 From:  Chris (CHRISSS)  
 To:  ALL

Trying to sort out my grandfather's computer which he said has been acting slowly on the internet recently. Thought it was all fine at first but something isn't right with it.


When clickig links in Google/Bing most of the time it takes you to a random website with some advertising or appears in the address bar then goes back to the search results. This is happening in IE and Chrome and it also has Firefox installed but that won't run at all.


So far I've run Spybot S&D and SuperAntiSpyware which found some stuff but hasn't fixed the problem.


Any ideas what else to look for or other software for removing crap?

 From:  Ken (SHIELDSIT)  
 To:  Chris (CHRISSS)     
38662.2 In reply to 38662.1 
Its still infected. I use malewarebytes usually. Sometimes its in the proxy settings that they mess with things. Id check there as well.
 From:  JonCooper  
 To:  Chris (CHRISSS)     
38662.3 In reply to 38662.1 
this guy seems to have fixed a similar problem ~

 From:  Chris (CHRISSS)  
 To:  Ken (SHIELDSIT)     
38662.4 In reply to 38662.2 
I'll try Malwarebytes and see what happens. That seems to be what John's link fixed a similar issue with too. Nothing in the proxy settings. It seemed ok yesterday when I was looking for Spybot and SAS but today it's not working well at all.

 From:  graphitone  
 To:  Chris (CHRISSS)     
38662.5 In reply to 38662.4 
Aye, I've used malwarebytes in the past and it's always served well, that combined with spybot and CCleaner makes for a fairly tidy system.

 From:  Chris (CHRISSS)  
 To:  ALL
Thanks all. Malwarebytes is scanning the computer at the moment so hopefully that will get things back to normal. If not I'll have a look at that malware removal guide.

 From:  graphitone  
 To:  Chris (CHRISSS)     
38662.7 In reply to 38662.6 
If you can find the .exe name of the process (providing it's not disguising itself as iexplorer or something equally inncocuous) then you could try googling that, there's loads of removal kits available for specific malware.

 From:  Chris (CHRISSS)  
 To:  graphitone     
38662.8 In reply to 38662.7 
Hmm. Malwarebytes didn't detect anything dodgy. I've looked in the task manager and not noticed anything out of the ordinary so there's ether something not running or hiding itself well. This could be fun to sort out :(

 From:  Ken (SHIELDSIT)  
 To:  Chris (CHRISSS)     
38662.9 In reply to 38662.8 
I haven't had much luck lately getting those things off, I usually just back up the data and reformat.
 From:  graphitone  
 To:  Chris (CHRISSS)     
38662.10 In reply to 38662.8 
Anything strange in the msconfig startup?

 From:  Chris (CHRISSS)  
 To:  graphitone     
38662.11 In reply to 38662.10 

A couple of things which I have disabled in the past, nothing new. I disabled all of the startup items yesterday just to be sure.


Running through a malware removal guide now and combofix.exe has found a .sys file patched with a rootkit. It's rebooting now so see if it helps.


I wish it was easier to switch between VGA and DVI on my monitor.

 From:  Ken (SHIELDSIT)  
 To:  Chris (CHRISSS)     
38662.12 In reply to 38662.11 
rootkits blow. Good luck!
 From:  Chris (CHRISSS)  
 To:  Ken (SHIELDSIT)     
38662.13 In reply to 38662.12 
Great things aren't they? This is the worst infection I've dealt with since my parents computer had XP Antivirus 2008 on it. I'm sure at some point I'll have to sort out Sian's grandfather's PC which is running sooooooooo slow for some reason. It's a Vista machine which used to work fine but literally takes about a minute to load IE and trying to browse websites is unbearably slow.

 From:  Chris (CHRISSS)  
 To:  ALL
I think Combofix has sorted the problem. It found a few rootkit infected files and now links in Google/Bing go straight to the correct website. Wonder how me managed to bugger it up so well.

 Reply   Quote More 

 From:  Ken (SHIELDSIT)  
 To:  Chris (CHRISSS)     
38662.15 In reply to 38662.14 
Good deal, glad you got it fixed!
 From:  Chris (CHRISSS)  
 To:  Ken (SHIELDSIT)     
38662.16 In reply to 38662.15 
Me too :D

 From:  Chris (CHRISSS)  
 To:  ALL



I just sorted out my grandfather's PC and now my dad just rang to say his computer isn't letting him do anything. I've just remote desktoped into it (surprised it let me change the settings to do that) and it has Win 7 Antispyware 2012 (it's from the future) blocking most things from running and being a total nuisance.


This is the second time I've had to sort out this for them now. The last one was XP Antispyware 2008 which did a very similar thing and was a total nightmare to sort out.



 From:  Drew (X3N0PH0N)  
 To:  Chris (CHRISSS)     
38662.18 In reply to 38662.17

(Seriously, for anyone who doesn't play games and uses their PC for web/email/office stuff, you really may as well. Firefox/Chrome, Thunderbird, Libre Office and you're away)

 From:  Chris (CHRISSS)  
 To:  Drew (X3N0PH0N)     
38662.19 In reply to 38662.18 
:D Good idea. There can't be much/anything that they do that wouldn't work with that.

 From:  Drew (X3N0PH0N)  
 To:  Chris (CHRISSS)     
38662.20 In reply to 38662.19 

(Or maybe Mint if you think a more windowsy interface would be better: )

