Help Please - Drive Cleaner and other redirects

Discussion in 'Malware Help (A Specialist Will Reply)' started by ecknapp8, Nov 26, 2006.

  1. ecknapp8

    ecknapp8 Private E-2

    Hey,

    Great site -- I hope someone can help me out. In MS IE I get redirected to "Drive Clean" and other sites. I've followed your tutorial steps 1-7 and completed all scans in safe mode:
    - CCleaner
    - Spybot
    - Counter Spy
    - BitDefender
    - Panda

    In addition I ran Ad-aware, ewido, and Mcafee Stinger.

    They all came up with different results (VSAdd-in, etc.,) but the problem still remains. I've got reports from most and can post them if you want to see them. I'm attaching hijack, getrun, & shownew to this message. Any help would be great since I'm stuck. Thanks.

    Eric
     

    Attached Files:

  2. ecknapp8

    ecknapp8 Private E-2

    Additional Info/progress:

    After doing some more research, I realized my problem was stemming from a nasty bit of malware "VSAdd-in" I did some checking on the castle cops board for people with similar problems. They recommended running "Superantispyware" and it worked with the following issues identified:

    - Trojan.Winfixer
    - VStoolbar
    - Clickspring/purity

    One remaining issue is my Add/Remove inside Control Panel will not remove the VSAdd-in program. Any advice? Thanks, and I'm posting the log from superantispy and an updated hijack log.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You forgot to attach the logs from Bitdefender and Panda. Do you still have them to attach?

    The below two items should have been uninstall when you first ran the READ & RUN ME while on step 0. But VS-Add may be gone now that you ran Super-AS. If you had uninstalled it while running the READ ME, that scan may not have been needed (assuming it actually would uninstall).
    Viewpoint Media Player
    VSAdd-in for Internet Explorer

    You still need to uninstall Viewpoint Media Player.

    Also, as far as I know the below WONswap program is either malware, installs malware, or is bundled with malware!! Did you knowingly install this? If not you should uninstall it too.
    WONswap


    Uninstall the below old version of Sun Java:
    J2SE Runtime Environment 5.0

    Now install the current version of Sun Java from: Sun Java Runtime Environment


    You also show the below programs are installed
    AOL Spyware Protection
    ewido anti-spyware 4.0
    Sunbelt CounterSpy
    Super-Antispyware

    Are any of the last three paid versions? If not do you plan on buying them? The point is that you do not want to have too many programs like this installed and eating up valuable system resources and slowing your PC down.

    Since I'm not sure what the total status of your PC is after running the Super-AS scan, I going to give you steps below based on your new HJT log and also on your old runkeys.txt and newfiles.txt logs. Thus some items may no longer be present.


    Continue by downloading a tool we will need - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {013A653B-49A6-4f76-8B68-E4875EA6BA54} - C:\WINDOWS\system32\ibkjofss.dll (file missing)
    O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll (file missing)
    O2 - BHO: (no name) - {BFFBF128-4F74-4614-B830-1B950F77EF1A} - (no file)
    O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
    O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll (file missing)
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
    O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)

    After clicking Fix, exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\wnscpsv.exe
    C:\WINDOWS\system32\yuuqfcfr.exe
    C:\WINDOWS\system32\nsatqqgm.dll
    C:\WINDOWS\system32\pmkhi.dll
    C:\WINDOWS\system32\ihkmp.ini
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.
    After reboot locate the below folders and delete if found:
    C:\Program Files\VSAdd-in

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  4. ecknapp8

    ecknapp8 Private E-2

    Ok -- I followed your instructions closely, and my computer seems to be running fine. IE is giving me no problems what-so-ever.

    I only had a couple issues/questions:

    1) VSAdd-in still shows up in Add/Remove programs, but the remove button has no effect. Any idea how to get rid of it or should I just ignore it since it doesn't seem to be doing any more harm?

    2) The files in the System 32 folder you wanted killbox to take out were not there. From reading your Note, I didn't think that was a big deal.

    3) I removed CounterSpy and ewido. Thanks for the tip. Because of my luck with SAspyware, I'm going to leave that on.

    4) Do you still need the early logs for Bitdefender and Panda? If so I can attach them to another post.

    I am attaching the logs for HJT, Run, and Show.

    By the way -- you guys rock! Thanks for you help.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try using this: Your Uninstaller! 2006

    Not completely true. One is still there and I just found another. Delete these:
    C:\WINDOWS\system32\ihkmp.tmp
    C:\WINDOWS\system32\ihkmp.ini2

    Just remember that SAS provides no malware blocking unless you buy it.

    Don't need them now.
     
  6. ecknapp8

    ecknapp8 Private E-2

    - I used Your Uninstaller! and it removed VSAdd-in (plus Viewpoint which had come back after a reboot). Apparently were still tied to some residual junk in the registery, which it cleaned up.

    - Killbox took out the two files you referenced with no problem.

    I am attaching my latest log from HJT. Everything is running great -- so here's hoping its clean!

    Thanks again for all your help.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  8. ecknapp8

    ecknapp8 Private E-2

    Done! Thanks for all your help. You guys do great work.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds