Computing.Net > Forums > Security and Virus > Registry help with Trojan.startpage

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

Registry help with Trojan.startpage

Reply to Message Icon

Original Message
Name: Dave7
Date: February 3, 2005 at 14:56:43 Pacific
Subject: Registry help with Trojan.startpage
OS: 2000 Windows
CPU/Ram: P3
Comment:

Ok guys, I know how good you all are but I have one of the biggest bitch trojans I have ever had. I have spybot, adaware, cwShredder and Symantic antivirus based on searches here I tried. I cant get rid of this Trojan.startpage. I am still very hesitant to mess with my registry but I did a hijackthis log, can anyone help me decipher it? Please ask me to post it and I will.

I see about 4 lines in the with references to about.blank but not sure to do anything without getting a second opinion...please help guys.

Dave


Report Offensive Message For Removal


Response Number 1
Name: Dave7
Date: February 3, 2005 at 15:25:53 Pacific
Reply:

Well I got a followup for you, I found this page:

http://hijackthis.de/index.php

It is amazing and I loved it, I followed what it said and I think I am back in the clear baby. Trojan.StartPage can suck it! Thanks aeveryone for the posts so I could find that lil jewel site


Report Offensive Follow Up For Removal

Response Number 2
Name: daisymay
Date: February 3, 2005 at 15:28:39 Pacific
Reply:

Hi,
Out of interest this may have helped...

http://securityresponse.symantec.com/avcenter/venc/data/trojan.startpage.html

daisymay


Report Offensive Follow Up For Removal

Response Number 3
Name: Derek
Date: February 3, 2005 at 15:29:02 Pacific
Reply:

First search Google for a little program called LSPFIX. When you attempt to get shot of about:blank you risk losing your internet connection. LSPFIX will get you back online again if this happens.

Next download and run this:
ABOUT:BUSTER

In order to run About:Buster this you will need to have the following file and register it (unless you already have it on board):
MSCOMCTL.OCX INFO & DOWNLOAD

If you look where it says "alternatively" you will see that the file registering procedure is very simple. This will save a 5.66M program download.

No promises but the above looks like your best bet. Avoid advertised removers generally, they are often riddled with spyware.

Derek.W


Report Offensive Follow Up For Removal

Response Number 4
Name: Derek
Date: February 3, 2005 at 15:31:39 Pacific
Reply:

Thx for feedback (arrived while typing mine). Worth knowing, sounds simpler and nice to know it worked.

Derek.W


Report Offensive Follow Up For Removal

Response Number 5
Name: Derek
Date: February 3, 2005 at 15:54:11 Pacific
Reply:

As an afterthought, I see this seems to have been cured within about half an hour - very fast. This nasty can hide itself and come back again. If it does, try my #3.

It would be very useful to us if you keep us posted and let us know if your fix lasted.

Thanks

Derek.W


Report Offensive Follow Up For Removal


Response Number 6
Name: Dave7
Date: February 3, 2005 at 16:55:42 Pacific
Reply:

OH thansk fellas and your so right Derek, I didnt get it with that. I found the perfect fix and I got it off the net and this guy nailed it. it worked perfectly but you have to go into Safe mode and do it exactly as he says. Here it is:

Go here and download Adaware SE. Install the program then in the main window look in the bottom right corner and click on Check for updates now then click Connect and download the latest reference files. but don't run it.

Also click here to download CWSinstall.exe. CWSinstall.exe file and it will install CWShredder, but don't run it yet either.

Set your folder options to show hidden files like so:

Go to Start > Search and under "More advanced search options".
Make sure there is a check by "Search System Folders" and "Search hidden files and folders" and "Search system subfolders"

Next click on My Computer. Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files" and "Hide extensions for known file types" . Now click "Apply to all folders"
Click "Apply" then "OK"

Now copy these instructions to notepad and save them to a convenient location like your desktop. You will need them to refer to in safe mode.

Restart into Safe mode.

How to start your computer in safe mode

Do all of the following in safe mode:


Run Hijack This and put a check by all of the following entries then click the "Fix Checked" button.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\OWNERY~1.002\LOCALS~1\Temp\sp.dll/sp.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\OWNERY~1.002\LOCALS~1\Temp\sp.dll/sp.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

O2 - BHO: (no name) - {D90307F0-2074-4EC3-B86A-E9C5D9010546} - C:\WINDOWS\System32\odml.dll

O18 - Filter: text/html - {72AA6E26-38B0-4C14-A3BF-F5ECA502189A} - C:\WINDOWS\System32\odml.dll

O18 - Filter: text/plain - {72AA6E26-38B0-4C14-A3BF-F5ECA502189A} - C:\WINDOWS\System32\odml.dll

Find and delete this file:

C:\WINDOWS\System32\odml.dll

Also in safe mode navigate to the C:\WINNT\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

Go to Start > Run and type %temp% in the Run box. The Temp folder will open. Click Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

Finally go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.

Empty the Recycle Bin

Run CWShredder Click on the cwshredder.exe then click "Fix" (Not "Scan only") and let it do it's thing.

Next run Adaware according to these insrructions:

From main window :Click Start then under Select a scan Mode tick Perform full system scan.

Next deselect Search for negligible risk entries.

Now to scan just click the Next button.

When the scan is finished mark everything for removal and get rid of it.(Right-click the window and choose select all from the drop down menu and click Next)

Restart your computer.


Report Offensive Follow Up For Removal

Response Number 7
Name: Derek
Date: February 3, 2005 at 17:31:50 Pacific
Reply:

Fine - thanks for the info. A kinda variation on a theme but the variations might make all the difference. Keep us posted - we need to know about any fix that holds up for more than a few days (as do those Googling to this page in future).

Err...doesn't everyone always show all files and extensions LOL? It's MS logic to do otherwise. I think it's supposed to protect system files from newbies but they can still do plenty of damage deleting the ones they can see (watch these forums).

Derek.W


Report Offensive Follow Up For Removal

Response Number 8
Name: T_Rahul
Date: February 6, 2005 at 23:44:38 Pacific
Reply:

Thanks Dave7 , finally I got rid of this nasty trojan through the procedure suggested by you.

It was a pain.

Regards
Rahul.


Report Offensive Follow Up For Removal

Response Number 9
Name: helpme911
Date: February 21, 2005 at 22:19:51 Pacific
Reply:

I did the same as response number 6, however i finally relized that there could be some differences in the file names.

For Example: not odml.dll but (haee.dll)

O18 - Filter: text/html - {72AA6E26-38B0-4C14-A3BF-F5ECA502189A} - C:\WINDOWS\System32\odml.dll

O18 - Filter: text/plain - {72AA6E26-38B0-4C14-A3BF-F5ECA502189A} - C:\WINDOWS\System32\odml.dll

Find and delete this file:

C:\WINDOWS\System32\odml.dll

same with this one above. Delete c:\windows\system32\haee.dll

after I deleted haee.dll, I was fine. I followed the same steps as in response 6 but still had problems because of the difference in file names. This Virus was the hardest thing for me to remove.

Thanks to Response 6 for getting us started



Report Offensive Follow Up For Removal

Response Number 10
Name: Derek
Date: February 22, 2005 at 15:08:10 Pacific
Reply:

Thx all for valuable feedback.

Derek.W


Report Offensive Follow Up For Removal

Response Number 11
Name: mafarka
Date: February 23, 2005 at 11:00:21 Pacific
Reply:

I got the b*stard yesterday and Responses 6 & 9 definitely work.

I searched for *dll files modifed that day and found a emfk.dll in System32. Checked on the net to see if emfk.dll was an authentic .dll file, but found it doesn't exist.

I ran spybot, hijack this and spyware blaster, deleted and immunised then restarted in Safe Mode. Found the file and renamed it as an *.old file.

Restarted normally and hey presto no more trouble.



Report Offensive Follow Up For Removal

Response Number 12
Name: vyntage
Date: February 27, 2005 at 07:17:42 Pacific
Reply:

Hi

Jus wanna ask whether is it possible to remove trojan.startpage by jus using 'hijackthis'? Is it necessary to go thru the procedures shown in respond #6?


Report Offensive Follow Up For Removal

Response Number 13
Name: Derek
Date: February 27, 2005 at 09:43:48 Pacific
Reply:

Hi Sue

I assume you Googled into this thread. That way we don't know your operating system. Best bet is to start a new post.

You might be lucky with HijackThis but about:blank is renowned to be a difficult one to get off your machine.
Be careful with any "wonder fixes" advertised on the internet (they are often spyware themselves).

If you are on Windows XP I gather that Microsoft's new Anti-Spyware freebie can fix this one.

Otherwise, as 6 & 9 appear to have done the trick then they would be your best bet (unless anyone comes along on here who knows a quick fix that actually works).

Derek.W


Report Offensive Follow Up For Removal

Response Number 14
Name: Ladyme
Date: February 27, 2005 at 15:46:00 Pacific
Reply:

Hey guys, I've tried all the above and as soon as I close and reopen IE or reboot the Trogan start page is back again. I have a firewall, run Norton's antivirus, run SpySubtact. CWShredder,Adaware and they find the problems but as soon as I reboot it is back.


Report Offensive Follow Up For Removal

Response Number 15
Name: Derek
Date: February 27, 2005 at 16:04:20 Pacific
Reply:

Keep an eye on this later post too:

S&V Forum 15222

Derek.W


Report Offensive Follow Up For Removal






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home



Results for: Registry help with Trojan.startpage

Trojan.Startpage virus problem
    Summary: Ran NAV2003 and was able to remove all virus infected files except c:/windows/system32/ctrlpan.dll (it's infected with Trojan.Startpage). I can't delete it or quarantine it and the norton alert page k...
www.computing.net/answers/security/trojanstartpage-virus-problem/8785.html

Trojan.Startpage Problem
    Summary: Hi Everyone! Since few days, my NAV tells me that my computer is infected with Trojan.StartPage. I did what it is written on Symantec Security Response page but the Trojan.Startpage is still there. ...
www.computing.net/answers/security/trojanstartpage-problem/14733.html

Help with Trojan.AppActXComp Virus !
    Summary: I run Windows 2000 Pro and I recently updated to IE 6. I have three Trojan's (i got while on IE 5 *i think* - here follows the scan details if it will make sense to you ... "Scan Results Virus Scan De...
www.computing.net/answers/security/help-with-trojanappactxcomp-virus-/573.html








Which MP3 player do you have?

iPod/iPhone
Zune
Something Else
None


View Results

Poll Finishes Today.
Discuss in The Lounge
Poll History






Data Recovery Software