Nightmare called visitorsurveyusa.com

Discussion in 'Malware Help (A Specialist Will Reply)' started by chinnboy, Apr 5, 2015.

  1. chinnboy

    chinnboy Private E-2

    6-10 days ago, I somehow picked up a very annoying adware popup that I've been unable to identify or eliminate with Malwarebytes or AdwareCleaner. They appear everywhere, offering free goodies for doing a survey. The offers are sometimes specific to the site they pop up on, including yahoo and amazon. Yesterday their popup came up when I navigated to MG.

    The initial popup lead to http://helpingtrk.com and from there visitorsurveyusa.com. I did a search with duckduckgo and both showed up with the comment "We would like to show you a description here but the site won't allow us". Not sure what that signifies, but I thought was amusing.

    I spent a considerable amount of time yesterday amassing the logs as directed. Hopefully I did ok and got them attached properly.

    As noted, I don't know how this infected me. This was just set up a few weeks ago with a clean OS install, and a few apps. I don't think I have installed anything downloaded anywhere except MajorGeeks except for some print drivers from Samsung and Canon. Also Java and Fiefox.

    I don't know if or how it could be related, but I also recently have been getting may script hickups, "a script is making your broser run very slow, igore stop etc." Happens with both IE 8 Firefox. I am running XP SP3 and IE8 with all updates.

    One thing that puzzled me along the way was the youtube video pertaining to attaching files to posts. It looked like doing a C:\majorgeeks\analyze\tools and something from there. I don't have anything like that or know how to get it. I do have an old version of HighjackThis as well as the newer Trend version, and as sonn as I send this post I'm going to install and run one of them. I'll make sure to save a log. HT is an old time firend I haven't seen for a long time.

    Any insights and guidance greatly appreciated.
     

    Attached Files:

  2. chinnboy

    chinnboy Private E-2

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which browser are you having problems with? If Internet Explorer, please run the below reset to defaults

    http://support.microsoft.com/en-us/kb/923737

    Now move on to the below.

    First please run MSconfig and put your PC into Normal Startup mode.


    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\WINDOWS\system32\DRIVERS\hiqbnsb.sys
    C:\Documents and Settings\All Users\Application Data\34DEDDF4CD.sys
    C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
    C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
    C:\WINDOWS\Temp\*.*
    C:\Documents and Settings\SJ\Local Settings\Temp\*.*
     
    :Reg
    [-HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dydtn]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXT log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. chinnboy

    chinnboy Private E-2

    Thanks for getting back We'll try to work thru this but can't at the moment.

    Trying to be helpful here, but you might try the MS link and see what happens for you. For me, whirlygig thing "loading", for 35 minutes now. I suggest: Open IE . Click Tools->Internet Options->Advanced . Go the bottom of the page and click on "Reset"

    I opened mscong, and set it back to normal, then rebooted.

    I then tried OTM. I am getting a screen with 3 tabs. Not sure what to do now. I don't see any type of list. The only choice I have is if I choose Cleanup! I didn't. screenshot attched, I hope.
     
    Last edited: Apr 5, 2015
  5. chinnboy

    chinnboy Private E-2

    I've tried several times to attach a screenshot.rtf uploaded. "Upload failed" Trust me, nothing I can do when I open OTM generates any kind of list.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    It works perfectly fine for me.

    I suggest disable or uninstalling your protection software. It may be getting in your way. Another thing you could try is to run the fix in safe boot mode.

    But after running the reset of IE to defaults, are you still having a problem with IE?

    Or are you using Firefox? If using Firefox then reset it to defaults. Reset Firefox to Defaults
     
  7. chinnboy

    chinnboy Private E-2

    Sorry for the absence. I initially managed to misunderstand your instructions to copy and paste your stuff into OTM. Then I got a missive from she who must be obeyed wanting me to amass a bunch of tax documentation for our son who graduated last year . At which point I was exasperated and suffering severe screen fatigue. So this morning Iwent back to work with fresh eyes.

    Everything seemed to go ok until XP was rebooting, during which I heard I heard an XP thump sound and thought to myself "uh-oh". Sure enough, the generic XP wallpaper comes up but nothing else but A message box-no icons bars or Start button.

    The message:
    "Windows could not find "C\Documenets and Settings\SJ\Desktop\OTM.exe. Make sure you typed the name correctly, and then try again. To seaarch for a file, click the Start button, and then click Search." with an OK button.

    I didn't proceed further.

    I am certain OTM.exe is or was on the desktop. I downloaded and saved it to the desktop, and just ran it from the desktop.

    thought or suggestions?
     
  8. chinnboy

    chinnboy Private E-2

    By the way, I am pretty sure NIS was disabled when all of the logs were generated. I had been disbling it 5 hrs at a time, the last time I disbled it permanently. May leave it that way for a good while.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If OTM.exe is no longer on your Desktop, this would mean NIS deleted it and you would have to start over again. So please check if OTM.exe is still on your Desktop. Just use Windows Explore to navigate to your Desktop and see if OTM.exe is there. If you do not know what Windows Explorer is, it is your Windows shell/file manager. One quick way to open it is to hold down the Windows logo button and then press the 'e' key.
     
  10. chinnboy

    chinnboy Private E-2

    OTM appears to have disappeared from my desktop. NIS shows it is and was not enabled. Search finds OTM.EXE-1849DC11.pf in C:\Windows\Prefetch, size 30k timestamped 9:47am when is when I clicked CleanIt!. It almost seems like it was moved by the startup script when OTM initiated a reboot. I could Uninstall NIS if you think that would help.
     
  11. chinnboy

    chinnboy Private E-2

    This morning I went ahead and uninstalled NIS. At that point I decided to download OTM.exe back to my desktop and try it again. Then unexpected things happened. When I clicked the OTM icon the regular program page did not come up. Instead the entire OTM window was occupied by what looked to be a log. The top line said something to the effect "All junkware enries removed". There were no visible options such as save or print. I believe I right clicked to try and copy the text and everything disappeared. Restarting OTM merely brought up the regular screen.

    I can say for sure that there is no .log or .txt files on my drive that could possibly be associated with OTM, and
    The previously noted OTM.EXE-1849DC11.pf file is now 36kb and datestamped this morning.

    After this, I ran JRT and the log is attached.

    I think its maybe time to give things a rest and see if OTM did actually fix something, and see if I experience reoccurence of the popups. They had appeared occasionally using Yahoo mail, none so far today.
     

    Attached Files:

    • JRT.txt
      File size:
      1.5 KB
      Views:
      1
  12. chinnboy

    chinnboy Private E-2

    Bad news. I tried bouncing around on Amazon yesterday, enough that I thought I would get a popup if it was still active. Looked like it might be gone. Not the case.

    This morning I'm getting them like mad, on both Amazon and eBay. I just got one that was new to me, it filled the screen. This is very frustrating.
     
  13. chinnboy

    chinnboy Private E-2

    Maybe all is not lost. While contemplating the prospect of doing another scratch rebuild, I decided to run through all previous steps and logs in succession. This morning I got 3 popups on 6 clicks with Amazon, similar on eBay. After the above, none so far with a lot more clicks. Knock on wood.

    Perhaps having NIS thoroughly uninstalled thru the entire process.

    When I ran OTM this time I copied and saved the info in the right side box before I rebooted. I'm attaching that. After rebooting I could find no trace of OTM anything. It looks like it deletes itself on reboot. It and RogueKiller are both absent on my desktop.

    Knock on wood, again.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Everything is going away including OTM.exe because you are clicking on the wrong button. The instructions that I gave you stated
    But you are clicking of the CleanUp! button which will remove all the tools not the malware.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds