how can i remove fun web products?

Discussion in 'System Security & Infection Support' started by brent, May 6, 2005.

Thread Status:
Not open for further replies.
  1. brent

    brent Reason

    Joined:
    Feb 6, 2004
    Messages:
    37
    Likes Received:
    0
    Location:
    Australia
    hi all
    i somehow have ended up with fun web products i have run adaware and spybot but neither will remove it can someone help?
     
    brent, May 6, 2005
    #1
    1. Advertisements

  2. brent

    Fenis-Wolf VIP Member

    Joined:
    Apr 30, 2003
    Messages:
    2,951
    Likes Received:
    35
    Location:
    Ann Arbor, Mi
    You should make an attempt to uninstall it in Safe Mode. Press F8 after leaving the BIOS and select 'Safe Mode' from the menu. Then run AdAware. This will almost always clean up anything nasty on your system.
     
    Fenis-Wolf, May 6, 2005
    #2
    1. Advertisements

  3. brent

    James Photojournalist

    Joined:
    Dec 24, 2002
    Messages:
    6,662
    Likes Received:
    35
    I believe CWS Shredder will remove it. Check out our Handy Tools under THQ Tools.
     
    James, May 6, 2005
    #3
  4. brent

    brent Reason

    Joined:
    Feb 6, 2004
    Messages:
    37
    Likes Received:
    0
    Location:
    Australia
    still no joy

    Unfortunatly both suggestions havnt solved it, i tired cws shredder and it found nothing. I also started in safe mode and ran adaware it also found nothing also in safe mode i ran spybot and it found 5 problems namely, Fun Web Products, but it cant remove them due to be still used in the system memory. Then it gives me the option to run again on startup which i did, still nothing. It reports 5 entries each one is titled HKEY________ . i dont know if thats enough info to give u more of an idea but if not let me know please.
    thanks
     
    brent, May 6, 2005
    #4
  5. brent

    James Photojournalist

    Joined:
    Dec 24, 2002
    Messages:
    6,662
    Likes Received:
    35
    I would install MS AntiSpyware and run it once in Windows, then run it once in Safe Mode. If that doesn't work, post your HijackThis log here.
     
    James, May 6, 2005
    #5
  6. brent

    brent Reason

    Joined:
    Feb 6, 2004
    Messages:
    37
    Likes Received:
    0
    Location:
    Australia
    still no good, james do u mind if i email u the log?
     
    brent, May 7, 2005
    #6
  7. brent

    Fenis-Wolf VIP Member

    Joined:
    Apr 30, 2003
    Messages:
    2,951
    Likes Received:
    35
    Location:
    Ann Arbor, Mi
    Post it here
    Never privately message us mods. It is a detriment to this forum. Please read the rules, which are posted at the top of every page under FAQ/Guides.
     
    Fenis-Wolf, May 7, 2005
    #7
  8. brent

    brent Reason

    Joined:
    Feb 6, 2004
    Messages:
    37
    Likes Received:
    0
    Location:
    Australia
    Logfile of HijackThis v1.99.1
    Scan saved at 11:44:24, on 07.05.2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kav.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Error Nuker\bin\ErrorNuker.exe
    C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
    C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
    C:\Program Files\Logitech\MouseWare\system\em_exec.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kavmm.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\brent\Desktop\HijackThis.exe
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fasterhomepage.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fasterhomepage.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: (no name) - {04079856-5845-4dea-848C-3ECD647AA554} - C:\Program Files\MySearch\SrchAstt\1.bin\MYSRCHAS.DLL
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
    O4 - HKLM\..\Run: [KAV50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kav.exe" -run -n PersonalPro -v 5.0.0.0 -chkss
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [Error Nuker] C:\Program Files\Error Nuker\bin\ErrorNuker.exe autostart
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O15 - Trusted Zone: *.boxsearch.net
    O15 - Trusted Zone: *.webseeking.com
    O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
    O23 - Service: Kaspersky Anti-Virus Service (KLBLMain) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kavmm.exe" -run bl -n PersonalPro -v 5.0.0.0 -ttsr 10000000 (file missing)
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
     
    Last edited by a moderator: May 8, 2005
    brent, May 8, 2005
    #8
  9. brent

    James Photojournalist

    Joined:
    Dec 24, 2002
    Messages:
    6,662
    Likes Received:
    35
    R3 - URLSearchHook: (no name) - {04079856-5845-4dea-848C-3ECD647AA554} - C:\Program Files\MySearch\SrchAstt\1.bin\MYSRCHAS.DLL
    O15 - Trusted Zone: *.boxsearch.net
    O15 - Trusted Zone: *.webseeking.com
     
    James, May 8, 2005
    #9
  10. brent

    brent Reason

    Joined:
    Feb 6, 2004
    Messages:
    37
    Likes Received:
    0
    Location:
    Australia
    still no good i removed what u said james then ran spybot again, they are still there
     
    brent, May 9, 2005
    #10
  11. brent

    brent Reason

    Joined:
    Feb 6, 2004
    Messages:
    37
    Likes Received:
    0
    Location:
    Australia
    new hijack this log
     

    Attached Files:

    brent, May 9, 2005
    #11
  12. brent

    James Photojournalist

    Joined:
    Dec 24, 2002
    Messages:
    6,662
    Likes Received:
    35
    O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cabO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

    Remove these options in Safe Mode. You should also use the advanced tools in MS AntiSpyware to reset your browser settings. Also, check your HOSTS file and let us know what's in it.
     
    James, May 9, 2005
    #12
  13. brent

    brent Reason

    Joined:
    Feb 6, 2004
    Messages:
    37
    Likes Received:
    0
    Location:
    Australia
    sorry man what is a host file?...lol
     
    brent, May 9, 2005
    #13
  14. brent

    James Photojournalist

    Joined:
    Dec 24, 2002
    Messages:
    6,662
    Likes Received:
    35
    Put this into your Run box: %windir%\system32\drivers\etc

    Open the HOSTS file in notepad.
     
    James, May 9, 2005
    #14
  15. brent

    brent Reason

    Joined:
    Feb 6, 2004
    Messages:
    37
    Likes Received:
    0
    Location:
    Australia
    should i attach the host file here?
     
    brent, May 10, 2005
    #15
  16. brent

    brent Reason

    Joined:
    Feb 6, 2004
    Messages:
    37
    Likes Received:
    0
    Location:
    Australia
    Another question, what programs do u use to keep your pc running smoothly?
     
    brent, May 10, 2005
    #16
  17. brent

    James Photojournalist

    Joined:
    Dec 24, 2002
    Messages:
    6,662
    Likes Received:
    35
    No, just paste what is in it. The only thing I run once in awhile is Norton WinDoc and MS AntiSpyware to scan once in awhile.
     
    James, May 10, 2005
    #17
  18. brent

    brent Reason

    Joined:
    Feb 6, 2004
    Messages:
    37
    Likes Received:
    0
    Location:
    Australia
    Theres nothing in it, if i have done it properly which i think i have. There was 2 host file s. I tried to delete entries from the registry but it wouldnt let me, then i ran spybot again now it only finds 2 problems instead of 4 so i guess u could say im halfway there.
    thanks for your time and effort james greatly appreciated :)
     

    Attached Files:

    brent, May 10, 2005
    #18
  19. brent

    brent Reason

    Joined:
    Feb 6, 2004
    Messages:
    37
    Likes Received:
    0
    Location:
    Australia
    Its gone dont know excatly how but it is. I deleted everything through regedit ran spybot then i had only 2 entries left instead of 4. Then i repeated the same process after a reboot and now its completly gone. Im very happy right now:) a big thank u to the techieHQ community
     
    brent, May 12, 2005
    #19
  20. brent

    nbgeezer

    Joined:
    Apr 18, 2011
    Messages:
    1
    Likes Received:
    0
    Remove Fun Web Products

    I entered "regedit" in the search function. Then opened the folder "HKEYCLASSESROOT". I ran the slider down to find the "Fun Web Products" folders - I found several. I right clicked on and deleted each one then closed "regedit" and restarted my computer. This seems to have fixed the problem. Good Luck
     
    nbgeezer, Apr 18, 2011
    #20
    1. Advertisements

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments (here). After that, you can post your question and our members will help you out.
Thread Status:
Not open for further replies.