stupid trojan start page

Discussion in 'Malware Help (A Specialist Will Reply)' started by wayne45, Mar 31, 2006.

  1. wayne45

    wayne45 Private E-2

    I need help! I'm running windows XP and I keep getting trojan.startpage when I try to use IE. I have run CCleaner, Spybot and Ad-aware. Spybot detects the following: Network Essentials.search-exe, EffectiveBandToolbar. Spybot says it removes them.
    Ad-aware identifies the following:coolwebsearch. It also removed it.

    What do I do next?

    Thanks for your help.
    Wayne
     
  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Welcome to MajorGeeks.com, please follow the steps below:

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis

    When you return to make your next post make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
     
  3. wayne45

    wayne45 Private E-2

    Thanks for your help so far. I'm afraid I haven't gotten very far. I could run most of the tools with the exception of bitdefender and panda active scan. I do not have access to IE. I did run hijack this and will attach log. I ran ccleaner, spybot,ad-aware and microsoft windows defender. They detected and removed. What do I do from here?
     

    Attached Files:

  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    HijackThis is installed incorrectly. Install HijackThis to C:\Program Files\HJT as request in our Read Me.

    Uninstall MyWay Search Assistant.

    You are running an anti-spyware program which is not trusted or recognized to be safe, this link provides some details:- http://www.spywarewarrior.com/rogue_anti-spyware.htm

    Therefore it is recommended that you remove it using the Add/Remove option on your computer:

    Start-Control Panel-Add/Remove

    Look for the following program and remove it:

    Spyware Remover.

    Follow the directions for about:Blank and HSA Hijacker - Simplified Removal

    Now scan and have HJT Fix the following:
    Download
    - Pocket Killbox
    - ExplorerXP

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open ExplorerXP navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Post the about:Buster log and a fresh HijackThis log.
     
  5. wayne45

    wayne45 Private E-2

    Shadow dude,
    Looks like I'm back in business. Nice to have IE back. I ran all the stuff you told me to do. I'm also attaching a fresh hijack this log and buster log. I can't tell you what it a relief it is to have th computer back! Thanks again for all your help!!
     

    Attached Files:

  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Your HijackThis log shows no other signs of infection.

    The version of Java on your machine is out dated; update to the lateset version.

    Safe Surfing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds