Page 1 of 3 123 LastLast
Results 1 to 16 of 45

Thread: Oh, I so love being a "computer expert" at Christmas

  1. #1
    Mostly Me Lucio's Avatar
    Join Date
    Mar 2007
    Location
    Tring
    Posts
    5,163
    Thanks
    443
    Thanked
    448 times in 351 posts
    • Lucio's system
      • Motherboard:
      • Gigabyte GA-970A-UD3P
      • CPU:
      • AMD FX-6350 with Cooler Master Seldon 240
      • Memory:
      • 2x4GB Corsair DDR3 Vengeance
      • Storage:
      • 128GB Toshiba, 2.5" SSD, 1TB WD Blue WD10EZEX, 500GB Seagate Baracuda 7200.11
      • Graphics card(s):
      • Sapphire R9 270X 4GB
      • PSU:
      • 600W Silverstone Strider SST-ST60F
      • Case:
      • Cooler Master HAF XB
      • Operating System:
      • Windows 8.1 64Bit
      • Monitor(s):
      • Samsung 2032BW, 1680 x 1050
      • Internet:
      • 16Mb Plusnet

    Oh, I so love being a "computer expert" at Christmas

    It's my own fault really, I should have just kept my mouth shut instead of going "oh I'm sure it's a quick fix".

    Turns out it's not...

    Basically there's *something* on this laptop that occasionally hijacks search engine results and redirects them to randomjunk or porn pages.

    So far I've tried the following

    F-Secure Blacklight rootkit inspection
    Malwarebytes
    Microsoft Security Essentials
    Hijackthis, and then running the log through hijackthis.de's analyzer, including manually deleting the registry entries that it couldn't remove.


    The only thing that stops the behaviour is running in safe mode, so I'm sure something that's engaging on startup is causing it, but so far not managed to find exactly what it is. Any ideas on what else I can try?

    (\___/) (\___/) (\___/) (\___/) (\___/) (\___/) (\___/)
    (='.'=) (='.'=) (='.'=) (='.'=) (='.'=) (='.'=) (='.'=)
    (")_(") (")_(") (")_(") (")_(") (")_(") (")_(") (")_(")


    This is bunny and friends. He is fed up waiting for everyone to help him out, and decided to help himself instead!

  2. #2
    Senior Member
    Join Date
    Sep 2006
    Location
    London
    Posts
    1,198
    Thanks
    26
    Thanked
    79 times in 70 posts

    Re: Oh, I so love being a "computer expert" at Christmas

    I would try adaware and spybot search and distroy.

  3. #3
    unknown Georgy291's Avatar
    Join Date
    Jan 2009
    Location
    university of york
    Posts
    1,492
    Thanks
    95
    Thanked
    84 times in 54 posts
    • Georgy291's system
      • Motherboard:
      • ga-p55-ud3
      • CPU:
      • intel i5 750 @4.2
      • Memory:
      • 4gig DDR3 1600mhz 8.8.8
      • Storage:
      • 1tb samsung F3 + 200gig WD caviar black
      • Graphics card(s):
      • 6850 XF
      • PSU:
      • antec 750w something or other
      • Case:
      • antec 300
      • Operating System:
      • windows 7
      • Monitor(s):
      • 23" acer @1080p
      • Internet:
      • 24mb BE @ 22mb

    Re: Oh, I so love being a "computer expert" at Christmas

    better idea, go to start run (xp) or in the search at the bottom vista / 7 then type in "msconfig"

    you should see a new window poping up, go to start up, and there you have a list off all the things are loaded up when windows loads up, untick everything they you have no idea what it is dont worry unticking too many things wont harm anything. and then re start hopefully that will fix it....ot atleast works with me most times
    Quote Originally Posted by MadduckUK View Post
    now that i think about the word "throttled" in a certain light... its not so far different to strangled really

    our boiler broke so we has no heating or hot water, this is the bloody result ^^

  4. #4
    Senior Member Ulti's Avatar
    Join Date
    Feb 2009
    Posts
    2,054
    Thanks
    769
    Thanked
    230 times in 195 posts
    • Ulti's system
      • Motherboard:
      • MSI B550I Gaming Edge
      • CPU:
      • AMD Ryzen 7 3700X
      • Memory:
      • Kingston 32GB HyperX 3200Mhz
      • Storage:
      • Corsair MP510 1920GB
      • Graphics card(s):
      • Nvidia RTX 3060 Ti FE
      • PSU:
      • SilverStone SX500-LG V2.0
      • Case:
      • SSUPD Meshlicious
      • Operating System:
      • Windows 10 Pro
      • Monitor(s):
      • AOC Agon AG322QC4 31.5"
      • Internet:
      • TalkTalk Fibre 150Mb

    Re: Oh, I so love being a "computer expert" at Christmas

    Yup msconfig is the way to go. It also makes startup much faster too and cleaner without all those junk programs you installed but never used popping up.

  5. #5
    Efficiently lazy shadowmaster's Avatar
    Join Date
    Oct 2006
    Location
    London
    Posts
    3,233
    Thanks
    397
    Thanked
    310 times in 208 posts
    • shadowmaster's system
      • Motherboard:
      • Gigabyte GA-890FXA-UD5
      • CPU:
      • AMD Phenom II X4 965 @ 3.6Ghz
      • Memory:
      • 4GB Corsair XMS3
      • Storage:
      • Kingston SSD V series 64GB + Samsung F3 1TB
      • Graphics card(s):
      • XFX 5870 1GB in Crossfire
      • PSU:
      • BeQuiet 1200W Dark Power Pro
      • Case:
      • Coolermaster Stacker 832 SE
      • Operating System:
      • Windows 7 Home Premium 64bit
      • Monitor(s):
      • 3 x BenQ G2222HDL 21.5inch 1080p
      • Internet:
      • BT Infinity 2

    Re: Oh, I so love being a "computer expert" at Christmas

    + 1 to the above, if that does not work I would do a format and reinstall, simply and easy

  6. #6
    MrM
    MrM is offline
    Registered+
    Join Date
    Dec 2009
    Posts
    21
    Thanks
    0
    Thanked
    2 times in 2 posts

    Re: Oh, I so love being a "computer expert" at Christmas

    If Spybot fails, then I'm afraid this will be challenging. Some malware still has to be removed manually despite all of these available programs.

    Your first step should be to try an alternative browser. You say it hijacks search engine results, assuming this is Internet Explorer, confirm that this doesn't happen in Firefox. Assuming this works, this also gives you a nice workaround to present to your relatives until it is fixed.

    Your second step is to go back through hijackthis and double check that things like localhost are all in order. Check the Internet Explorer settings to confirm that the network settings aren't re-reouting traffic.

    If all appears in order, then go through msconfig and the services tab of Task Manager. Google anything that appears remotely suspicious. Look for misspellings of common services. Symantec's website normally has great instructions for manual removal if you do find it this way.

    If all that fails to lead to results, then your best bet is to go through the System32 folder via Date Modified. Ask your relatives roughly when this started happening and try and see if there were any suspicious file modifications or creations on this date.

  7. #7
    Senior Member Perfectionist's Avatar
    Join Date
    May 2007
    Posts
    824
    Thanks
    245
    Thanked
    39 times in 30 posts

    Re: Oh, I so love being a "computer expert" at Christmas

    tbh just move the individual's personal files over to an external HD then bootnuke it and reinstall OS and software, they probably have loads of crap they never use anyway if they are the kind of person to get these kind of things (e.g. no knowledge of personal security). Afterwards they'll be all wow my system is so much faster.

    Probably faster in the long run too. Also with Windows there's so many ways to embed stuff behind the whole uninstall/msconfig kind of thing you'll never be sure otherwise.

  8. #8
    Pre-Cambrian nibbler's Avatar
    Join Date
    Aug 2009
    Location
    London
    Posts
    3,668
    Thanks
    913
    Thanked
    266 times in 216 posts
    • nibbler's system
      • CPU:
      • i5-2410m
      • Memory:
      • 6GB ddr3 1333mhz
      • Storage:
      • 256GB Plextor M5S SSD
      • Graphics card(s):
      • 1GB 6650M
      • Operating System:
      • Windows 7 64 bit

    Re: Oh, I so love being a "computer expert" at Christmas

    Reinstall now is quicker surely, done in 2 hours instead of 2 days looking for something that avoids having to reinstall.

  9. #9
    MrM
    MrM is offline
    Registered+
    Join Date
    Dec 2009
    Posts
    21
    Thanks
    0
    Thanked
    2 times in 2 posts

    Re: Oh, I so love being a "computer expert" at Christmas

    Quote Originally Posted by nibbler View Post
    Reinstall now is quicker surely, done in 2 hours instead of 2 days looking for something that avoids having to reinstall.
    Remember that typical PC users will have an OS going for years accumulating programs, not necessarily backed up and the original install CDs could be lost. It may not necessarily be the easiest option.

  10. #10
    Senior Member
    Join Date
    Aug 2005
    Posts
    1,528
    Thanks
    18
    Thanked
    76 times in 63 posts
    • lodore's system
      • Motherboard:
      • X570 AORUS MASTER
      • CPU:
      • Amd Ryzen 5900x
      • Memory:
      • 32GB DDR4 2666 Mhz
      • Storage:
      • 1TB Gigabyte AORUS 7000s SSD and sandisk 1tb sata 3
      • Graphics card(s):
      • EVGA 1080TI 11gb
      • PSU:
      • Ion+ 860W
      • Case:
      • Corsair 4000D AIRFLOW
      • Operating System:
      • Windows 10 pro 64bit
      • Monitor(s):
      • Iiyama 34inch ultra wide quad HD 144hz and 24inch asus HD
      • Internet:
      • 80Mbps Zen

    Re: Oh, I so love being a "computer expert" at Christmas

    first off try autoruns and process explorer
    a repair maybe easier depending on how much software on the computer and how much data to backup.
    start process explorer go to view select columns. go to process image, tick verify signer,image path and company and click on ok. now go to options and click on verify image signatures.
    most of the legit processes should be signed so it will be easier to tell what process is the malware.
    for any your unsure about check the process image section on the right of the process and it will tell you where its running from.
    terminate the malware process/processes and delete it from startup using msconfig or autoruns.
    remember if the OS is vista or 7 run process explorer as administrator.
    did you reset all the internet settings to default and check the hosts file?
    how does the computer connect to the internet?
    Last edited by lodore; 26-12-2009 at 07:37 PM.

  11. #11
    Senior Member
    Join Date
    May 2009
    Location
    Norfolk
    Posts
    474
    Thanks
    3
    Thanked
    26 times in 26 posts
    • pipTheGeek's system
      • Motherboard:
      • Asus P6T Deluxe
      • CPU:
      • Core i7 920 @ 3.6GHz
      • Memory:
      • 3 * 2Gb Corsair XMS @ DDR3 1800
      • Storage:
      • 300GB 15K SAS + 500Gb
      • Graphics card(s):
      • GTX570
      • PSU:
      • corsair 760i
      • Case:
      • Corsair 550d
      • Operating System:
      • Windows 7
      • Monitor(s):
      • Dell Alienware 23"
      • Internet:
      • VM 50Mb

    Re: Oh, I so love being a "computer expert" at Christmas

    I would go with msconfig to edit startup items first. If that fails then I would go with a re-install, assuming that their machine was in a state where it can be re-installed and they haven't lost all the media.

    Does anyone mind if this thread becomes tales of christmas tech support?

    My christmas tech support challenge is a friend bought their son an Acer Aspire One D250. Then spilt a wkd in it. They were reasonably quick at pooring the drink back out of the laptop. It still boots, but pressing keys just results in beeps. Sadly I don't know how to get the keyboard out and there appears to be screws under it.

  12. #12
    stormrazer razer121's Avatar
    Join Date
    Sep 2009
    Posts
    3,178
    Thanks
    880
    Thanked
    146 times in 128 posts

    Re: Oh, I so love being a "computer expert" at Christmas

    haha i had this...wow 4 times mate is the pc on windows 7?? cos it only happened to me since i had windows 7, really odd and i was in firefox, to be honest i tryed everything everyone is telling you, which does catch alot of it...but it still remains there, personaly? i think you should reinstall ive had to
    Quote Originally Posted by TAKTAK View Post
    It was so small that mine wouldn't fit into it

  13. #13
    MrM
    MrM is offline
    Registered+
    Join Date
    Dec 2009
    Posts
    21
    Thanks
    0
    Thanked
    2 times in 2 posts

    Re: Oh, I so love being a "computer expert" at Christmas

    Quote Originally Posted by pipTheGeek View Post
    My christmas tech support challenge is a friend bought their son an Acer Aspire One D250. Then spilt a wkd in it. They were reasonably quick at pooring the drink back out of the laptop. It still boots, but pressing keys just results in beeps. Sadly I don't know how to get the keyboard out and there appears to be screws under it.
    Can you boot to Windows? If it's simply a keyboard issue you can hold out hope it will dry, but if it's beyond that I'm afraid options are going to be extremely limited.

  14. #14
    Pre-Cambrian nibbler's Avatar
    Join Date
    Aug 2009
    Location
    London
    Posts
    3,668
    Thanks
    913
    Thanked
    266 times in 216 posts
    • nibbler's system
      • CPU:
      • i5-2410m
      • Memory:
      • 6GB ddr3 1333mhz
      • Storage:
      • 256GB Plextor M5S SSD
      • Graphics card(s):
      • 1GB 6650M
      • Operating System:
      • Windows 7 64 bit

    Re: Oh, I so love being a "computer expert" at Christmas

    I'm getting scared of windows 7 because this is all I head about on it

  15. #15
    Senior Member
    Join Date
    Aug 2005
    Posts
    1,528
    Thanks
    18
    Thanked
    76 times in 63 posts
    • lodore's system
      • Motherboard:
      • X570 AORUS MASTER
      • CPU:
      • Amd Ryzen 5900x
      • Memory:
      • 32GB DDR4 2666 Mhz
      • Storage:
      • 1TB Gigabyte AORUS 7000s SSD and sandisk 1tb sata 3
      • Graphics card(s):
      • EVGA 1080TI 11gb
      • PSU:
      • Ion+ 860W
      • Case:
      • Corsair 4000D AIRFLOW
      • Operating System:
      • Windows 10 pro 64bit
      • Monitor(s):
      • Iiyama 34inch ultra wide quad HD 144hz and 24inch asus HD
      • Internet:
      • 80Mbps Zen

    Re: Oh, I so love being a "computer expert" at Christmas

    Quote Originally Posted by pipTheGeek View Post
    I would go with msconfig to edit startup items first. If that fails then I would go with a re-install, assuming that their machine was in a state where it can be re-installed and they haven't lost all the media.

    Does anyone mind if this thread becomes tales of christmas tech support?

    My christmas tech support challenge is a friend bought their son an Acer Aspire One D250. Then spilt a wkd in it. They were reasonably quick at pooring the drink back out of the laptop. It still boots, but pressing keys just results in beeps. Sadly I don't know how to get the keyboard out and there appears to be screws under it.
    Hello,
    since its a new laptop find out what the warranty from acer is like. if you wish to replace the laptop keyboard yourself then read the following.
    replacing a laptop keyboard is quite easy.
    the best way is to download the service manual from the acer website for the laptop and then follow the guidance which should be the same as i have written below:
    1. open the screen fully so its completely flat open.
    2.Along the row where the power button is there is a section on the right hand side where you can carefully put a screwdriver in. you carefully place in a screwdriver and undo the clips by sliding the screwdriver along.
    3.you may need to place the screw driver in to the left hand side to undo a few clips.
    4. take the panel off.
    5. undo the two screws securing the keyboard in place.
    6. carefully lift up the keyboard and carefully unplug the laptop cable (if there is a cable)

  16. #16
    Senior Member
    Join Date
    Oct 2009
    Location
    Ohio
    Posts
    319
    Thanks
    2
    Thanked
    10 times in 10 posts

    Re: Oh, I so love being a "computer expert" at Christmas

    Quote Originally Posted by Lucio View Post
    It's my own fault really, I should have just kept my mouth shut instead of going "oh I'm sure it's a quick fix".

    Turns out it's not...

    Basically there's *something* on this laptop that occasionally hijacks search engine results and redirects them to randomjunk or porn pages.

    So far I've tried the following

    F-Secure Blacklight rootkit inspection
    Malwarebytes
    Microsoft Security Essentials
    Hijackthis, and then running the log through hijackthis.de's analyzer, including manually deleting the registry entries that it couldn't remove.


    The only thing that stops the behaviour is running in safe mode, so I'm sure something that's engaging on startup is causing it, but so far not managed to find exactly what it is. Any ideas on what else I can try?
    Delete the Temp files, all of them. Check your startup in MSCONFIG. Make sure everything in there is legit. Disable (uncheck) everything that isn't OS essential.

Page 1 of 3 123 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Replies: 19
    Last Post: 01-08-2006, 03:27 PM
  2. Christmas Photos (56k warning)
    By Paul Adams in forum Consumer Electronics
    Replies: 4
    Last Post: 29-12-2005, 11:04 AM
  3. Christmas??!!
    By Honoop in forum General Discussion
    Replies: 41
    Last Post: 26-10-2004, 09:03 PM
  4. Christmas Feel Good Thread
    By Zak33 in forum General Discussion
    Replies: 5
    Last Post: 03-01-2004, 02:56 PM
  5. Do you believe in a thing called love?
    By TeePee in forum Question Time
    Replies: 8
    Last Post: 18-11-2003, 10:45 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •