1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive fun4u malware removal

Discussion in 'Malware and Virus Removal Archive' started by ChillyToes74, 2015/04/09.

Thread Status:
Not open for further replies.
  1. 2015/04/09
    ChillyToes74

    ChillyToes74 Inactive Thread Starter

    Joined:
    2015/04/08
    Messages:
    2
    Likes Received:
    0
    [Inactive] fun4u malware removal

    Hello,
    Evidently my computer got infected with some kind of malware called fun4u. This is a "pop-up malware ". I currently have 2015 McAfee Total Protection installed on my computer but somehow it missed this malware. Coincidentally, this malware started showing up either the day or the day after I installed this brand new in-the-box software.
    I've tried looking for fun4u in my program file/s but there's nothing there that indicated this malware. I've looked in the .exe file and can't find anything there either.
    The following is what happens:
    I open a browser (usually FireFox or Chrome) and I can open different web sites but if I try to click on ANY link on ANY web site the browsers start opening very quickly, a bunch of them. Plus it allows these little "ad-windows" from just about every area of the page (left/right side, top/bottom, etc.) If I try to close those little pop-ups it will cause ANOTHER BROWSER and still doesn't close the add. Consequently I can't surf the Internet at all because of all these issues. I have no idea what caused this.
    Any help you might be able to provide would be greatly appreciated.
    Thanks.
    My computer info:
    Dell Inspirion
    Windows 8
    Intel i5 core processor
    64 bit OS processor, x64bassed processor
    Use either: Firefox, or Chrome browsers


    Dell Inspirion
     
  2. 2015/04/09
    Admin.

    Admin. Administrator Administrator Staff

    Joined:
    2001/12/30
    Messages:
    6,687
    Likes Received:
    107
    Hi,

    Read this post as indicated at the top of this forum & follow the instructions.
     

  3. to hide this advert.

  4. 2015/04/09
    ChillyToes74

    ChillyToes74 Inactive Thread Starter

    Joined:
    2015/04/08
    Messages:
    2
    Likes Received:
    0
    fun4u

    # AdwCleaner v4.201 - Logfile created 08/04/2015 at 22:52:17
    # Updated 08/04/2015 by Xplode
    # Database : 2015-04-08.1 [Server]
    # Operating system : Windows 8 (x64)
    # Username : Kat - RUBYRED
    # Running from : C:\Users\Kat\Downloads\adwcleaner_4.201.exe
    # Option : Cleaning

    ***** [ Services ] *****

    Service Deleted : {c5e48979-bd7f-4cf7-9b73-2482a67a4f37}Gw64
    [#] Service Deleted : 0094081427852267mcinstcleanup

    ***** [ Files / Folders ] *****

    Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip Malware Protector
    Folder Deleted : C:\Program Files (x86)\globalUpdate
    Folder Deleted : C:\Program Files (x86)\WinZip Malware Protector
    Folder Deleted : C:\Users\Kat\AppData\Local\Temp\ClearThink
    Folder Deleted : C:\Users\Kat\AppData\Local\globalUpdate
    Folder Deleted : C:\Users\Kat\AppData\LocalLow\AVG SafeGuard toolbar
    File Deleted : C:\Users\Public\Desktop\WinZip Malware Protector.lnk
    File Deleted : C:\WINDOWS\Reimage.ini
    File Deleted : C:\Users\Kat\AppData\Local\Temp\ReimageRepair.exe
    File Deleted : C:\WINDOWS\System32\wsusnative64.exe
    File Deleted : C:\WINDOWS\System32\drivers\{c5e48979-bd7f-4cf7-9b73-2482a67a4f37}Gw64.sys
    File Deleted : C:\Users\Kat\AppData\Roaming\Mozilla\Firefox\Profiles\g76f85h4.default\searchplugins\astromenda.xml
    File Deleted : C:\Users\Kat\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_homes.trovit.com_0.localstorage
    File Deleted : C:\Users\Kat\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_homes.trovit.com_0.localstorage-journal
    File Deleted : C:\Users\Kat\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_searchresults.harrietcarter.com_0.localstorage
    File Deleted : C:\Users\Kat\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_searchresults.harrietcarter.com_0.localstorage-journal
    File Deleted : C:\Users\Kat\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
    File Deleted : C:\Users\Kat\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage-journal
    File Deleted : C:\Users\Kat\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.reimageplus.com_0.localstorage
    File Deleted : C:\Users\Kat\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.reimageplus.com_0.localstorage-journal

    ***** [ Scheduled tasks ] *****

    Task Deleted : WinZip Malware Protector_startup
    Task Deleted : 33f5d077-5033-4263-87c3-76948c5aafc7-4

    ***** [ Shortcuts ] *****


    ***** [ Registry ] *****

    Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\REI_AxControl.DLL
    Key Deleted : HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine.1
    Key Deleted : HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}
    Key Deleted : HKCU\Software\GlobalUpdate
    Key Deleted : HKCU\Software\IM
    Key Deleted : HKCU\Software\ImInstaller
    Key Deleted : HKCU\Software\InstallCore
    Key Deleted : HKCU\Software\SweetIM
    Key Deleted : HKCU\Software\Reimage
    Key Deleted : HKCU\Software\reimagerepair
    Key Deleted : HKLM\SOFTWARE\GlobalUpdate
    Key Deleted : HKLM\SOFTWARE\ImInstaller
    Key Deleted : HKLM\SOFTWARE\SweetIM
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinZip Malware Protector_is1
    Key Deleted : [x64] HKLM\SOFTWARE\Reimage
    Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local

    ***** [ Web browsers ] *****

    -\\ Internet Explorer v10.0.9200.17183


    -\\ Mozilla Firefox v37.0.1 (x86 en-US)

    [g76f85h4.default\prefs.js] - Line Deleted : user_pref( "extensions.astrmndasr.hmpgUrl ", "hxxp://astromenda.com/?f=1&a=ast_app_14_38_ch&cd=2XzuyEtN2Y1L1Qzu0EtD0D0ByDyD0C0E0EtA0D0A0BzytCtDtN0D0Tzu0SzyzyyEtN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1[...]
    [g76f85h4.default\prefs.js] - Line Deleted : user_pref( "extensions.astrmndasr.newTabUrl ", "hxxp://astromenda.com/?f=2&a=ast_app_14_38_ch&cd=2XzuyEtN2Y1L1Qzu0EtD0D0ByDyD0C0E0EtA0D0A0BzytCtDtN0D0Tzu0SzyzyyEtN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDy[...]
    [g76f85h4.default\prefs.js] - Line Deleted : user_pref( "extensions.astrmndasr.prtnrId ", "WSE_Astromenda ");
    [g76f85h4.default\prefs.js] - Line Deleted : user_pref( "extensions.astrmndasr.srchPrvdr ", "Astromenda ");
    [g76f85h4.default\prefs.js] - Line Deleted : user_pref( "extensions.astrmndasr.tlbrSrchUrl ", "hxxp://astromenda.com/?f=3&a=ast_app_14_38_ch&cd=2XzuyEtN2Y1L1Qzu0EtD0D0ByDyD0C0E0EtA0D0A0BzytCtDtN0D0Tzu0SzyzyyEtN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzyt[...]

    -\\ Google Chrome v41.0.2272.118

    [C:\Users\Kat\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Extension] : bopakagnckmlgajfccecajhnimjiiedh
    [C:\Users\Kat\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Default_Search_Provider_Data] :

    *************************

    AdwCleaner[R0].txt - [21846 bytes] - [08/04/2015 22:50:09]
    AdwCleaner[S0].txt - [6469 bytes] - [08/04/2015 22:52:17]

    ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6528 bytes] ##########

    JUST AN FYI: I think I'm doing this properly, but not exactly sure. I read the "initial" post about how this site works and I thought I was, but evidently I wasn't.
    I hope this is what you're asking for.
    Let me know please.
    Thanks.
     
  5. 2015/04/09
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Please follow the instructions given on the page Arie linked to - Step 1 ....

    Also: there's no need to mark your logs bold
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.