Trend Micro popup - malware gone?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by aiou99, Oct 21, 2008.

  1. aiou99

    aiou99 Private E-2

    It all started with my system crashing and me doing a system recovery. Then, before I could get my antivirus setup again I got some spyware and it took over the computer to where it couldn't run anything, so I did another system recovery. After that, everything was fine except there was a "delself" MS-DOS prompt icon on my desktop which I read can be not so great. So that led me to you. I followed the malware removal and the icon disappeared, but I'm still getting this Trend Micro popup everytime I turn on the computer. This has happened since the first system recovery and the spyware got on the computer. I don't remember if it was there before the other spyware stuff so I'm not sure if it is a legitimate popup (I feel it's not). I have never had Trend Micro products. Here is the popup and my logs are attached. Thanks for any help you can provide!
     

    Attached Files:

    Last edited by a moderator: Oct 21, 2008
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We still need the C:\MGLogs.zip.
     
  3. aiou99

    aiou99 Private E-2

    Here it is... I waited for the post to show up to reply again but I didn't see it for a while. The pop up below is the one I'm getting, I tried to insert it in the other post but I guess it didn't take. The address is http://img183.imageshack.us/img183/9859/popupve6.png if it doesn't work again. Also, I'm running Windows XP Media Center with Service Pack 3. Let me know if you need anything else. Thanks.





    EDIT: No not need to see the screen shot.
     

    Attached Files:

    Last edited by a moderator: Oct 21, 2008
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please tell me what this is:
    C:\Documents and Settings\HP_Administrator\Desktop\LZs6YjZl20081020042815.zip??
    If you don't know, delete it.

    Use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  5. aiou99

    aiou99 Private E-2

    Ok. I did avenger and GetLogs.bat and the logs are attached. FYI - when avenger rebooted the computer the Trend Micro popup came up again and there was an error message:
    [​IMG]
    Try Again and Continue didn't do anything. I had to push cancel several times for the window to go away.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean...though we have some items to finish up.

    First you never answered my question as to what this was:
    C:\Documents and Settings\HP_Administrator\Desktop\LZs6YjZl20081020042815.zip

    Next question is do you have an external hard drive?

    Other than the error what is happening?

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.
     
  7. aiou99

    aiou99 Private E-2

    The zip file is one of my files put on after the spyware. It's not anything bad. I do have an external drive hooked up. That error occurred when rebooting from avenger. The only problem the computer is having is the Trend Micro popup every time it restarts. Other than that, it's running fine. I just wanted to make sure that everything was clean since I don't know where that popup is coming from. I'll remove Windows Messenger. Thanks for the help. Is there anything else I should do because of my external hard drive? And which of these programs that have been downloaded in this entire process should I get rid of? Or should I just keep them all on the computer?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Was the external hard drive connected when you did the scans?

    Does the pop up happen you have it disconnected?

    Have you searched that drive for any traces of Trend Micro?

    We will deal with the other questions when we are sure your issues are taken care of.
     
  9. aiou99

    aiou99 Private E-2

    Yes, the external hard drive has been hooked up the whole time. I disconnected it and restarted the computer and the popup still happened. I just briefly looked in all of the folders and didn't see anything related to Trend Micro, although I'm assuming that since it did it without it that the external hard drive wouldn't cause it.... but I don't know.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do an actual search....as in start / search / all files and folders .......make sure you click on advanced and look in sub folders and system files.
     
  11. aiou99

    aiou99 Private E-2

    Ok. I did a search of the external drive a couple different ways for Trend Micro and nothing came up.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You already determined that it wasn't the external causing it so I really wanted you to search you C: drive.

    I can navigate to the page.......it is a legit page. The question remains as to why it is popping up. It looks like your internet explorer is what is opening, right?

    Please use Startup Manager and tell me what all is in that list.
     
  13. aiou99

    aiou99 Private E-2

    I ran a search of all hard drives and all that came up where the history files for the popups. Yes, internet explorer is the one opening the popup. Also, internet explorer isn't really used on my computer at all as it's not my default browser. Here are the startup items:

    ctfmon.exe - C:\WINDOWS\system32\cftmon.exe
    SUPERAntiSpyware
    ehTray - C:\WINDOWS\ehome\ehtray.exe
    HotKeysCmds - C:\WINDOWS\system32\hkcmd.exe
    Persistence - C:\WINDOWS\system32\jgfxpers.exe
    HPBootOp - C:\Program Files|Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
    RTHDCPL - RTHDCPL.EXE
    LSBWatcher - C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
    TkBellExe - C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    avast!
    QuickTime Task - QTTask.exe
    iTunesHelper.exe
    Adobe Gamma Loader.lnk
    Adobe Reader Speed Launch.lnk
    HP Digital Imaging Monitor.lnk
    Microsoft Office.lnk
    SpySubtract.lnk
    Updates from HP.lnk
     
  14. aiou99

    aiou99 Private E-2

    Ok. New problem. Windows did some automatic updates last night while I was sleep and restarted on it's own. I woke up to a message saying windows could not start because the following file is missing or corrupt: <Windows root>\system32\ntoskrnl.exe. Please re-install a copy of the above file. How do I fix this? Any idea what may have caused this?
     
  15. aiou99

    aiou99 Private E-2

    In reference to my last post. I was finally able to get the computer to restart with the last known good configuration (it took a while). avast! showed up with an application error for ashServ.exe - The instruction at 0x7e19dda refernced memory at 0x6608a058. The required data was not placed into memory because of an I/O error status of 0xc000009c. Ok to terminate. Cancel to debug.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This may indicate a failing hard drive. You can check by opening My computer / right click the c drive / properties / tools / error checking.....check both boxes...then allow for a restart.....watch the scan for any bad sectors.
     
  17. aiou99

    aiou99 Private E-2

    It's still doing the disc check...it's about 90% done and it's getting a little out of hand...so far it's listed 180+ file record segments as unreadable. That's bad, huh?

    EDIT - Now, it's just past 92% done with 250+ file record segments listed as unreadable.
     
    Last edited: Oct 24, 2008
  18. aiou99

    aiou99 Private E-2

    OK. It's over 300 with only 94% done. I had to stop keeping track of all of the file record segments. What does all of this mean?
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It means your hard drive is failing. :(
     
  20. aiou99

    aiou99 Private E-2

    I'm guessing it's beyond repair and I have to either get a new hard drive or a new computer. Which would you recommend? Is replacing the hard drive something I can do myself? Is this common for a computer that's only a little over 2 years old? I've never had a computer do this before. Sorry if it's gotten off topic a bit, but this is somewhat of an unknown territory for me as it's never happened.
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    A new hard drive is easy to put in....I suggest that you post in the software section regarding this issue and what may be the best solution for you. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds