Help - Search - Members - Calendar
Full Version: Joke-bluescreen And Hjt Won't Run
BleepingComputer.com > Security > Am I infected? What do I do?
   
JeffMig
I'm a new member, and this is my first post.

Wonder if anyone would have some quick advice about the next steps I should take. I got hit with I think joke-bluescreen.c a couple days ago and I have probably spent 12 hours trying to figure this out and educate myself. I ran Ad Aware and that seemed to get rid of some of the problems like the message in the middle of the screen telling me I was infected (how cute). But IE is definitely hijacked and now won't run (it seems to find the home page and then I get the box saying IE has encountered a problem and needs to close, etc.

I've tried downloading some programs on another computer and then installing them on the infected one but with mixed results. SuperAntiSpyware loaded but if I run a full scan I get the Blue screen of death (I think that is what it's called). If I run a custom scan it seems to work but doesn't seem to help.

I tried downloading both Mozilla and HJT but nether will install. When I click on the HJTInstall.exe file (794kb) it asks me if I want to run it, I click yes, the cursor turns to the hourglass for a blink and then dissapears. Quite frustrating. And from reading different forums it seems that getting a HJT log is a standard step (which I can't do) and there seems to be lots of other software options and not sure which to try next.

Any advice about how to approach this from here on out would be great. It's runnig windows XP.

Thanks,
JeffMig
Budapest
Hello JeffMig and welcome.gif to Bleeping Computer.

Here's something you can try.

Download Dr.Web CureIt! on another computer and run it on the problem computer in Safe Mode.

How to start Windows in Safe Mode
JeffMig
This seemed to have helped. The quick scan found NtRoorKit.127 trojan and deleted it. I then started a full scan which after about 0 minutes was 25% through and had found a number of other ones then got stuck on a large exe file that I didn't need, so I stopped it, deleted the file, and started the scan again. Before I restarted I tried HJT which ran and put out a log file (into a SAS file (statistical software) for some reason).

So I'll finish the scan with Dr.Web CureIt for now and see what happens. If you have other thoughts of next steps after this scan, it would be appreciated.

Thanks,
JeffMig
JeffMig
Note: the above reply was supposed to say 'after 90 minutes' not 0 minutes.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2008 Invision Power Services, Inc.