| Windows 7: Help needed removing malware(browser related) |
28 Oct 2011
|
#1 | | Windows 7 professional 64 bit |
Help needed removing malware(browser related) Hello. I am trying to fix a friend's laptop computer that has Windows 7 installed.
When he gave it to me it was infected with some assorted malware(trojans, etc.). At first, I could not open any applications whatsoever. Every time I would try it would ask me if I wanted to use internet explorer to open it.
I created a few rescue CD's(dr web, avira, avg, etc) and ran those. They cleaned up most of the problems.
Also, I installed AVG free edition and malware bytes. I ran both of those. That removed several more pieces of malware.
At that point, things were mostly good. But I noticed that almost all of the files on the computer had been marked as hidden(the desktop images were all faint, etc). So I went through and manually removed the "hidden" setting from all the PC files.
It seems like I am 99% good. However, when I open firefox browser and enter a google search, and click on a link in the search results, it sometimes redirects me to some other unwanted site. So I guess that there is still some malware lingering in the background that could not be found by AVG and malware bytes.
Any recommendations to fix this?
Thanks!
TC | My System Specs |
| System Manufacturer/Model Number Dell OS Windows 7 professional 64 bit CPU Intel E8400 Memory 8 gig DDR2 Hard Drives 320 gig Western Digital |
28 Oct 2011
|
#2 | | Windows 7 Home Premium 64bit |
A friend of mine had an issue with his browser redirecting search results, and it took me a few days to find a fix, but I found a program called TDSSKiller and that removed the problem. You can try it out for yourself to see if it will also be a fix for you, and hopefully it will. Anti-rootkit utility TDSSKiller
Edit: Here's a little bit more info about the trojan if you need it. Backdoor.Tidserv | Symantec | My System Specs | | System Manufacturer/Model Number Toshiba Qosmio x505-Q8100X OS Windows 7 Home Premium 64bit CPU Intel i5-2410M Motherboard ? Memory 4GB DDR3 1333MHz memory Graphics Card NVIDIA® GeForce® GTX 460M with 1.5GB GDDR5 discrete graphics Sound Card Conexant SmartAudio HD/NVIDIA HD Audio Monitor(s) Displays Laptop/18.4"/1680x945 Keyboard Built-in full. Mouse Razer Mamba PSU ? Case ? Cooling ? Hard Drives Toshiba ST9500420AS/500GB 7200RPM. |
28 Oct 2011
|
#3 | | Win7 x 6 PC's California, Florida, Boston |
In addition to excellent idea TDSS Killer, I'd install MSE or Avast6 but not AVG which is no longer recommended by anyone here. For a boot scan use Microsoft Standalone System Sweeper
Often a serious infection requires reinstalling. In your case you can run Dell factory recovery after backing up your files: Dell Restoring Your Computer´s Software to the Factory Settings
Or if you're one of the lucky ones who got the Dell Reinstallation DVD you have the option to do a clean reinstall without the factory bloatware for a lighter weight install. Follow these steps to get it perfect: Reinstalling Windows 7 | My System Specs | | |
28 Oct 2011
|
#4 | | Windows 7 Home Premium x64 SP1 SoCal USA |
If you get to the point where you are contemplating a repair install or fresh install, then I would give this tool a try first, as I have read some very positive things about it, and at this point, you really have nothing to lose: |MG| Tweaking.com - Windows Repair 1.4.3 Download | My System Specs | | OS Windows 7 Home Premium x64 SP1 |
28 Oct 2011
|
#5 | | Windows 7 Home Premium 32 bit In a house with a cat trying to kill me |
You may wish to give Norton Power Eraser a try, which offers a rootkit scan in addition to virus scanning: Norton Rescue Tools Quote: Because Norton Power Eraser uses aggressive methods to detect threats, there is a risk that it can select some legitimate programs for removal. You should use this tool very carefully. But, as gregrocker stated, your safest bet for a clean PC is a clean install. | My System Specs | | System Manufacturer/Model Number Dell Hell oh Well OS Windows 7 Home Premium 32 bit CPU Intel Core 2 Duo 2.93GHz Memory Not much with my ADHD Graphics Card ATI Radeon HD 4350 Monitor(s) Displays I have one...It's bright. A 19 inch CRT actually. Keyboard It's 10 years old and amazingly still works Mouse Same deal with the mouse, 10 yrs old, if it ain't broke... Case Don't get on my case...man :D Cooling I have an Air Conditioner & Diet Pepsi Hard Drives 250 GB Main Drive, 2 - 1 TB Externals, various FD's. |
28 Oct 2011
|
#6 | | Windows 7 Ultimate SP1 (x64) South Australia |
Hi,
You might also want to flush the DNS and reset the hosts file. Please try this:
1. Copy the following text into a blank Notepad file: @Echo on
pushd\windows\system32\drivers\etc
attrib -h -s -r hosts
echo 127.0.0.1 localhost>HOSTS
attrib +r +h +s hosts
popd
ipconfig /release
ipconfig /renew
ipconfig /flushdns
netsh winsock reset all
netsh int ip reset all
shutdown -r -t 1
del %0
2. Save this as FLUSH.BAT to your desktop.
3. Right-click on FLUSH.BAT and run as Administrator.
The PC will reboot itself. Once it has done that, open a browser and see if the redirection has been fixed.
Regards,
Golden | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Golden Mk. I.3 OS Windows 7 Ultimate SP1 (x64) CPU Intel i7 860 @ 2.80 GHz Motherboard Gigabyte P55A-UD3R Rev.1. Award BIOS F13 Memory 16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24) Graphics Card EVGA NVidia GTX 560 1024MB Sound Card Realtek Integrated Monitor(s) Displays Dual Samsung SyncMaster 2494HS Screen Resolution 1920*1080 and 1920*1080 Keyboard Logitech G110 Mouse Logitech MX518 PSU Thermaltake ToughPower QFan 750W Case Thermaltake Element S VK60001W2Z Cooling Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans Hard Drives 1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
3*Samsung F1 SpinPoint 1TB in RAID5;
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0 Internet Speed Not fast enough!!! Antivirus MSE and Malwarebytes Pro Browser Chrome Version 25 Other Info Laptop: ASUS X54C, Intel Core i3-2330M @ 2.0Ghz, 4GB RAM, Intel HD on-board graphics, Windows 7 Professional SP1 (x64), LinuxMint 14 (x64), PepperMint 3 (x86) |
28 Oct 2011
|
#7 | | Windows 7 Home Premium x64 SP1 SoCal USA |
I have to admit, that if my machine were to ever get infected, I would re-image to my once per month image. Even if I didn't have an image to fall back on, I would then re-install windows. I know it's excessive and most might find it unnecessary, but that is just me. I would never feel 100% safe using a machine that I knew had at one point in time been compromised.
But if I were cleaning a friend's machine, then all of the advice in this thread would be followed. I would like to also add Hitman Pro ( Home - SurfRight) as a great tool as well. Also, SUPERAntiSpyware has an online scanner that is pretty good too. ( SUPERAntiSpyware.com - SUPERAntiSpyware Portable Scanner ) | My System Specs | | OS Windows 7 Home Premium x64 SP1 |
29 Oct 2011
|
#8 | | Windows 7 professional 64 bit |
Hey guys, thanks for all of the good information. I will try your recommendations and report back.
A few other things......
First, why is AVG out of favor with people here? I have had decent luck with it over the years, especially for something free. Call me cheap, but I am VERY partial to free stuff
Also, I do agree with the remarks that fresh installs are better. That is what I usually do myself with my own computers. However, in this case, this is my friend's computer, and he wants to keep his applications and settings. So if I can get his system disinfected then he will try that for a while. But it would not surprise me if we eventually do end up going with a new install at some point.
Regarding a possible reinstallation for him.......... I have gotten to the point where I usually buy dell systems for myself, in part, because the windows reinstallation disks are so easy to come by. However, this laptop is an MSI product. I do not have an MSI specific Windows installation disk.
I do have a Dell reinstallation disk. Can I use that to reinstall Windows on his laptop? He does have an authentic Windows 7 license key. And thank the lord, it is still legible.
Thanks,
TC | My System Specs | | System Manufacturer/Model Number Dell OS Windows 7 professional 64 bit CPU Intel E8400 Memory 8 gig DDR2 Hard Drives 320 gig Western Digital |
29 Oct 2011
|
#9 | | Windows 7 Ultimate SP1 64-Bit Peterborough, England |
The Dell DVD is an OEM version and will throw a wobbly if you try and install it on a computer other than the one it's tied to, unfortunately.
You say the product key is still legible. Can you borrow a Windows DVD off someone? It would need to be the same version as what is on his computer. | My System Specs | | System Manufacturer/Model Number HP Pavilion Elite 495UK OS Windows 7 Ultimate SP1 64-Bit CPU Intel Core i7 870 @ 2.93GHz Motherboard MSI 2A9C (CPU1) Memory 8Gb Dual-Channel DDR3 @ 664MHz Graphics Card nVidia GeForce GTX 460 1024MB dedicated RAM Sound Card Realtek HD Audio Monitor(s) Displays HP2310i Screen Resolution 1920 x 1080 Keyboard Logitech K750 solar-powered keyboard Mouse Logitech Wireless M180 mouse PSU 460W Case HP Elite Cooling Air cooled Hard Drives 1x1954GB Hitachi HDS22020ALA 330 (RAID), 1x1954GB Hitachi External for backup and storage Internet Speed 2Mb Other Info Pure Avanti Flow Internet Radio with iPod Dock, 64Gb iPod, HP USB Speakers, Sony MDR-V500 Headphones, Sony Vaio F-Series Laptop |
29 Oct 2011
|
#10 | | Win7 x 6 PC's California, Florida, Boston |
If you're partial to free stuff, then use the AV's which are recommended for best performance with Windows 7 and it's firewall, MSE and Avast6.
All that's extra in the Dell Reinstallation DVD is Dell branding and SLP reactivation, I believe, which won't activate in another machine. You can try using it to clean reinstall, then remove the Dell logo from Computer>Properties page, activate with key on COA sticker.
But it would be best to find a clean-copy ISO for your version to burn to DVD or write to stick using Windows 7 USB-DVD Download Tool. If you need to download one, google Official Windows 7 ISO download from My Digital Life | My System Specs | | Help needed removing malware(browser related) problems? All times are GMT -5. The time now is 12:14 AM. | |