Found one virus, can't figure out what else is wrong

Discussion in 'Malware Help (A Specialist Will Reply)' started by Em@luquette, Feb 8, 2010.

  1. Em@luquette

    Em@luquette Private E-2

    I just recently got hired at a small business & the computer I inherited had the Security Tool virus, which I have removed (using the instructions at www.im-infected.com/rogue/security-tool.html), but I cannot figure out what else is wrong with it. The user before me apparently clicked on popups & opened all email & attachments, so who knows what or when this all went pear-shaped. The three clues I have are: CPU running fairly constantly; Internet explorer reported as not being used (in Add/Remove Programs) since 1/17/10, although it has been used every workday until last Thursday (2/4); and the webpage www.VistaPrint.com (a legitimate website that the prior user needs to get marketing materials ordered) permanently blocked no matter what program (Explorer, Firefox, Chrome) I use.
    I'm also not entirely certain that MG Tools was able to run properly; it seemed to abort itself in less than 10 seconds.
    NOTE: The computer crashed during my first MBAM scan, so I did it 2x. I hope this is okay; I have attached both logs.
     
  2. Em@luquette

    Em@luquette Private E-2

    Part 2

    Attached are the remaining logs.
    Thank you!
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I need the logs from running:
    SAS
    MBAM
    ComboFix

    MGTools did not run. Are you sure you right clicked the exe and ran it as administrator? Did you get any error messages? I see your RootRepeal log is showing a D: drive. If this is your root drive, is that where you placed MGTools.exe?
     
  4. Em@luquette

    Em@luquette Private E-2

    My apologies; attached are the missing logs.

    I tried MGTools again; I do not get error messages, it just seems to abort itself. However, it created a new zip file, so perhaps it worked this time? I've attached that as well.

    The D drive is not the root drive; it is the C drive, which is where I placed MGTools.

    Thank you very much; sorry about the gaffs in my first post.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing much in your logs. The link worked fine for me. Does it not work in either IE or FF?

    This is a used business machine? There are accounting programs on it --> do you still use them?
    This system needs twice the amount of RAM it has. You should have a minimum of 1 gig.

    Let's just do this:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and then rename this file:
    C:\WINDOWS\system32\bd8480dn.dat --> to: C:\WINDOWS\system32\bd8480dn.dat.old

    Now uninstall your old Java:
    Java(TM) 6 Update 7
    J2SE Runtime Environment 5.0 Update 9

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds