The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    win32 startup trojan help !!!!!!!!!!!!

    Discussion in 'Security and Anti-Virus Software' started by jerryw618, Apr 10, 2010.

  1. jerryw618

    jerryw618 Newbie

    Reputations:
    0
    Messages:
    6
    Likes Received:
    0
    Trophy Points:
    5
    ok so several programs have detected win32startup trojan , but i cant get it cleaned out ? file mfplay.dll is locked or something i cant delete it? any ideas?
     
  2. flipfire

    flipfire Moderately Boss

    Reputations:
    6,156
    Messages:
    11,214
    Likes Received:
    68
    Trophy Points:
    466
    Which programs are you using?

    Its probably locked because its in use by the virus.

    Deleting a .dll can be risky. Confirm that its a virus first
     
  3. jerryw618

    jerryw618 Newbie

    Reputations:
    0
    Messages:
    6
    Likes Received:
    0
    Trophy Points:
    5
    well pest patrol confirmed it says it will delete it at reboot but warning keeps popping up , and file still there. i have pest patrol , avg antivirus, spybot search and destroy,easycleaner, programs
    but i cant gt rid of this pest
     
  4. MrDJ

    MrDJ Notebook Nobel Laureate

    Reputations:
    2,594
    Messages:
    10,832
    Likes Received:
    363
    Trophy Points:
    501
    is it the free avg your using. if so delete it and try another free antivirus like avast or microsoft security essentials as not all are the same and sometimes miss or give of a false positive.
     
  5. jerryw618

    jerryw618 Newbie

    Reputations:
    0
    Messages:
    6
    Likes Received:
    0
    Trophy Points:
    5
    hi no its a paid full version of avg. ive just downloaded several free av's avira eset and microsoft security ill try em all out till i get this cleaned any other suggestions ? searches for win32 startup all take you to sites that want you to buy their av stuff
     
  6. Baserk

    Baserk Notebook user

    Reputations:
    2,503
    Messages:
    1,794
    Likes Received:
    1
    Trophy Points:
    56
    Have you tried the free versions of Malwarebytes'Antimalware and HitmanPro?

    Can you upload the dll to VirusTotal or Jotti's Malware Scan to confirm it's not a false positive?
     
  7. jerryw618

    jerryw618 Newbie

    Reputations:
    0
    Messages:
    6
    Likes Received:
    0
    Trophy Points:
    5
    not yet will check them oyt though thanks , ill post results soon thanks
     
  8. MrDJ

    MrDJ Notebook Nobel Laureate

    Reputations:
    2,594
    Messages:
    10,832
    Likes Received:
    363
    Trophy Points:
    501
    dont forget to turn off your paid for avg before using any others as they will clash.

    also download Spybot Search & Destroy which is a great free bit of kit.
     
  9. jerryw618

    jerryw618 Newbie

    Reputations:
    0
    Messages:
    6
    Likes Received:
    0
    Trophy Points:
    5
    well i tried all this stuff posted and not one alerts too it just pest patrol ? so how do i deal with this do i just ignore it in pest patrol since nothing else sees it as a threat ???????
     
  10. gerryf19

    gerryf19 I am the walrus

    Reputations:
    2,275
    Messages:
    3,990
    Likes Received:
    0
    Trophy Points:
    105
    http://www.file.net/process/mfplay.dll.html

    according to that, mfplay.dll is part of a Browser Helper Object--the reason it cannot be deleted is that it loads with IE--and since IE is so tightly integrated into Windows, it essentially loads with Windows.

    It is likely part of a toolbar. You can probably uninstall it by removing all toolbars in add/remove control panel applet.
     
  11. MrDJ

    MrDJ Notebook Nobel Laureate

    Reputations:
    2,594
    Messages:
    10,832
    Likes Received:
    363
    Trophy Points:
    501
    if nothing else shows it up as a trojan then it could be a false positive and you dont really have a trojan at all.
     
  12. gerryf19

    gerryf19 I am the walrus

    Reputations:
    2,275
    Messages:
    3,990
    Likes Received:
    0
    Trophy Points:
    105
    That is not really the case...it depends on ones definition of "trojan"--simply a trojan is a program that purports to do one thing, but actually does another (perhaps in addition to its stated purpose).

    Pest patrol could be taking that definition at faqce value and a toolbar that enables you to search from the browser while also recording the search history can be construed as a trojan.

    Without looking at the machine, I cannot say what he has, but I will bet that it is third party browser helper object from a non-major corporation like the gamevance toolbar, or something.
     
  13. MrDJ

    MrDJ Notebook Nobel Laureate

    Reputations:
    2,594
    Messages:
    10,832
    Likes Received:
    363
    Trophy Points:
    501
    strange that its not showing up in any other antivirus software though.