Gracey
Topic Starter
Computer is a compaq, system is WinXP Pro, antivirus is AVG Free{}
It's been a long time since I asked for help here (well not here, actually but at Net-Integration and TomCoyote) and I am pretty much at my wit's end. (actually used to help out some at net-integration and then tomcoyote when it first started - user name then was 'gracesaved')
I need to start off with - at this moment I cannot post a HJT log. The computer I am cleaning is my daughter's and is sitting on my table not connected to the internet. I refuse to connect it to my router and I also refuse to burn anything from that computer to a disc and stick the disc in my computer.
I spent all of yesterday (Saturday) running a cleanup on it and managed to get rid of coolweb search and a number of other issues with various cleaners as recommended by reading forums, and what I know myself from keeping my own computer clear of this stuff.
All that's left is this "murlo" thing.
Spybot S&D finds it but will not remove it - even when running on startup - in safe mode, or in normal mode.
HiJack This will not even complete a scan - it stops responding when it hits the Services section, even in safe mode. So even if I wanted to post a log, I cannot get one completed.
I have run the Smit cleaner recommended here, I have tried to remove the file with KillBox, I have tried to edit and remove the registry entry, all to no avail.
I renamed the original Windows temp file where the file resides, but the registry entry just creates a new temp file with the file in it so due to my own stupidity I have two of these files now - neither of which can be killed. Also, when I first began this epic venture (yesterday) the registry editor was unaccessible - turned off, which I managed to get back on.
I downloaded most of the programs I normally use (using my computer) and burned them to a disc to install on the infected computer (since it has no internet connection) along with a couple of new ones (Smitfraud and Killbox, and printed the instructions for running and fixing) Currently installed and used are:
AVG Anti-virus
Spybot Search & Destroy (downloaded yesterday from Safer Networking, along with new updates)
A-Squared Free (downloaded yesterday)
CWShredder
HiJack This
Smitfraud Fix
Killbox
I have just downloaded SD Fix but have not run that yet.
The registry entry that will not let me edit it is:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\startdrv.exe
The file is located in C:\Windows\Temp\startdrv.exe
Can somebody please tell me how in the world to kill this file?