Toseeka virus help

Discussion in 'Malware Help (A Specialist Will Reply)' started by ugean, Jul 27, 2009.

  1. ugean

    ugean Private First Class

    Please Help!!! I have been trying to get rid of this virus for about a week. I have run every scan I can find. I have both XP and Vista on my system. The virus only appears to be affecting my Google searches in XP. I am using Firefox. I have scanned the system in XP safe, Vista and from my laptop over the network which has vista. Every time I think I have killed it it pops up again. SuperAntispyware is the only thing that finds anything. It is also affecting my boot time. XP boot is 4+ minutes. Vista 1.5 minutes I have not been able to run the analyse.exe (hijackthis) every time I do it hangs up. Attached are all of my log files. I have also tried many of the fixes (if not all) from the threads I could find on your site. Please help...I have to go to work shortly but will do any and all fixes when I get back or in the am. Thank you in advance
     

    Attached Files:

  2. ugean

    ugean Private First Class

    Finally got hijackthis to run
     

    Attached Files:

  3. ugean

    ugean Private First Class

    Help Please!!! Anyone?
     
  4. ugean

    ugean Private First Class

    Was just able to get combofix to run. Ran on Vista first then on XP. Both on the same computer. I think I am getting closer but I still get redirected when using google. Please Help
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you read the sticky threads???? See this: Don't Bump! It Only Hurts You!!!

    You need to run ALL steps from the below cleaning procedure and attach ALL the requested logs. Do not attach logs that we don't ask for. Also do not attempt to work on multiple boot partitions at the same time nor in the same thread. It will cause massive confusion.

    You must make sure you use the proper versions of programs too. Since you are way out of date with MBAM, I'm assuming you will be out of date with others too.



    Please follow the instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.
    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First. If TDSSserv is not found, just continue on with the READ & RUN ME.
    READ & RUN ME FIRST. Malware Removal Guide
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  6. ugean

    ugean Private First Class

    I have run everything in the run & read me. I think I may have finally gotten rid of it but I have thought that before and it has just come back. I am sorry just thought I would attach what I had to help. What should I do next?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you did not finish since you did not attach the 5 logs.


    Attach the 5 logs requested in the procedure. The below is a direct quote:
     
  8. ugean

    ugean Private First Class

    My superantispyware does not offer to save a log file. It says not to run RootRepeal on a 64 bit system which is what I have. Here are the log files that I have. Is there an option somewhere that I am missing in superantispyware to turn on log files? Thank you

    Edit: the other log files are already attached so it will not allow me to reattach them.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It always saves a log automatically. The instructions in the READ & RUN ME tell you how to see the logs. All of your logs from SAS are in the below folder:

    C:\Documents and Settings\Stephen\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs

    No you do not have a 64 bit system. Your logs show you have a 32 bit system. In addition, if you had a 64 bit system, ComboFix would not have run.


    As stated in my previous message, you are way out of date with your copy of MBAM. You need to update to the current version and rescan just to be safe. Then attach a new log from it too.
     
    Last edited: Jul 31, 2009
  10. ugean

    ugean Private First Class

    Thank you, I thought the X2 processor was 64 bit. I know XP is only 32 bit (I'm not running XP64) but I did not want to cause damage to anything. I have attached the logs. Thank you for your patients.
     

    Attached Files:

  11. ugean

    ugean Private First Class

    here is the most up to date mbam.
    Thank you,
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Now download LSP - Fix

    Run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the 'c:\windows\temp\ntdll64.dll file (in the ā€œKeepā€ section) to select it.

    Then, Select the >> button to move 'c:\windows\temp\ntdll64.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.
    If it is already in the Remove section, just click Finish.

    Some items that I'm asking you to fix with HJT below may not be found anymore. That's okay. Just ignore anything not found and continue.

    Uninstall the below old versions of software:
    Java(TM) 6 Update 12

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,
    O1 - Hosts: 209.44.111.62 surety.microsoft.com
    O1 - Hosts: 209.44.111.62 aware-protect.com
    O1 - Hosts: 209.44.111.62 www.aware-protect.com
    O4 - HKUS\S-1-5-19\..\Run: [dinokepuma] Rundll32.exe "C:\WINDOWS\system32\fidetiga.dll",s (User '?')
    O4 - HKUS\S-1-5-18\..\Run: [] C:\WINDOWS\TEMP\w0uqtnq.exe (User '?')
    O4 - HKUS\.DEFAULT\..\Run: [] C:\WINDOWS\TEMP\w0uqtnq.exe (User 'Default user')
    O20 - AppInit_DLLs: avgrsstx.dll djmqas.dll jlwafm.dll nkcjij.dll C:\WINDOWS\system32\retegefu.dll C:\WINDOWS\system32\behipaya.dll C:\WINDOWS\system32\nijopido.dll C:\WINDOWS\system32\risoyaza.dll C:\WINDOWS\system32\lebenesa.dll c:\windows\system32\gubebusi.dll

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.



    Now download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Stephen\Local Settings\Temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )



    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  13. ugean

    ugean Private First Class

    Thank you so much for your help. I actually have not been redirected on Google for a couple of days now (before running your fixes). However my boot time is still well over 4 minutes. The first part of what you had me run (the LSP fix) did not have the 'c:\windows\temp\ntdll64.dll' file. There were four other files: mswsock.dd; winrnr.dll; nwprovau.dll; rsvpsp.dll therefore I did not complete that section.

    The files:
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,
    O1 - Hosts: 209.44.111.62 surety.microsoft.com
    O1 - Hosts: 209.44.111.62 aware-protect.com
    O1 - Hosts: 209.44.111.62 www.aware-protect.com
    O4 - HKUS\S-1-5-19\..\Run: [dinokepuma] Rundll32.exe "C:\WINDOWS\system32\fidetiga.dll",s (User '?')
    O4 - HKUS\S-1-5-18\..\Run: [] C:\WINDOWS\TEMP\w0uqtnq.exe (User '?')
    O4 - HKUS\.DEFAULT\..\Run: [] C:\WINDOWS\TEMP\w0uqtnq.exe (User 'Default user')
    O20 - AppInit_DLLs: avgrsstx.dll djmqas.dll jlwafm.dll nkcjij.dll C:\WINDOWS\system32\retegefu.dll C:\WINDOWS\system32\behipaya.dll C:\WINDOWS\system32\nijopido.dll C:\WINDOWS\system32\risoyaza.dll C:\WINDOWS\system32\lebenesa.dll c:\windows\system32\gubebusi.dll

    Did not show when I ran analyse.exe so I did not remove anything. (hopefully that means the system is clean)

    Everything else went smooth. Attached are the logs that you requested.

    I cannot thank you enough for your help. Please let me know if I am good to go.
     
  14. ugean

    ugean Private First Class

    For some reason the files did not attach with my last post
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    You need to put your PC into normal startup mode with MSconfig as requested in step 1 of the READ & RUN ME. Please read that step again. You must not use MSconfig like this. I cannot continue until you correct this.

    Click Start, Run, and enter services.msc and click OK. This will bringup the Services form. Scroll down to exactly the below service name:

    Windows Management Instrumentation

    and double click on it. Make sure the Service status: shows as Started. Also make sure the Startup type: shows as Automatic. Let me know what you find. I have a feeling this service may not be running since the sysinfo.txt log in the MGlogs.zip file shows Can't Collect Information.


    Also please tell me how much memory your PC has.


    Did you use to have Windows installed on drive D? I'm wondering why the below show up:

    O23 - Service: NetMeeting Remote Desktop Sharing (mnmsrvc) - Unknown owner - D:\WINDOWS\system32\mnmsrvc.exe (file missing)
    O23 - Service: Remote Desktop Help Session Manager (RDSessMgr) - Unknown owner - D:\WINDOWS\system32\sessmgr.exe (file missing)
     
  16. ugean

    ugean Private First Class

    Ok, I changed msconfig back to normal. I did originally have it set to that when I started to clean out the system. I changed it back later to try and speed up my boot time. There are a lot of things that start up on normal boot up that drastically increase my boot up time. Right now it takes over ten minutes(with msconfig set to normal). Mainly this is due to the fact that I run one ATI and one GeForce graphics card and the controls for them conflict. I have to disable both control programs and just let windows run the drivers manually. The Service status: shows as Stopped but the Startup type: shows as Automatic. My system has 8GB of memory but XP only runs 3.25. When I boot to Vista I get use of all 8 GB. I did not have Windows loaded on the drive that is now D:\ However at one point in time the Drive that is now C:\ was D:\ and running windows XP. Currently I run XP on C:\ and vista on F:\ The C:\ is on its manyith computer.

    I have not been redirected from google in quite a while but am still struggling with long boot times for XP. This is extremely annoying as I do not like to leave my power hungry computer running when I am sleeping or at work and I do sometimes reboot from OS to OS. Eventually I will upgrade the rest of my hardware to Vista capable and get rid of XP. My boot time for XP was 2 minutes before I caught that virus. I don't know if it changed a setting somewhere in windows or if I am still just infected.

    Does any of this help?
    Thank you
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    MSconfig should not be used for this purpose as stated in step 1 of the READ & RUN ME.

    Not sure why you are doing this but this is not a topic for the Malware Forum anyway.

    As I stated, the Service status needs to be started. You need to start this service now. If you have been disabling services on your PC, I would advise against this as it will lead to problems. The below two services are also potential problems since they are point to the D drive rather than the C drive.

    NetMeeting Remote Desktop Sharing (mnmsrvc) - D:\WINDOWS\system32\mnmsrvc.exe (file missing)
    Remote Desktop Help Session Manager (RDSessMgr) - D:\WINDOWS\system32\sessmgr.exe (file missing)


    You need to locate these services in the list and fix them to point to the correct path on the C drive.

    Which possibly explains the reason for the above services pointing to the wrong place and could be reasons for other problems on your PC including slowness.


    May not be due to malware. It may be due to your installation (software & hardware) and also what you are running.

    After starting the Windows Management Instrumentation service and fixing the path for the other services, do the below.


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\MGlogs.zip
     
  18. ugean

    ugean Private First Class

    Ok, since we last were in contact I have installed UltraMon and gone through the startup list for msconfig in normal mode and unchecked some programs that I know do not need to run on startup. I was also messing around with wome web page design programs and features to windows. I am trying to learn how to create an intranet. My boot time seems to be back to normal at under 3 minutes. However I was redirected with the same green globe logo in the address bar while searching for how to do the fixes you told me to do.

    When I start the WMI service you told me to I get the following message:

    "the windows management instrumentation service on local computer started and then stopped. Some services stop automatically if they have no work to do, for example, the performance logs and alerts service."

    I don't know what to do from there. In regards to:

    NetMeeting Remote Desktop Sharing (mnmsrvc) - D:\WINDOWS\system32\mnmsrvc.exe (file missing)
    Remote Desktop Help Session Manager (RDSessMgr) - D:\WINDOWS\system32\sessmgr.exe (file missing)

    the last time windows was on the D:\ was about 3-4 years ago. I don't know how to fix this. I tried running the files but they run under processes in the task manager for a few seconds (do not display anything) and then close. Can I somehow just delete the references that are calling for them? Is there a way to test that the programs are actually working?

    Also I have noticed 6 svchost.exe files running in the processes recently where as before I only remember 1 or 2. I googled it and have a vague understanding of what it is and that it may be normal, but I just thought to mention it.

    Attached are the logs. Thank you again!
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should not be doing this. In the very first section of the READ & RUN ME under the Read These Important Notes it stated the below in the last bullet list item

    You also should not be doing this. Step 4 of the READ & RUN ME stated the below
    I cannot continue with you now that you are using MSconfig.
    You may need to post in the Software Forum for this as this can be a problem getting started again and it is not a malware issue.

    Also not really an issue for this forum. Somewhere along the lines with the changes you have made to this system, you have messedup the services for your Windows OS. There may even be other services I cannot see from the logs that are having issues and that could also be the cause for the WMI service not staying running.

    You should check your services list to see if there are NetMeeting Remote Desktop Sharing and Remote Desktop Help Session Manager services that are listed and showing a Path to executable located in C:\Windows\system32 for the same file names shown above. However these will not be running. They should be Manual and Stopped.

    Quite normally. You will never have only 1 or 2 running in a normal boot up session.

    You need to
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds