HELP a soldier in need...

Discussion in 'Malware Help (A Specialist Will Reply)' started by xratedsoldier, Jun 24, 2006.

  1. xratedsoldier

    xratedsoldier Private E-2

    Hey guys/gals,

    i need some major help. no pun intended. I am in Iraq and I have been working on this issue for about a week now. I some malware on my computer and i thought that i had gotten rid of it...boy was I wrong. I had the thing where it told me i had a virus on my computer and then took me to their site so i would buy their crap. Had a buddy of mine that had it and i got rid of it for him. no problems. so i did about the same thing for mine but now it just keeps getting worse. I started getting URLsearch windows poping up. I got tired of that so I bought Ad-aware professional. that found alot of stuff but wouldn't get rid of it. So I got system mechanics, it found like 7-8 trojans! So i "deleted" them. then I started getting the BSOD. right now I am running in safe mode. I am going to add my hijack this log and what the windows thing says, well what i got from the dump thing. oh and my system32 always opens at startup now too. Thanks for any help.

    MINIDUMP:

    0x00000002

    0x80070003

    Symantec NetDetect.job

    Viruses something found:


    C:\windows\system32\wintfj32.dll
    winlogon.exe\wintfj32.dll

    Edit: Removed HJT log as it was from safe mode/msconfig
     
    Last edited by a moderator: Jun 24, 2006
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Do please follow our standard cleaning procedures which are necessary for us to provide you support, these steps help eliminate many of malware compontents that could be infectation your PC before running Hijackthis, Hijackthis is good at removing the reminents left over, but misses many in which the other steps will catch. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis


    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
    • Bitdefender
    • Panda Scan
    • HijackThis


    Edit: Very curious as to if your in Iraq, your IP points to Nevada USA??
     
    Last edited: Jun 24, 2006
  3. xratedsoldier

    xratedsoldier Private E-2

    all righty then...i have run the programs you have asked me to run. i am getting this browser hijack, it's ie.redirect...aol/hp something like that. but it takes me to a aol/hp wesite. I don't know...i am confused. i ran hijackthis and deleted a bunch of stuff from my registry(i made sure that they could be deleted and were bad first) and i keep getting the BSOD when i run windows in normal mode. i can't really find anything else wrong. maybe you can. i will send you the hijackthis log and my minidump (the whole thing) i have the full dump too but it's to big to attach. Let me know what else you need.


    About being in Iraq, we are using sattelite internet of some sort, i think it might be from a military sattelite thats sitting outside. i wasn't here when they set it all up. there are about five other sattelite receivers on top of our building so hell it could be one of those. I don't know...how can you tell my proximity from my IP? Just curious. Again, thanks for the help guys.

    SPC(e-4) ramey
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to attach the logs from Bitdefender and PandaActiveScan. Also we really need HijackThis logs from normal boot mode as indicated in the READ ME. Are you saying you cannot run in normal boot mode at all. Try using a different user account.

    Your current HJT log shows no malware.

    Did you delete the file you mentioned earlier: C:\windows\system32\wintfj32.dll
     
  5. xratedsoldier

    xratedsoldier Private E-2

    I can't find the panda log, but i will attach the bdo. I couldn't find C:\windows\system32\wintfj32.dll anywhere. I will try and start my computer normally, hopefully I'll have enough time. It worked fine last night for about three hours, no problems at all, then it just crashed and burned.:mad:
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have to save the Panda log per the instructions when you ran the scan. But I doubt it is going to show anything useful. Your Bitdefender log shows nothing just like your HJT log.

    I expect that what ever you removed (did you keep track of what you removed? Did you save backups?) is what caused your problems. Perhaps you removed some necessary files for your OS. At anyrate there is no malware present based on your logs.
     
  7. xratedsoldier

    xratedsoldier Private E-2

    here is the hjt log. i didn't save the backup i deleted it just a few minutes ago(doh!). i am going to send my adaware thing it show the registry values being changed and hjt shows the page being redirected.
     

    Attached Files:

  8. xratedsoldier

    xratedsoldier Private E-2

    i really need some help here. i have been working on this damn thing for 6 hours today and all day yesterday. I just can't figure this out. i searched the forums and found a place that describes the BSOD but i get a different error just about every time. I go to the web site that someone had suggested and i have two of the issues people have posted (logitec mouse, ATI video card) the problem with installing the drivers is that i can't do it in safe mode. i can't run windows normally long enough to down loead the needed drivers(to supposedly fix the problem) I could really use some help. tell me what you need and I will get it.

    Known Problems:
    IE redirect(on last post)

    BSOD (0x0000007e(0xc0000005,0xa73818d4,0xf7a73bf0,0xf7a738ec))

    DRIVER_IRQL_NOT_LESS_OR_EQUAL
    BSOD (0x000000d1(0x00000011,0x00000002,0x00000000,0x86f7aa68))
     
  9. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Do you have your XP CD and any other HP driver CDs with you?

    Also as you have a laptop, the drivers or any driver you have installed for the ATi graphics were they specifically from HP, because you will most likely get that BSOD IRQL error from a bad/wrong or corrupt driver, if they were the general Ati drivers as laptops need specific drivers.

    Check if its like my Compaq/HP laptop for is location as its a store for drivers from HP you have installed in the past C:\SwSetup it may have an Ati driver setup file their you can install.

    As to the logitec mouse I guess your using a normal mouse over using the touchpad?

    Can friend or collegue help in downloading any needed drivers and pop them on CD or USB to allow you to re-install the drivers?

    BTW which model HP is it.. just so I can look at any info that could be relevent and locate the drivers.


    I do have a few other ideas but without the XP or HP driver CDs they are risky and involve deleting the Devices from Device Manager and hope that XP on reboot picks up some basic drivers, thus allowing you to re-install the correct full drivers as Microsoft drivers are very basic.. but this is last resort.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are no malware issues in these logs. If you don't want those start pages then disable Ad-Watch and change your start pages to whatever you like. Then re-enable Ad-Watch and if it shows any popups about changes to the start pages, just approve/allow the change!

    You need to look into what Halo is saying. You do not have malware problems. You have problems with your Windows OS or driver related issues.
     
  11. xratedsoldier

    xratedsoldier Private E-2

    Hey thanks for your help guys I figured it out finally. I did everything all at once so i don't know exactly what it was. it wasn't malware though. I found the drivers for the mouse and the ati video card driver was up to date. I searched the bsod code on microsoft and after reading about 20 different things that it could be i found a hotfix that windows has decided to not let out until the next service pack. haha there a few of those. if someone else has this issue i would just go to microsoft web site and enter the first number in the code then read through everything that might apply to your computer and pick one see what happens. thanks for your help though guys. i really appreciate it. do you guys have a donation site or somehthing? Xratedsoldier
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. I'm happy to see you got it all worked out.

    Some of us have PayPal accounts where you can donate if desired but you would also have to have a PayPal account inorder to do this.
     
  13. xratedsoldier

    xratedsoldier Private E-2

    well hook me up then. can you tell me a little about the email worm brontok.q i haven'te been able to find anything on the net about it put it was passed to about three computers (see limited or no connectivity, in networking forum) through a buddy's thumb drive. kapersky found it and said that it had cleaned it. now anyone who ahd used the thumb drive, including myself, are haveing internet issues. within 30 mins. of being connected and doing a winsock fix i had sent 60,000 packets and recieved 1,500! oh well, back to banging my head on the wall...
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The closest link I had in my list of references right now is for Brontok.N . It is probably very similar. See the below:

    http://www.f-secure.com/v-descs/brontok_n.shtml

    Do you have Private Messages (PM) enabled? If not, enable it and send me (via PM) an email address where I can send you PayPal info.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds