SOHOtechRob
Active Member
- Reaction score
- 63
- Location
- Columbus, Ohio USA
Situation:
Customer and his wife each have laptops. One is Win7, the other Win8 (maybe 8.1, didn't check).
Symptoms:
When using IE or Chrome (the only browsers installed), getting pop-under and other additional tab ads/scary notices about video player not being compatible, need to update this or that or sometimes just a blatant garbage site like $lutroulette. Wife accesses her AOL.com email account from both laptop and iPhone.
Unsuccessful Efforts:
On both machines customer already has MBAM premium which scanned and found nothing. On both machines, customer already has SuperAntiSpyware which has scanned and found nothing. On both machines, in a combination of SAFE and NORMAL modes, I have run ComboFix, CCleaner, TDSS Killer, ADW Cleaner, RevoUninstaller (to remove obvious junk), System Ninja and RogueKiller. Either no items found or minor items found which I removed. No extensions/add-ons are in the browsers besides Norton 360. I disabled a few suspicious scheduled tasks. But problem persists when performing Google search or just entering data on web sites (like entering travel dates on Kayak.com)
Compounding Problem:
Wife uses Safari on her iPhone and performing a browse causes a warning prompt to appear that something is out of date and she needs to update. This looks like a typical fake warning that would appear on a computer browser, but this is on her iPhone.
I'm at a loss here. Not only is the problem software not showing up on these scanner/cleaner tools, but it's on both systems AND her iPhone. I don't trust a System Restore since I don't know how long this problem has been present. At this point, my only safe suggestion is to back up data, note installed software so they can gather installation media/keys, and then perform a full pave nuke.
Does anybody have any suggestions???
Many thanks!
Update: Thanks to trevm999. It was indeed malicious DNS entries on the router. I set to Google and now husband and wife are all good!
Customer and his wife each have laptops. One is Win7, the other Win8 (maybe 8.1, didn't check).
Symptoms:
When using IE or Chrome (the only browsers installed), getting pop-under and other additional tab ads/scary notices about video player not being compatible, need to update this or that or sometimes just a blatant garbage site like $lutroulette. Wife accesses her AOL.com email account from both laptop and iPhone.
Unsuccessful Efforts:
On both machines customer already has MBAM premium which scanned and found nothing. On both machines, customer already has SuperAntiSpyware which has scanned and found nothing. On both machines, in a combination of SAFE and NORMAL modes, I have run ComboFix, CCleaner, TDSS Killer, ADW Cleaner, RevoUninstaller (to remove obvious junk), System Ninja and RogueKiller. Either no items found or minor items found which I removed. No extensions/add-ons are in the browsers besides Norton 360. I disabled a few suspicious scheduled tasks. But problem persists when performing Google search or just entering data on web sites (like entering travel dates on Kayak.com)
Compounding Problem:
Wife uses Safari on her iPhone and performing a browse causes a warning prompt to appear that something is out of date and she needs to update. This looks like a typical fake warning that would appear on a computer browser, but this is on her iPhone.
I'm at a loss here. Not only is the problem software not showing up on these scanner/cleaner tools, but it's on both systems AND her iPhone. I don't trust a System Restore since I don't know how long this problem has been present. At this point, my only safe suggestion is to back up data, note installed software so they can gather installation media/keys, and then perform a full pave nuke.
Does anybody have any suggestions???
Many thanks!
Update: Thanks to trevm999. It was indeed malicious DNS entries on the router. I set to Google and now husband and wife are all good!
Last edited: