PDA

View Full Version : Need Help Removing Win.32Murlo.ff



Frank Wilson
2007-10-19, 18:09
Spybot detects and Identifies my computer is infected with:

Win.32Murlo.ff 2 entries

this trojan also loads other trogans including:

PWS.LDPinchIE 2 entries

Computer is running Win 2000 SP 4

I have run Spybot ver 5.1 detections dated 10-10-07


repeatedly with the computer restarted in

standard mode
safe mode
and on restart.

Spybot is unable to clean Win.32Murlo.ff in all modes
and advised to contact Spybot S and D for assistance.


F. Wilson

tashi
2007-10-19, 18:22
Hello.

Can you give us an update as to the health of the machine after you started a topic here: http://forums.spybot.info/showthread.php?p=121053#post121053 as a log was not posted.

Thanks.

Frank Wilson
2007-10-19, 22:28
Here is the update.

First, yes it is the same machine. After the first post I updated Spybot to version 1.5 and updated definitions. I ran Spybot repeatedly with the computer in Normal Mode, on Startup, and in Safe Mode. At least 5 times in each mode. I was able to get rid of all Malware detected by Spybot except Win.32Murlo.ff (2 entries) by running Spybot with the computer started in the Safe Mode. Win.32Murlo.ff appears to rather rapidly load additional trojans such as PWS.LDPinchIE if the computer is run in the normal mode. Internet Explorer appears to be hijacked as it will no longer run for internet access, although Instant Messenger runs(I am sending this from another computer). I can access the computer to load files through the network it is connected to (a home network with 2 computers on it)

It has become very difficult to start Spybot S&D as I must attempt to launch it multiple times, 5 to 10 times, before it launches. I believe this is the result of a trojan.

The primary problem left appears to be Win.32Murlo.ff 2 entries as reported by Spybot S&D

The computer is running Win 2000 SP4

F. Wilson

tashi
2007-10-20, 08:41
Hello.

I suggest you follow through and post the HJT log in the malware forum, as discussed before, so that someone can take a look at the system. :)

Best regards.

Frank Wilson
2007-10-20, 22:38
Will download HJK program and post in malware form

F. Wilson