home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Join TechIMO for Free!
Register Blogs FAQ Members List Calendar Search Today's Posts Mark Forums Read
Reply Get bargains at  »  Dealighted.com
 
Thread Tools
Currently Active Users: 1858
Discussions: 188,470, Posts: 2,244,177, Members: 232,725
Old November 12th, 2004, 04:02 AM   Digg it!   #1 (permalink)
Ultimate Member
 
Join Date: Oct 2001
Location: Seattle, WA
Posts: 1,172
I got infected with startpag.hi, how do I clean it?

Ran the usual online free virus scanners today and saw a surprise, I have been infected with trojan.startpag.hi. Two scanners both found the same file (C:\windows\system32\mtwirl.dll) but neither could clean it.

Does anybody know how to clean this trojan? I ran both Ad-aware and Spybot and neither I think detects/cleans trojans either.

I hope this is why my computer has seemed to be running slowly the past couple of days...

Ruahrc

Ruahrc is offline   Reply With Quote
Old November 12th, 2004, 05:36 PM     #2 (permalink)
Member
 
Join Date: Jun 2003
Location: Maine
Posts: 168
Have you tried McAfee's stinger?

http://vil.nai.com/vil/stinger/

That may find it.

Also, try downloading Hijack this (becareful running it though). That may let you kill the file for cleaning.

Elburn is offline   Reply With Quote
Old November 14th, 2004, 08:06 PM     #3 (permalink)
Ultimate Member
 
Join Date: Oct 2001
Location: Seattle, WA
Posts: 1,172
I ran stinger, it didn't find anything (the list on the download page did not include startpage.hi as a detectable item, but at least none of the other viruses were on my system either)

Anyhow I tried to unregister the dll with regsvr32.exe and it failed, said it could not find the unmount point for the dll? so I just erased the file (my friends' PC's did not have that dll, so i figured it was a bogus dll not critical to windows) and now the virus scanners come up clean but my system is still running slow.

I will try that new AVG7.0 listed above, but do you guys think it is something else or is it the trojan still in my system?

I can remember the exact moment things began to act funny/slow, if that helps. I downloaded some airplane sounds for MS Flight Sim 2004 and was trying them on an airplane. When I loaded the airplane everything was really slow, even after I erased the sounds and reverted back to the original sounds. Do you think the download was infected? It only consisted of wav's and txt files, so I don't think there was malicious code in it, also I got it from a pretty reputable site (www.avsim.com) which I think scans for viruses/trojans before they upload files onto their webpage. At any rate even it were infected I think they would have posted news about it at the site too?

Any other suggestions?

Ruahrc

Ruahrc is offline   Reply With Quote
Old November 14th, 2004, 08:20 PM     #4 (permalink)
Member
 
Join Date: Jun 2003
Location: Maine
Posts: 168
Hmm, when you bring up the task manager, is there anything that is running that is using a large amount of memory? That is, suspicous applications?

Don't forget about Hijack this, that will tell what processes are currently running on your computer.
Elburn is offline   Reply With Quote
Old November 14th, 2004, 08:30 PM     #5 (permalink)
Ultimate Member
 
Join Date: Oct 2001
Location: Seattle, WA
Posts: 1,172
That is the thing, I don't really notice any suspicious processes running on my computer, I do however notice this happening sometimes (look at the attached jpg) notice how the cpu usage reported in the bottom is greater than what the individual processes report? I was transferring some files at the time from another computer but normally (i.e. before this wierd behavior happened) this type of stuff wouldn't happen (the cpu usage).

Also during times of system load my mouse gets "choppy" and "jerky" like the computer can't draw it fast enough. Again this has never happened before.

I'm running AVG7.0 scan now I will see if it picks anything up.

Also I am not very familiar with hijackthis.exe, would it help you if I posted the hijackthis log maybe you can make some sense out of it? The first time I ran it it found some browser holes I was suspicious of so I removed them but the behavior is still the same.

Ruahrc
Attached Thumbnails
i-got-infected-startpag-hi-how-do-i-clean-cpu.jpg  
Ruahrc is offline   Reply With Quote
Old November 14th, 2004, 08:34 PM     #6 (permalink)
Ultimate Member
 
mazdarx7-64's Avatar
 
Join Date: Aug 2004
Location: Knoxville, TN
Posts: 2,044
That pic is weird. I'd suggest antivir you can download it from www.download.com It gets most of the hard to kill viruses off the PCs that I work on.
__________________
BSOD.........
The reason why I'll be drunk tonight.
Are you a winner?
mazdarx7-64 is offline   Reply With Quote
Old November 14th, 2004, 08:39 PM     #7 (permalink)
Senior Member
 
TechKnickle's Avatar
 
Join Date: Aug 2004
Location: LA, California
Posts: 808
Send a message via AIM to TechKnickle Send a message via MSN to TechKnickle
Every infection of startpage is a total pain-in-the-butt to get rid of. Your best bet if you cannot format and reload is to just stuff the file somewhere and make sure it hasnt been executed. As long as your IE homepage settings have not been tampered with, the trojan has most likely not been executed.

Try to quarantine the file, because it is really, really hard to delete. I have only had about 3 successes in deleting that .exe file, and i had to use a command prompt via DOS to do it.
__________________
People are like coins, there's always two sides.
TechKnickle is offline   Reply With Quote
Old November 14th, 2004, 08:57 PM     #8 (permalink)
Member
 
yeadon563's Avatar
 
Join Date: Jun 2002
Posts: 321
Send a message via MSN to yeadon563
Have tried A sqaured? It is a freeware malware scanner.

Yeadon563
yeadon563 is offline   Reply With Quote
Old November 15th, 2004, 04:42 AM     #9 (permalink)
Ultimate Member
 
Join Date: Oct 2001
Location: Seattle, WA
Posts: 1,172
making some progress here, i think. I installed and ran AVG7.0 and it says it did not find anything. I install and run Spyware Doctor 2.1 for windows and it comes up with a few things, including cws and slotchbar? also a few others.

Spyware doctor freeware cannot remove any of the trojans/problems, you must register it to do so. Is there a freeware program that will both detect and delete/repair these problems? I am trying out a^2 and also antivir to see if they will pick this up.

I do have a backup of my HD although it has gotten a little old (i do a complete image backup to a normally-disconnected spare HD in my computer every so often) so if possible I'd like to fix this installation and keep going on it, although a reformat may be on the calendar at some point (this installation is going on 3 years old now, but before this problem it has run perfectly)

I'm glad I do all my real stuff on my powerbook g4, the pc is just there for flight simulator

Ruahrc
Ruahrc is offline   Reply With Quote
Old November 15th, 2004, 03:35 PM     #10 (permalink)
Ultimate Member
 
Kuasimodem's Avatar
 
Join Date: Oct 2001
Location: Holmen, Wisconsin US
Posts: 2,852
Send a message via MSN to Kuasimodem Send a message via Yahoo to Kuasimodem
SpySubtract has a fully functional 30 day trial, it's $30 a year after that.
__________________
What did a tornado sound like before freight trains were invented?
Kuasimodem is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may post new threads
You may post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
PC Infected jamesy505 Security and Privacy Issues 1 June 28th, 2004 08:12 PM
Unable to delete file dabugs General Tech Discussion 5 September 15th, 2003 05:01 AM
PC will not go past windows 2000 splash screen T_Dogg21 Technical Support 12 August 15th, 2003 12:03 AM
HELP!!virus found on my system robin801 General Tech Discussion 31 October 14th, 2002 03:55 AM
Reg seeker.c jutah General Tech Discussion 6 March 21st, 2002 07:21 PM

Most Active Discussions
Is It Just Me? (3000)
"mastermind" of London at.. (65)
Intel Pentium 4 531 (7)
Please don't divorce us (40)
AMD Phenom II X4 940 Black Edition (11)
nVidia GTX 295 now available (21)
Replacing integrated video card (5)
Folderchat Weekday thread (458)
building a gaming computer, input p.. (14)
Recent Discussions
can't add picture to this forum (1)
NTVDM CPU has encountered an il.. (8)
canon eos20d problem (1)
I cant sign into msn messenger,.. (8)
nVidia GTX 295 now available (21)
Folderchat Weekday thread (458)
Could I run this set-up (15)
Bought the Visiontek Radeon 387.. (1)
CPU Overheating ?? (18)
Blackberry Storm, Gears of War .. (2)
Core 2 Quad Q9550 system (3)
COWBOOM Ripoff! Used Laptop w/$.. (4)


All times are GMT -4. The time now is 07:04 AM.
TechIMO Copyright 2008 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28