TechguyUK
Member
- Reaction score
- 1
- Location
- Lincoln, UK
ok, I'm stuggling with this one.
Customer called reporting Thinkpoint malware. I went over and did the usual to remove it...end the hotfix process with task manager and reset the explorer shell in the registry. Loaded MWB, updated it and did a full scan which found and removed a couple more issues - one of note was 'cleansweep.exe' which i've had problems with before. I then ran SAS - no issues found. Ran a full scan with MSE which also picked up a couple more issues and removed them. TDSSKiller finds nothing. So all is well I thought.
I'm about to hand the machine back to the customer when I notice Google searches are getting redirected to advertising via something called brawsing-check.com. I happens about 1:10 times I click on a link. I've reset IE8, checked for proxies (both in Internet Settings AND in the registry), rogue DNS entries, modified HOSTS file etc etc and I simply can't find the issue.
As of this morning, I've done a system restore to a week prior to when the customer started to experience the issue. The machine is running XP-SP3 with latest MS updates. There is nothing obvious in Autoruns or Process Explorer and I've just run full scans with TDSSKiller, GMER, MWB, MSE and a Kaspersky Rescue Disk 10 all with their latest updates and all report no issues found. I thought it could be a router hijack but the machine has been moved to my workshop and the redirect is still happening.
Anyone any more ideas?
Customer called reporting Thinkpoint malware. I went over and did the usual to remove it...end the hotfix process with task manager and reset the explorer shell in the registry. Loaded MWB, updated it and did a full scan which found and removed a couple more issues - one of note was 'cleansweep.exe' which i've had problems with before. I then ran SAS - no issues found. Ran a full scan with MSE which also picked up a couple more issues and removed them. TDSSKiller finds nothing. So all is well I thought.
I'm about to hand the machine back to the customer when I notice Google searches are getting redirected to advertising via something called brawsing-check.com. I happens about 1:10 times I click on a link. I've reset IE8, checked for proxies (both in Internet Settings AND in the registry), rogue DNS entries, modified HOSTS file etc etc and I simply can't find the issue.
As of this morning, I've done a system restore to a week prior to when the customer started to experience the issue. The machine is running XP-SP3 with latest MS updates. There is nothing obvious in Autoruns or Process Explorer and I've just run full scans with TDSSKiller, GMER, MWB, MSE and a Kaspersky Rescue Disk 10 all with their latest updates and all report no issues found. I thought it could be a router hijack but the machine has been moved to my workshop and the redirect is still happening.
Anyone any more ideas?
Last edited: