Can't finish cleaning - all sorts of issues

Discussion in 'Malware Help (A Specialist Will Reply)' started by mycomputerhatesme, Jun 2, 2010.

  1. mycomputerhatesme

    mycomputerhatesme Private E-2

    My computer hates me.

    I was able to do almost everything in the READ & RUN until I got to the Combofix. I thought I had disabled any and all antivirus software and firewalls, but Combofix kept telling me that Trend Micro was still running. Problem is, I can't even open Trend or do anything with it. I can't even uninstall it at this point, neither in Add/Remove programs or through Trend itself. I always get a "debug" error message no matter what I try to do.



    So I've attached what I could:
    mbam log
    MG log
    RR log
    SAS log

    My problems started about 2 months ago. My computer was acting strange and so I opened IE to download any Windows updates and BAM! That's when the lovely fake Antivirus software attacked me. Pop ups galore, fake security messages, redirects, etc. I downloaded Microsoft Security Essentials immediately, since I was unable to run anything else due to the virus, and it seemed to pick it up and help a little bit. But nothing on my computer has been the same ever since.

    Along the way I've found remnants of Keyloggers, Key Stroke Spy and the like. Some of which I still cannot completely delete. I haven't been able to use IE at all. And just recently, up until I ran your XP Cleaning process, my computer was literally taking HOURS to even open anything, let alone get anything to actually run. And I have not been able to connect to the internet for 2 weeks, wireless or wired in.

    I'm at a loss here. I use the computer for my freelance graphic design work and to store photos of my 2 year old, none of which I've been able to access in weeks and it's KILLING ME!

    So thank you kindly in advance for any help!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please try to run the below to uninstall TrendMicro

    http://esupport.trendmicro.com/1/How-do-I-remove-old-or-new-versions-of-Trend-Micro-products-in-my-comp.aspx

    Now we also need to cleanup from having Symantec installed. Please run the below then reboot. After reboot run it one more time.

    Norton Removal Tool (SymNRT)

    Now also uninstall Microsoft Security Essentials ( at least for now until we cleanup your PC so that it does not get in the way ).


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
    O4 - HKLM\..\Run: [C:\Program Files\dfjdkjfdkjf99ldjf\dfjdk99jfldjf\winlogin.exe] "C:\Program Files\dfjdkjfdkjf99ldjf\dfjdk99jfldjf\windowsclock.exe" /R
    O4 - HKLM\..\Run: [AACKWin] C:\Program Files\ksysconfig\chrome.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Cheryl\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe (file missing)

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Cheryl\Local Settings\Temp

    Now run Ccleaner!

    Now goto this link Using MGtools and download the new version of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. mycomputerhatesme

    mycomputerhatesme Private E-2

    Still cannot uninstall Trend - Keep getting the same error message as before while trying to uninstall:
    Trend Micro Diagnostic Toolkit has encountered a problem and needs to
    close.
    Debug\Send Error Report\Don't Send
    And this is the error info:
    EventType : InPageError P1 : c000009c P2 : 00000003


    I was able to uninstall Microsoft Security Essentials and run through the other steps and I've attached the logs.

    So things are working now. Still getting weird debug errors for stuff I've never seen before. And still cannot connect to the internet. One such error is:
    HP Image Zone has encountered a problem and needs to close.
    I don't even know what that is.
     
  4. mycomputerhatesme

    mycomputerhatesme Private E-2

    Oops. Don't think my attachments went through.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like you did not allow MGtools to finish running as some logs did not get updated. However before getting a new log, please see if you can use the below to uninstall TrendMicro:

    Revo Uninstaller


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). Make sure that you let it finish running.

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. mycomputerhatesme

    mycomputerhatesme Private E-2

    Hmm. Trend is no longer showing up on my Add/Remove list, nor on the list for the tool you provided. BUT it's still all over my computer, in my Start Menu etc. etc.

    I went back to Trend's Toolkit window and tried to uninstall there, and a "Deleting" window popped up for the first time. I received several miscellaneous "Installation failed" errors in the process, but it finally asked me to reboot to finalize the changes (which I did, of course). So maybe it's finally gone now?

    * Two errors just popped up upon reboot, before my desktop even loaded: svchost and imapi.exe. And now everything seems to be running suuuuper slow again and my task bar is all out of whack.

    *It's been an hour now and I still have an hourglass pointer and cannot open/run anything. Rebooting again and hoping everything works this time.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the new log I requested.
     
  8. mycomputerhatesme

    mycomputerhatesme Private E-2

    3 hours now and I still cannot open MGtools yet. Everything is SO incredibly slow. It took 2 hours to even open the folder. Scrolling down on an open window is nearly impossible.

    We have all sorts of tornado warnings right now and I can see the storm rolling in. We almost always lose power during bad storms. This other laptop I have been communicating with you on must be plugged in to function so if you don't hear from me for a while longer, you'll know why. Be it the storm or my super slow computer. ;) I'll be back though - thank you SO much for everything thus far!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Disconnect your network cable to the internet and see if things speed up. Also if necessary ( just to get this next log ) try booting in safe mode with networking and running GetLogs.bat.

    Also in regards to any error messages, give us the exact word for word error messages.
     
  10. mycomputerhatesme

    mycomputerhatesme Private E-2

    Well i tried a dozen more times to run MGlogs last night and this morning with no such luck. Even in Safe Mode I kept on getting a "grep has encountered a problem and needs to close." message error that popped up non-stop.

    I'm also all of a sudden encountering the following errors upon rebooting :
    (this one is at boot up when I sign in before my desktop loads)
    svchost.exe
    The instruction at "0x7c917c20" referenced memory at "0x76be28b4". The required data was not placed into memory because of an I/O error status of "0xc000009c".

    (and this one comes as soon as my desktop finishes loading)
    imapi.exe
    The instructions at "0x01019bbc" referenced memory at "0x01019bbc." The required data was not placed into memory because of I/O error status of "0x000009c".

    So again, everything is incredibly slow since we uninstalled Security Essentials and since trying to get rid of Trend. Before that, right after the XP Cleaning Read&Run, everything seemed to be running much better than it has for me in the last 2 weeks.

    **I have not been able to connect to the internet for weeks now, wirelessly nor wired in, so I don't think that is what's slowing me down at this point. I'm not connected at all at this point, and am going back and forth on a different computer to communicate with you.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is starting to sound like you have a bunch of problems with your Windows installation. Please try to run a disk error check as described in the below link:

    http://support.microsoft.com/kb/315265


    Or if that cannot be done do to the way your system is running, you could also run the disk check from the Recovery Console with your Windows XP boot CD.
    • Boot from your Windows CD
    • Select the first R prompt, to log into the recovery console
    • Press 1 then Enter
      • Then type: chkdsk C: /f then press enter
      • Or type: chkdsk C: /R if it cannot find "F"
    After doing the above and whether it helps or not, continue on with the below to run System File Check:

    Click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System File Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it.


    Did running these help?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds