• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

Hijacked by monosearchDOTcom

Bob151

Senior member
My wife's local account (profile) on this PC got highjacked by some website called monosearchDOTcom (don't go there casually).

The most disturbing thing, McAfee AV (I know!), Spybot SD, nor Lavasoft's Ad-Watch, stopped this infection from occuring in the firstplace.

Nor does Spybot SD or Lavasoft's Ad-Aware recognize the hijack to remove it.

Launching IE loads popups, other useless crap.

No matter how many times I try to get tools like hijackthis (in safe mode) to remove the monosearchDOTcom from IE startup, it always comes back. She is NOT PC savy and she just can't handle all of this. Her account is a "User" account, not power users, not admin, she doesn't have rights to install stuff.

The other profiles on the PC, mine and my duaghter's, are not messed up. So, it doesn't appear to be a wide scale infection.

Google comes up with near nothing. This can't be that unknown, we've been infected here for at least two weeks.

Help?
 
Drastic thing would be to delete her account. Also have your tried MS Antispyware? Before you do this turn off System Restore and then run said scan in safe mode.
 
Run Hijack this then use the hijackthis.de website to see what you can remove. Also use Microsoft's Anti-Spyware if you're running 2k or XP. Try running the Trend Micro's House Call online scanner as well as Panda's Online scanner. If that doesn't work, try installing Avast and running that. Also remember to disable system restore so they don't come back.
 
monosearch.com



Administrator:
Name-- Registrant(187640)
EMail-: (info@fashionid.com)
tel --: +1.25255572
org: Registrant
P.O. Box No. 71826, KCPO
Hong Kong,Hong Kong,HK 852

Technical Contactor:
Name-- Registrant(187640)
EMail-: (info@fashionid.com)
tel --: +1.25255572
org: Registrant
P.O. Box No. 71826, KCPO
Hong Kong,Hong Kong,HK 852
 
Thanks for your ideas. I'll try these in the next few days.

OK, I see two of you say to disable system restore. So, does that mean I should never enable it again?
 
you can enable it... once you have the problem fixed 🙂

the only thing is if you have sys restore enabled, the spyware / bad stuff will stay on those restore points and come back .

 
Back
Top