Hi,

I read another post on here with the same problem, tried to follow the advice there but it didn't fix my problem.

IE starts when windoes starts up, but it looks odd (has a different lay out) and goes to MSN.com. I cannot get it to stop. Once i close it though it doesn't reappear until another start up.

Any help? Gopher?

Dani AI

Generated

Good to see the visible symptom vanished — thanks for the follow-up, . ’s caution is valid: symptom removal can be only the start. Malware that modifies browsers or uses hidden persistence often leaves artifacts that let it return or that indicate broader compromise. The checklist below covers verification steps that go beyond the initial “sticky” cleanup.

A practical verification checklist:

  • Update antivirus definitions and run a full, offline-capable scan with the primary AV engine.
  • Run a second‑opinion on‑demand scanner (an on‑demand engine different from the installed AV).
  • Perform an offline/bootable rescue scan to detect kernel/MBR/rootkit-level infections.
  • Inspect autorun/autostart locations with a tool like Sysinternals Autoruns (Run, RunOnce, Services, Scheduled Tasks, BHO/AppInit_DLLs).
  • Check the hosts file (C:\Windows\System32\drivers\etc\hosts), proxy settings, and browser add‑ons; reset IE settings if altered.
  • Verify system integrity with System File Checker and ensure Windows Update is current.
  • If credentials were used on the machine while infected, change those passwords from a known‑clean device.

Examples of quick checks (run from an elevated command prompt):

sfc /scannow
netstat -bano
ipconfig /flushdns

(sfc checks system files; netstat shows active connections; flushdns clears cached DNS entries that malware may have poisoned.)

Logs that help confirm a complete cleanup: Autoruns output, a full on‑demand scan log, a Farbar/FRST scan log (or equivalent system scan), and Windows Event Viewer entries around the infection time. Sanitize personal info before posting. When a rootkit or low‑level persistence is suspected, the only 100% certain remedy is a full image restore or clean OS reinstall after backing up verified data.

Recommended Answers

All 3 Replies

Ok, followed the sticky cleaning process and it fixed it. It was some trojan and rootkit. Thanks for the help!

Ok, followed the sticky cleaning process and it fixed it. It was some trojan and rootkit. Thanks for the help!

How can you be 100% certain that everything is gone. Those are preliminary steps only. There likely would be other steps required to complete the cleanup. If everything isn't gone then further work will be much more difficult.

This is a help forum, it would have also provided help to others experiencing the same problems if you had been willing to share all the information with others and also the helpers here.

Sorry you have chosen not to go forward with other steps. Hope all works well for you.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.