This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Startpage Problems

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here's the log: Warning! This utility will find legitimate files in addition to malware. Do not remove anything unless you are sure you know what you're doing. ——- System Files in System Directory ——- Volume in drive C has no label Volume Serial Number is 2A5F-12E5 Directory of C:\WINDOWS\SYSTEM 16,395.06 MB free ——- Hidden Files in System Directory ——- Volume in drive C has no label Volume Serial Number is 2A5F-12E5 Directory of C:\WINDOWS\SYSTEM LXAR9XDH GID 17,991 05-05-04 6:57p LxAR9xdh.GID CTDETECT GID 10,826 04-09-03 11:55p CTDETECT.GID RATINGS POL 8,192 02-21-03 10:39a RATINGS.POL FOLDER HTT 13,122 02-18-03 11:34a folder.htt DESKTOP INI 266 02-18-03 11:34a desktop.ini 5 file(s) 50,397 bytes 0 dir(s) 16,395.05 MB free —————- User Agent ———— REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] —————— Locate.com Results —————— No matches found. ———— Strings.exe Qoologic Results ———— C:\WINDOWS\VPTNFILE.502: TROJ_QOOLOGIC.G C:\WINDOWS\VPTNFILE.502: TROJ_QOOLOGIC.C C:\WINDOWS\VPTNFILE.502: TROJ_QOOLOGIC.B C:\WINDOWS\VPTNFILE.502: TROJ_QOOLOGIC.A C:\WINDOWS\lpt$vpn.502: TROJ_QOOLOGIC.G C:\WINDOWS\lpt$vpn.502: TROJ_QOOLOGIC.C C:\WINDOWS\lpt$vpn.502: TROJ_QOOLOGIC.B C:\WINDOWS\lpt$vpn.502: TROJ_QOOLOGIC.A C:\WINDOWS\SYSTEM\pav.sig: Qoologic C:\WINDOWS\SYSTEM\pav.sig: Qoologic ————– Strings.exe Aspack Results ————- C:\WINDOWS\vsapi32.dll: ASPACK EXE C:\WINDOWS\vsapi32.dll: ASPACK2 EXE C:\WINDOWS\vsapi32.dll: ASPack 1.08.04 C:\WINDOWS\vsapi32.dll: ASPack 1.08.03 C:\WINDOWS\vsapi32.dll: ASPack 1.08.02b C:\WINDOWS\vsapi32.dll: ASPack 1.08.01 C:\WINDOWS\vsapi32.dll: ASPack 1.08 C:\WINDOWS\vsapi32.dll: ASPack 1.07b C:\WINDOWS\vsapi32.dll: ASPack 1.61 C:\WINDOWS\vsapi32.dll: ASPack 1.05b C:\WINDOWS\vsapi32.dll: ASPack 1.03 C:\WINDOWS\vsapi32.dll: ASPack 1.02 C:\WINDOWS\vsapi32.dll: ASPack 1.01 C:\WINDOWS\vsapi32.dll: ASPack 1.00 C:\WINDOWS\SYSTEM\pav.sig: AsPack —————– HKLM Run Key —————— ————– Strings.exe Umonitor Results ————- 
To use it:
  • Download CCleaner from http://www.ccleaner.com/ and install.
  • Open CCleaner.
  • Place a check by everything in the Applications tab.
  • Place a check by Internet Explorer, Windows explorer, and System in the Windows tab.
  • Hit the button that says Run CCleaner
  • Reboot to remove index.dat files.
CCleaner also has some other useful features:

Cookies: In CCleaner, you can customize which cookies to delete and which to keep, so you won't lose valuble logon information. To do so, open CCleaner, then go to Options>Cookies. Select the name of a website you logon to often (For example, forums.tomcoyote.org). Then, click the '–>' button so it's in the 'Cookies to keep' list. Repeat this for any other cookie you wish to keep. To place a cookie back on the 'Cookies to Remove' list, simply select the cookie and hit the '<–' button.

Uninstall manager: It's a tool to let you uninstall programs, and rename and delete uninstall entries.

It also has a forum here: http://forum.ccleaner.com/

Check for updates weekly, as new versions are released periodically

CCleaner also has some other useful features:

Cookies: In CCleaner, you can customize which cookies to delete and which to keep, so you won't lose valuble logon information. To do so, open CCleaner, then go to Options>Cookies. Select the name of a website you logon to often (For example, forums.tomcoyote.org). Then, click the  '–>' button so it's in the 'Cookies to keep' list. Repeat this for any other cookie you wish to keep. To place a cookie back on the 'Cookies to Remove' list, simply select the cookie and hit the '<–' button.

143934



I have Webroot's Window Washer program, which has a Cookie Wizard which does something similar. Will doing this with CCleaner cause a conflict?
I probably should have run that before I hit the clean button, as it has now erased all of the cookies I'd previously saved. :wall:

It says it removed 46 MB of stuff, but I didn't see anything that said "StartPage" on it.
On reboot, the System Performance is at 64%, and those programs still aren't listed in the Add/Remove application in the control panel (although, I should be able to use the unistall manager in CCleaner instead, right?)

What's next? :)

and those programs still aren't listed in the Add/Remove application in the control panel

Are they really not there or is there a blank area. Be sure to look ALL they way down to the bottom.

I should be able to use the unistall manager in CCleaner instead, right?)
Yes, but 48 MB must have been more then just cookies.

I've also asked one of our Pro's to have a look when he has a chance.
Copy and past below, thick, lines in notepad


%systemdrive%
cd \
dir /s WUInst*.* > c:\log.txt
start log.txt


Save as this file as: find.bat on your desktop
Choose by "Save as type": all files

dubbelclick the file you just made




Past log.txt here.
Are they really not there or is there a blank area. Be sure to look ALL they way down to the bottom.

There is no blank area. It lists everything that I've installed in the last few days (MS Office, the Lexmark printer, and all of the Cleaning programs we've been putting in). There should be stuff listed there for MusicMatch, AOL, games, burner software, etc.

Now, there's a new problem. Programs are freezing in mid-load: MusicMatch played the intro sound, but got stuck before opening the program. AOL froze before the start up screen could complete. One of the things I installed today must be doing this, right? Maybe the AVG scan thing?
Just to let you know, when I got online and typed in the address to come to the forum, the page opened and closed very quickly. It only stayed open the second time I did it. This isn't the first time this has happened since I got infected by this thing. Okay, the result from the find.bat thing: Volume in drive C has no label Volume Serial Number is 2A5F-12E5 Directory of C:\ 16,559.67 MB free
Download StartDreck from HERE. Unzip to its own folder and start the program:

UnZip the startdreck.zip file first. DoubleClick: 'StartDreck.exe'
First click on the config button.
Now click the Unmark all button
Put a check by these boxes only:
*Registry->run keys
*Registry->Browser helper objects
*System/drivers> Running processes
hit >ok.

Now click the Save button to save that log. Go to the StartDreck folder and find the Startdreck.log file.

Copy and Paste the contents of that log back here and await further instructions.
Here's the log: StartDreck (build 2.1.7 public stable) - 2005-03-19 @ 16:29:35 (GMT -05:00) Platform: Windows 98 SE (Win 4.10.2222 A) Internet Explorer: 5.00.2614.3500 Logged in as David Maltman at V9B8M7 »Registry »Run Keys »Current User »Run »RunOnce »Default User »Run »RunOnce »Local Machine »Run *ScanRegistry=C:\WINDOWS\scanregw.exe /autorun *TaskMonitor=C:\WINDOWS\taskmon.exe *SystemTray=SysTray.Exe *LoadPowerProfile=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme *POINTER=point32.exe *LexmarkPrinTray=PrinTray.exe *Lwinst Run Profiler=C:\Program Files\Logitech\WingMan Profiler\Lwtest.exe /detect /quiet /launch "C:\Program Files\Logitech\WingMan Profiler\Lwpevntm.exe" *StillImageMonitor=C:\WINDOWS\SYSTEM\STIMON.EXE *Drag'n'Drop_Autolaunch="C:\Program Files\Iomega HotBurn\Autolaunch.exe" *MCUpdateExe=C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE *MCAgentExe=C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe *VSOCheckTask="C:\PROGRA~1\MCAFEE.COM\VSO\MCMNHDLR.EXE" /checktask *VirusScan Online="C:\PROGRA~1\MCAFEE.COM\VSO\mcvsshld.exe" *TkBellExe="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot *Lexmark X73 Button Monitor=C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe *Lexmark X73 Button Manager=C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe *LexStart=Lexstart.exe +OptionalComponents +IMAIL *Installed=1 +MAPI *NoChange=1 *Installed=1 +MAPI *NoChange=1 *Installed=1 »RunOnce »RunServices *LoadPowerProfile=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme *McVsRte=C:\PROGRA~1\MCAFEE.COM\VSO\mcvsrte.exe /embedding »RunServicesOnce **zpv=rundll32 C:\WINDOWS\CONFOG.TXT,DllGetClassObject »RunOnceEx »RunServicesOnceEx »Browser Helper Objects (LM) *AcroIEHelper.AcroIEHlprObj.1/{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} `InprocServer32=C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX *{53707962-6F74-2D53-2644-206D7942484F} `InprocServer32=C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL »Files »System/Drivers »Running Processes +FF0F2725=C:\WINDOWS\SYSTEM\KERNEL32.DLL +FFFF73B5=C:\WINDOWS\SYSTEM\MSGSRV32.EXE +FFFF6405=C:\WINDOWS\SYSTEM\MPREXE.EXE +FFFE1AAD=C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSRTE.EXE +FFFEE06D=C:\WINDOWS\RUNDLL32.EXE +FFFE2EF5=C:\WINDOWS\SYSTEM\mmtask.tsk +FFFE742D=C:\WINDOWS\EXPLORER.EXE +FFFDB9A9=C:\WINDOWS\TASKMON.EXE +FFFDB3ED=C:\WINDOWS\SYSTEM\SYSTRAY.EXE +FFFDC039=C:\PROGRAM FILES\MICROSOFT HARDWARE\MOUSE\POINT32.EXE +FFFD3CA9=C:\WINDOWS\SYSTEM\PRINTRAY.EXE +FFFC8455=C:\WINDOWS\SYSTEM\STIMON.EXE +FFFD7541=C:\WINDOWS\SYSTEM\SPOOL32.EXE +FFFCD371=C:\PROGRAM FILES\IOMEGA HOTBURN\AUTOLAUNCH.EXE +FFFC2835=C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE +FFFCF6F9=C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHLD.EXE +FFFCFCA1=C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE +FF038BC9=C:\PROGRAM FILES\LEXMARKX73\ACMONITOR_X73.EXE +FF038759=C:\PROGRAM FILES\LEXMARKX73\ACBTNMGR_X73.EXE +FF03D7A9=C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSESCN.EXE +FF03C205=C:\PROGRAM FILES\LOGITECH\WINGMAN PROFILER\LWPEVNTM.EXE +FF0376A9=C:\WINDOWS\SYSTEM\MSTASK.EXE +FF037D85=C:\PROGRAM FILES\EYETIDE MEDIA\EYETIDE VIEWER\EYETIDECONTROLLER.EXE +FF02DB21=C:\WINDOWS\SYSTEM\LEXBCES.EXE +FF025FD1=C:\WINDOWS\SYSTEM\RPCSS.EXE +FF013CCD=C:\WINDOWS\SYSTEM\WMIEXE.EXE +FF00FD45=C:\WINDOWS\SYSTEM\LEXPPS.EXE +FF02B12D=C:\PROGRAM FILES\AMERICA ONLINE 8.0\AOL.EXE +FF00B0F5=C:\PROGRAM FILES\AMERICA ONLINE 8.0\WAOL.EXE +FF06F01D=C:\WINDOWS\SYSTEM\DDHELP.EXE +FF065FE1=C:\PROGRAM FILES\AMERICA ONLINE 8.0\AOLWBSPD.EXE +FF0514A1=C:\WINDOWS\SYSTEM\TAPISRV.EXE +FF040B85=C:\WINDOWS\SYSTEM\RNAAPP.EXE +FF0B33B9=C:\WINDOWS\DESKTOP\NEWEST STUFF MARCH 7 2005\STARTDRECK\STARTDRECK.EXE »Application specific
This is the file that keeps loading the hijack: C:\WINDOWS\CONFOG.TXT We will have to boot to DOS to delete the file. Restart your computer Press the F8 key until the startup menu appears. Choose the Command Prompt only option then press Enter. From c:> cd\windows C:\windows> del CONFOG.TXT Reboot.
Okay, when I rebooted, I got this message: RUNDLL Error loading C:\WINDOWS\CONFOG.TXT The system cannot find the file specified. I assume this is a good thing? :) What do I do next? How do I know for sure that it's really gone?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI