This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help with WIN32.MURLO.ff.rtk

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Computer is a compaq, system is WinXP Pro, antivirus is AVG Free{} It's been a long time since I asked for help here (well not here, actually but at Net-Integration and TomCoyote) and I am pretty much at my wit's end. (actually used to help out some at net-integration and then tomcoyote when it first started - user name then was 'gracesaved') I need to start off with - at this moment I cannot post a HJT log. The computer I am cleaning is my daughter's and is sitting on my table not connected to the internet. I refuse to connect it to my router and I also refuse to burn anything from that computer to a disc and stick the disc in my computer. I spent all of yesterday (Saturday) running a cleanup on it and managed to get rid of coolweb search and a number of other issues with various cleaners as recommended by reading forums, and what I know myself from keeping my own computer clear of this stuff. All that's left is this "murlo" thing. Spybot S&D finds it but will not remove it - even when running on startup - in safe mode, or in normal mode. HiJack This will not even complete a scan - it stops responding when it hits the Services section, even in safe mode. So even if I wanted to post a log, I cannot get one completed. I have run the Smit cleaner recommended here, I have tried to remove the file with KillBox, I have tried to edit and remove the registry entry, all to no avail. I renamed the original Windows temp file where the file resides, but the registry entry just creates a new temp file with the file in it so due to my own stupidity I have two of these files now - neither of which can be killed. Also, when I first began this epic venture (yesterday) the registry editor was unaccessible - turned off, which I managed to get back on. I downloaded most of the programs I normally use (using my computer) and burned them to a disc to install on the infected computer (since it has no internet connection) along with a couple of new ones (Smitfraud and Killbox, and printed the instructions for running and fixing) Currently installed and used are: AVG Anti-virus Spybot Search & Destroy (downloaded yesterday from Safer Networking, along with new updates) A-Squared Free (downloaded yesterday) CWShredder HiJack This Smitfraud Fix Killbox I have just downloaded SD Fix but have not run that yet. The registry entry that will not let me edit it is: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\startdrv.exe The file is located in C:\Windows\Temp\startdrv.exe Can somebody please tell me how in the world to kill this file?
Hello and welcome to the forums

These should fit on a thumb drive / memory stick.

download & run this file
http://www.techsupportforum.com/sectools/s…Disinfector.exe

Next:

Download ComboFix from Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you, combofix.txt. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick while its running. That may cause it to stall
LD - thanks very much for the reply. I got very frustrated this morning (even though I know you have to wait your turn) - I don't own a thumb drive, sorry. I finally looked up the instructions for running SD Fix and ran that(before your reply), then rebooted the computer and ran HJT - no sign of the "startdrv.exe" file, but the tea-timer popped up with a couple of registry changes deleting the registery entry for that file (yay), I okayed that, ran SSD just to be sure - hmph - it found both the startdrv.exe file, as well as the created file it makes (forget the name but it's always the same and SSD always gets rid of it). This time, however, SSD was able to remove the startdrv.exe (probably because the registry entry was deleted?). I rebooted and ran all security scans (SSD, HJT, A squared and AVG) again with negative results. I have had the computer on and off all day rechecking and so far, there seems to be no recurring problem. The system is also running about 100% faster. Thanks to the forums available here I was able to find the information I needed. I wouldn't recommend that to people on the whole, but this computer would have had a format and reinstall anyway, so there wasn't much risk in trying. Thank you good people again!
Thanks - looks like there's a lot of people worse off than me though. One of the things I do remember how to do is read the HJT logs. Really appreciate having these forums. You guys are doing an amazing job here! (By the way - for your readers - all this carp** was downloaded because a babysitter downloaded a p2p program while my daughter was out - warn your folks to lock down the computers when they aren't home!)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI