Toseeka won't go away

Discussion in 'Malware Help (A Specialist Will Reply)' started by ugean, Dec 28, 2009.

  1. ugean

    ugean Private First Class

    Please help. I have run the READ & RUN ME FIRST. Malware Removal Guide the best that I can. I was very through and tried every detail. Most went smooth until the end. Every time I run the MGTools it locks up at:
    Zipping hijackthis.log
    updating: hijackthis.log (208 bytes security) (deflated 68%)

    (let go overnight still no change)

    I am running XP on C:\ and this is my primary operating system that is in trouble. Every time I open my browser (firefox or IE) I get a pop up 4 tabs long. Any and all search engines are completely useless. Every time I select a link I get taken to one of the virus sites. Generally the scans come back clean however when I finally had time yesterday to run all of the scans and steps in order Malwarebytes did find one and occasionally AVG will come up with a threat. This has been going on for a bout a month as I have not had time to run all of the steps in READ & RUN ME FIRST. Malware Removal Guide. Each scan takes about 2-2.5 hours.

    On F:\ I am running Vista but rarely us until lately. It is not infected but hardly any of my software or programs are installed or work on it. None of the scan in the attached logs were run from Vista.

    I also have a couple of Networked computers that I have run all of the scans from. They are not infected and do not find anything on this one. I would like to add W7 pro but want to ensure XP is clean first.

    I have had this virus once before and nothing seemed to work for the longest time then all of a sudden it was gone. I had upgraded fire fox and IE and that still didn't work before.

    Also I cannot update AVG to 9.0 as I keep getting an error. Windows update for : Microsoft .net Framework 3.5 Family Update KB959209 x86 does not install. As I just copied that from the little box I realized there was another update and I have just installed that. (Sometimes I miss them because I have to ignore the other one)

    Please help me you guys are the Greatest
     

    Attached Files:

  2. ugean

    ugean Private First Class

    Here are the MGlogs that I do have
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O1 - Hosts: 91.212.127.226 osguard-pro.com
    O1 - Hosts: 91.212.127.226 www.osguard-pro.com
    O2 - BHO: FlashGetBHO - {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - C:\Documents and Settings\Stephen\Application Data\FlashGetBHO\FlashGetBHO3.dll (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. ugean

    ugean Private First Class

    I did what you asked but MGtools still locked up at the same point (only 67% this time). Attached are the logs and my browser is still infected.

    note: Combo fix updated when I ran it.

    thank you for your help
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not a message that it is locking up. That message tells you that it already finished compressing the HijackThis log and that it compressed it by 67%. It is somewhere after this that the process is not able to finish.

    I can see from your MGlogs.zip file that some of the logs are not getting updated due to this. Some logs are still from 8/11/2009 since your previous thread was never completed. This may e due to the same thing I mentioned to you last time that was about various required Windows Services not running properly (not a malware problem). It is is due to your Windows installation being messed up. Your system thinks some of your Windows OS files are to be found on drive D. You must have installed a second copy of Windows at some point onto a new drive to cause this. You can see the below to services referring to drive D:

    O23 - Service: NetMeeting Remote Desktop Sharing (mnmsrvc) - Unknown owner - D:\WINDOWS\system32\mnmsrvc.exe (file missing)
    O23 - Service: Remote Desktop Help Session Manager (RDSessMgr) - Unknown owner - D:\WINDOWS\system32\sessmgr.exe (file missing)



    And I believe you have other services like WMI doing the same and this may be why the MGtools scans cannot complete. Again this is not a malware problem, it is your Windows installation.

    There is a required system file missing that we will replace now, and I will also have ComboFix delete the current MGlogs.zip file so that old information is removed.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. ugean

    ugean Private First Class

    I did everything you said and let MGtools run over night. Same thing. Combo fix did update when I ran it. Here are the new logs. I know it did something because when I downloaded the new mgtools i noticed that combo fix did delete the old mglogs.zip
    Thanks
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download and run the below special version of MGtools. This new version is named MGtoolsSF.exe

    MGtoolsSF

    After running it, attach the new C:\MGlogs.zip file. Let me know if you still notice a hang after the HijackThis log is deflated.
     
  8. ugean

    ugean Private First Class

    Happy New Year! Sorry for the delay in getting back to you. It locked up at the same place again, but this time after tdsslog.txt it gave me an error message:

    There was an error accessing Windows Management Instrumentation. Please verify that it is installed on you system

    Once I clicked ok it went on to userid something...

    I did not see any log files with SF at the end but this MGtools was updated today.

    Thanks
     

    Attached Files:

  9. ugean

    ugean Private First Class

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Happy NY!

    See what I said at the beginning of message # 5. This is one of the services I mentioned that is messed up in your Windows installation. This is not a malware problem but it is part of all you troubles. Toseeka does not appear to be your problem but since some of the scans cannot run properly due to your Windows installation being broken, we cannot see everything we need to see.

    Please do the following.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to NetMeeting Remote Desktop Sharing
    • Then right click the entry, select Properties
    • On the next form you will see the Path to executable: setting set to D:\Windows\System32\mnmsrvc.exe change this so that it says C:\WINDOWS\System32\mnmsrvc.exe
    • Make sure Start-up Type is Disabled
    • Make sure Service status: is Stopped
    • Now click Apply and OK to get back to the list of Services
    • Scroll down to Remote Desktop Help Session Manager
    • Then right click the entry, select Properties
    • On the next form you will see the Path to executable: setting set to D:\WINDOWS\system32\sessmgr.exe change this so that it says C:\WINDOWS\system32\sessmgr.exe
    • Make sure Start-up Type is Manual
    • Make sure Service status: is Stopped
    • Now click Apply and OK to get back to the list of Services
    • Scroll down to Windows Management Instrumentation
    • Then right click the entry, select Properties
    • On the next form you will see the Path to executable: setting. I'm not sure what it is currently set to but make sure it is set to the C:\WINDOWS\system32\svchost.exe -k netsvcs
    • Make sure Start-up Type is Automatic
    • Make sure Service status: is Started
    • Now click Apply and OK to get back to the list of Services
    • Click OK until you get back to Windows.
    There could be other services that are also messed up and set to drive D or to the wrong state. That was part of the reason for giving you the new MGtoolsSF which was trying to list services for me. But since you have too many things broken, it would not run. Let's see if the above helps and find out exactly what happens.

    Click Start, Run, and enter cmd and click OK. This will open a command prompt. In the command prompt Window enter the below black bold print commands. The purple text is only comments to help you follow what should be happening. Observe the spaces in the commands.

    cd C:\MGtools <<-- if this works, the prompt should change to C:\MGtools>
    processdll << if this runs, a list of process should scroll by and a file name procdll.txt should appear on your Desktop. I expect you may get an error. Tell me exactly what happens.
    ServiceFilter.vbs << if this runs, the prompt will quickly return to just C:\MGtools but a few log files should be created. I expect you may get an error. Tell me exactly what happens.
    GetLogs.bat <<-- should run a full scan of all MGtools. Tell me exactly what happens and what error messages you get if/when it hangs.


    Attach the new C:\MGlogs.zip file. Along with a description of what happened
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No since I'm not sure at this point this is your problem and you have major issues in your Windows installation that you need to fix.
     
  12. ugean

    ugean Private First Class

    "On the next form you will see the Path to executable: setting set to D:\Windows\System32\mnmsrvc.exe change this so that it says C:\WINDOWS\System32\mnmsrvc.exe"

    I was not able to change this on any of them. I could highlight sections but I could not change anything about it.

    "Make sure Start-up Type is Disabled" (I don't know how to do that cool quote thing you do)

    I changed this from Manual to Disabled and it seemed to work.

    "Make sure Service status: is Started"

    Windows Management Instrumentation was Stopped I clicked the Start button and go the message:

    The windows Management Instrumentation service on local computer started and then Stopped. Some services stop automatically if they have no work to do, for example, the performance logs and alerts Service.

    "cd C:\MGtools <<-- if this works, the prompt should change to C:\MGtools>"
    Worked fine

    "processdll << if this runs, a list of process should scroll by and a file name procdll.txt should appear on your Desktop. I expect you may get an error. Tell me exactly what happens."

    The cursor just moved to the next line. I let it go for a while to see if it would do anything and nothing. I could not type anything else so I closed it. then reopened cmd and wasn't sure if it should be "process.dll" so I tried that an it did not recognize the command

    "ServiceFilter.vbs << if this runs, the prompt will quickly return to just C:\MGtools but a few log files should be created. I expect you may get an error. Tell me exactly what happens."

    "the prompt will quickly return to just C:\MGtools" this is what it did. I do not know about any log files. Are they in MGlogs.zip?

    "GetLogs.bat <<-- should run a full scan of all MGtools. Tell me exactly what happens and what error messages you get if/when it hangs."

    I got the error:

    There was an error accessing Windows Management Instrumentation. Please verify that it is installed on you system

    Three times. Once Just after the scan started and twice just after tdsslog.txt

    Then the scan froze up at the same point it has been.

    Thank you for taking the time with a Rookie who has been building new systems with old parts over the years.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I suggest that you reboot into safe mode and repeat my previous instructions. Also if it still does not allow you to change the D: into a C: then stop and then disable the service first. Then retry the change to the Path. Then set the Startup Type and Status back to the proper states. You need to get these problems with your Windows services fixed. This is not a malware problem. If you cannot fix it, you will need to may need to do a Windows repair or a reinstall as this is the cause of many of your problems.
     
  14. ugean

    ugean Private First Class

    I cannot access XP safe mode with Vista installed only Vista Safe Mode. (or at least I don't know how to) I have the OEM XP install disk if needed I just do not want to loose any programs that are installed or any files as I do not have enough disk space to copy everything over. Although you may be helpful in getting my wife to approve another HD purchase. I can tell you that Windows (with that disk) has been completely reinstalled since it was on a D:\ drive (at least once).

    I went in under Vista and Windows Management Instrumentation was the only one listed and it was on the F drive like Vista.

    Just tell me what to do. A clean sweep of XP definitely wouldn't be the worst thing I'm just nervous about loosing too much data.

    P.S. I do not mind loosing Vista Just the other files on that drive too. I am going to replace Vista with W7.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can use MSconfig to select safe boot mode for the Win XP setup. I'm not too positive on thinking this will work. Make sure you have no browsers or other processes open when you repeat those steps. If this does not work, then I suggest you figure out how to back up what you need (CD/DVD, flashdrive...etc) and then reinstall XP if you need it.

    Not something I can help you with.

    Why do you need a new HD? Windows reported the below in your logs 261,361,229,824 bytes free

    Okay since you are saying you had Windows installed on drive D at one time that may have something to do with the messed up services. How it got like this would mean someone installed/reinstalled incorrectly.
     
  16. ugean

    ugean Private First Class

    I was beginning to wonder if you ever took a day off...Thanks for your help! I have lots of free space spread out across my drives. If I had to clear my C the back up file would not fit on my F drive. (I tried) I have too many media files that i don't want to loose. If I'm going to end up on W7 maybe it is time I rebuild XP. If I del Vista it will work but it is starting to grow on me since I got this Virus. I will have to think it over and see what I can do. Thank you!
     
  17. ugean

    ugean Private First Class

    Is there a section of your site or can you refer me to somewhere that can assist me with the rebuild of my system when I am ready to do it? I want to avoid having these problems in the future if I do decide to wipe the slate clean. Thanks
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    You could ask specific questions in the Software Forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds