delete the registry entries manually


    Follow me here:

    First:

    Make a backup of your registry before modifying it.

    Now click Start > Run > Type in regedt32 and press OK.

    Second:

    Navigate to the following key:

    HKEY_USERS\S-1-5-19\Software

    Now look for Fun Web Products, After you find it right click and delete it.

    Third:

    Exit Registry Editor.

    Problem should be resolved. Let me know how this work :)
     
  49. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Yes, When running Norton Internet Security your running 2 firewalls including Windows XP Firewall. When running Norton AntiVirus & AVG your running 2 antivirus programs. You need to choose ONE firewall & ONE antivirus program so that you wont have any conflicts and/or problems. Personally I would do without NIS as it can cause major internet connectivity problems if something ever happens to it, same goes with NAV. But its completely up to you what you keep and what you uninstall.
     
  50. Dragonball82

    Dragonball82 Private E-2

    Thanks for getting back to me - sorry was delayed - went out with kids.
    OK please be gentle with me here I am a little wary of doing this, but in the cause of learning I will.
    1. How do I back up reg keys ? On to what format CD, HDD etc
    2. Would like to talk further on the AntiVirus (Norton AVG) topic some more. However one thing at a time is my way to go.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds