Xander
Banned
- Reaction score
- 66
- Location
- Niagara region, Ontario
Okay, it's been a while since I put my hat in my hand and posted one of these but this virus is kicking my ass.
Win7 Home system. MSN is his homepage and when he uses the Bing search box, it 404s. Tried going to Bing.com and it gives you a "You must update to Flash Player Pro" page.
All links on the page still say Bing.com. Even image properties on the page claim it's from Bing (thinking if it was some random site, I could search the registry for references).
It also does this in Safe Mode.
Reset anything network relevant with D7II.
Flushed DNS.
ADW found some common junk but didn't fix it.
MBAM ... same...just crumbs of the other stuff.
Combofix...nothing.
Nothing standing out in HijackThis.
Ran stuff I usually don't: Emsisoft CMD, Norton Power Cleaner, Norman and a few others....NOTHING.
Adapter settings are plain jane. Same results when wired or wireless.
HOSTS is empty.
He'd been running MSSE but I've swapped that for their KAV trial (nothing found).
I'm running a KAV offline disc but it's 90% done and has found nothing yet.
Next step will be an offline SFC in case it's one of those ATAPI.SYS type infections.
I even had him bring his router with him just in case it had been tampered with (but it did the same things on my network so it was just wishful thinking)
Win7 Home system. MSN is his homepage and when he uses the Bing search box, it 404s. Tried going to Bing.com and it gives you a "You must update to Flash Player Pro" page.
All links on the page still say Bing.com. Even image properties on the page claim it's from Bing (thinking if it was some random site, I could search the registry for references).
It also does this in Safe Mode.
Reset anything network relevant with D7II.
Flushed DNS.
ADW found some common junk but didn't fix it.
MBAM ... same...just crumbs of the other stuff.
Combofix...nothing.
Nothing standing out in HijackThis.
Ran stuff I usually don't: Emsisoft CMD, Norton Power Cleaner, Norman and a few others....NOTHING.
Adapter settings are plain jane. Same results when wired or wireless.
HOSTS is empty.
He'd been running MSSE but I've swapped that for their KAV trial (nothing found).
I'm running a KAV offline disc but it's 90% done and has found nothing yet.
Next step will be an offline SFC in case it's one of those ATAPI.SYS type infections.
I even had him bring his router with him just in case it had been tampered with (but it did the same things on my network so it was just wishful thinking)