Hijacked by monosearchDOTcom

Bob151

Senior member
Apr 13, 2000
857
0
0
My wife's local account (profile) on this PC got highjacked by some website called monosearchDOTcom (don't go there casually).

The most disturbing thing, McAfee AV (I know!), Spybot SD, nor Lavasoft's Ad-Watch, stopped this infection from occuring in the firstplace.

Nor does Spybot SD or Lavasoft's Ad-Aware recognize the hijack to remove it.

Launching IE loads popups, other useless crap.

No matter how many times I try to get tools like hijackthis (in safe mode) to remove the monosearchDOTcom from IE startup, it always comes back. She is NOT PC savy and she just can't handle all of this. Her account is a "User" account, not power users, not admin, she doesn't have rights to install stuff.

The other profiles on the PC, mine and my duaghter's, are not messed up. So, it doesn't appear to be a wide scale infection.

Google comes up with near nothing. This can't be that unknown, we've been infected here for at least two weeks.

Help?
 

globalcitizen

Senior member
Sep 6, 2004
954
0
0
Drastic thing would be to delete her account. Also have your tried MS Antispyware? Before you do this turn off System Restore and then run said scan in safe mode.
 

Nocturnal

Lifer
Jan 8, 2002
18,927
0
76
Run Hijack this then use the hijackthis.de website to see what you can remove. Also use Microsoft's Anti-Spyware if you're running 2k or XP. Try running the Trend Micro's House Call online scanner as well as Panda's Online scanner. If that doesn't work, try installing Avast and running that. Also remember to disable system restore so they don't come back.
 

timswim78

Diamond Member
Jan 1, 2003
4,330
1
81
monosearch.com



Administrator:
Name-- Registrant(187640)
EMail-: (info@fashionid.com)
tel --: +1.25255572
org: Registrant
P.O. Box No. 71826, KCPO
Hong Kong,Hong Kong,HK 852

Technical Contactor:
Name-- Registrant(187640)
EMail-: (info@fashionid.com)
tel --: +1.25255572
org: Registrant
P.O. Box No. 71826, KCPO
Hong Kong,Hong Kong,HK 852
 

Bob151

Senior member
Apr 13, 2000
857
0
0
Thanks for your ideas. I'll try these in the next few days.

OK, I see two of you say to disable system restore. So, does that mean I should never enable it again?
 

onza

Diamond Member
Sep 21, 2000
8,937
0
0
reviews.ragingazn.com
you can enable it... once you have the problem fixed :)

the only thing is if you have sys restore enabled, the spyware / bad stuff will stay on those restore points and come back .

 

Merlyn3D

Platinum Member
Sep 15, 2001
2,148
0
0
NOD32 2.5 beta > *

It just received Checkmark Certification for spyware, one of only two programs.