Suspect url

I thought there was a special place to report websites. Sorry, can’t find it atm.
http://www.openoffice.us DOT com/download-openoffice-free.php contains this thing:
http://malwaretips.com/blogs/remove-pup-downloadadmin-virus-removal-guide/

WOT alerted me. For once, it was right.

PUP = not virus / Possible Unwanted Program … usually crap that comes bundled with freeware downloads
avast PUP detection is default off exept for in boot scan… so if you want PUP detection, turn it on in the shields and scan types you want it

this may save you from some of them installing Unchecky http://unchecky.com/

PUP are usually removed with Malwarebytes and AdwCleaner
if you need help from a removal expert, follow instructions http://forum.avast.com/index.php?topic=53253.0

Hi CCV,

Why did you go with Open Office and not the newer LibreOffice?

Download may bundle potentially unwanted software during setup with minimal user consent.
DrWeb detects this as Adware.Downware.2220. Detection here: http://v.virscan.org/Adware.Downware.2220.html
See: https://www.virustotal.com/nl/file/69c9c7ca12642ca0958618070818592b6e2871dbfda3353c6e3eaa72c87e8060/analysis/1397177309/
See for April 17th last: http://www.herdprotect.com/openofficesuite-setup.exe-a169d68d37709427d8b3b98cdbf922705a2d1291.aspx
More recent: http://www.herdprotect.com/openofficesuite-setup.exe-91e16fa2bd687eef136559eb6f431cb821f54667.aspx

Manual removal instruction from Strelian Pilici in his article here: http://malwaretips.com/blogs/remove-pup-downloadadmin-virus-removal-guide/
and here: http://www.malwareremovalguides.info/pup-downloadadmin-removal-guide/
As you see there a combination of AdwCleaner and MBAM will cleanse your puter of this pup.

polonus

Hello,

I’ve used OF (Open Office). I didn’t have it come bundled w/ anything extra.

Hi Michael,

That is the whole discussion here. We find ourselves in a discussion to-day that the user has a great responsibility to seek those downloads free of PUP and adware bundled crap. So you could download from the developer site, whenever that developer has not fallen for the crap bundling craze. Or you know the download is free of crap because you download from G2G or another adware remover platform. As the commercialization and marketing prevalence on the Interwebs takes larger and larger proportions and the user protection is less of a consideration/priority this situation will only get worse until those that bundle have shot themselves in the feet so badly they are going knee-bent and it is starting to backfire beyond the scope of profits they may reap from parties like pup-bundlers and trackers. Follow the money and you get a the culprit of the problems here.

polonus

I should mention, the site in question is not the official Open Office download site (it’s not even the latest version of OO - it’s 3.x, not 4.x.)
I have never found any problem with Open Office, from the legitimate source, in some years of using it.

I didn’t install the software either, tho a friend might well have. I downloaded the file to check out if there was indeed malware there, as WOT reported.

As far as I can tell, avast! Shields are set to detect PUPs (and “Suspicious” files) by default. Web shield is working too, I know.
Puran Defrag tries to download some ‘download manager’ during install. Avast! detects it as a PUP and blocks it OK. Something on our laptop looked like a Windows update download, but avast! goes ‘too new or too rare etc…’, as well (that was yesterday).

Scan settings are a different matter, for sure. Um, but… Now I find a problem.
How do I get Scan from Windows Explorer (context menu) to save settings? Access to Settings in this case is only available after a scan. Even then, any changes made just disappear after another scan.
Something for avast! developers to look at, perhaps.