Link to home
Start Free TrialLog in
Avatar of Daniele Brunengo
Daniele BrunengoFlag for Italy

asked on

Incredibly nasty malware/adware

Hello, so this customer of mine has a malware opening the usual ad pages while he browses.
This is stuff I tackle daily and I've never had this much trouble.

He is still on XP, so that's a definite minus.

I've gone through all my usual steps: Adwcleaner run (nothing found), Malwarebytes run (just a couple of nothings).

Then I used Autorun to examine all his startup software, and found no anomalies.

The problem comes up with both Firefox and Chrome (tried resetting Chrome, reinstalling it clean to no avail).

I ran Farbar Recovery Scan Tool, I'll attach the files but I don't see anything strange. Not an expert of this software though.

His AV is Nod32, by the way, which is a very good AV but finds nothing in the system.

Do you have any suggestions? Thanks guys.
Addition.txt
FRST.txt
SOLUTION
Avatar of John
John
Flag of Canada image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Daniele Brunengo

ASKER

Thanks, I'll try that as soon as I have access once again to the pc, this evening or tomorrow. Then I'll report back.
SOLUTION
Avatar of davorin
davorin
Flag of Slovenia image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
I've tried that but it varies quite a lot. The network settings are fine.

I had also considered the possibility of a router virus, but other pcs in the network aren't affected.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
I've seen a couple of D-Link routers get infected actually. Strange stuff. Usually ones with factory passwords. One infection changed the router dns with a malicious one.
I checked with Process Explorer, but there's not a single process out of place right now.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
I haven't tried a restore because my customer says it's been happening for quite a long time but can't tell me how long exactly.

Scott, it's an idea, I'll try that tomorrow.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
I'll check that out this evening (Italy) when I'll have access again to the computer.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
I chose my own solution because Combofix made the problem go away.