Windows Image restored, virus still there

Vincenzo

New Member
Power User
Messages
299
My friend's computer started getting multiple pop-ups like "Your video player is out of date...." so I restored it using the Windows Image I had created shortly after he bought it. But it almost immediately started getting the popups again.

Is it possible that the infection persisted through the image restore? Does a Windows image restoration recover the master boot record too, or could a virus/rootkit have remained in there?

His hard drive is partitioned into C: (system) and E: (data files). The image was only for the C: drive and most likely the system reserved partition.

I did scan the E: drive with Norton, found nothing there.

Thanks
 

My Computer

System One

  • OS
    Windows 8 Pro
It is possible that the problem was there when you made the image backup otherwise the infection would not have persisted through the image restore.

Download and run Malwarebytes Free on the whole computer. I would remove Norton entirely using their removal tool as it presents there own problems. Just use Windows Defender.
 

My Computer

System One

  • OS
    windows 8.1 Update 1 Pro 64bit
    System Manufacturer/Model
    Pavillion H8-1202
    CPU
    I7-2600 @ 3.4 GHz
    Motherboard
    PEGATRON
    Memory
    8 GB
    Graphics Card(s)
    NIVDIA GeForce GT 520
    Sound Card
    Realtek ALC656GR CODEC
    Monitor(s) Displays
    Samsung SyncMaster S22B350
    Screen Resolution
    1920X1080 32 bit color
    Hard Drives
    Samsung 850 EVO SSD 500GB
    Keyboard
    Razer Blackwidow Ultimate 2013
    Mouse
    Logitech M510
Since rootkits write a cloaked partition, it is possible for a rootkit to survive a restore.

Run TDSSKiller & see if it finds anything. Before running the program, click on the "Change Parameters" text & check the box next to "Detect TDLFS File system." Then run a scan.

Malwarebytes also makes a rootkit scanner.

Malwarebytes | Anti-Rootkit BETA - Free Rootkit Scanner & Remover

It sounds like you may have some stubborn adware, so after the rootkit scan, run AdwCleaner.
 

My Computer

System One

  • OS
    Win 7 32, Win 7 64 Pro, Win 8.1 Pro
    Computer type
    PC/Desktop
    System Manufacturer/Model
    It's a Dell, Dude.
    CPU
    Intel Caffinated Core Duo
    Motherboard
    Father is bored too.
    Memory
    4 GB
    Graphics Card(s)
    NVidia something-or-another
    Monitor(s) Displays
    24" HD TV/Monitor/Alternative Dimensional Viewing Portal
    Screen Resolution
    Fuzzy after a couple drinks
    Hard Drives
    2 or 3, depending on if it's a night they're arguing about having a "split personality crisis" because I partitioned the drive.
    Case
    Don't get on my case....man
    Cooling
    Scotch on the rocks on the weekends..
    Keyboard
    Mad Catz Cyborg V7. Or maybe Cyborg Catz Are Mad At V7's??? I know it lights up...far out.
    Mouse
    currently being stalked by the cat...
    Internet Speed
    Never fast enough...
    Browser
    Defeated by Mario...wait...OH...BRowser...
    Antivirus
    Various
I ran ADWCleaner, it came up clean.

The new version of MBAM has the rootkit scanning option built in, and I ran the Custom Scan using that. It found nothing.

I also ran Hitman Pro, came up clean.

I'll give TDSSKiller a run today. Thanks
 

My Computer

System One

  • OS
    Windows 8 Pro
Good advice here! Good luck!
 

My Computer

System One

  • OS
    Win 10 Pro 64bit
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Home built Intel i7-3770k-based system
    CPU
    Intel i7-3770k, Overclocked to 4.6GHz (46x100) with Corsair H110i GT cooler
    Motherboard
    ASRock Z77 OC Formula 2.30 BIOS
    Memory
    32GB DDR3 2133 Corsair Vengeance Pro
    Graphics Card(s)
    GeForce GTX 980ti SC ACS 6GB DDR5 by EVGA
    Sound Card
    Creative Sound Blaster X-Fi Titanium HD, Corsair SP2500 speakers and subwoofer
    Monitor(s) Displays
    LG 27EA33 [Monitor] (27.2"vis) HDMI
    Screen Resolution
    1920x1080
    Hard Drives
    Samsung SSD 850 EVO 250GB (system drive)
    WD 6TB Red NAS hard drives x 2 in Storage Spaces (redundancy)
    PSU
    Corsair 750ax fully modular power supply with sleeved cables
    Case
    Corsair Air 540 with 7 x 140mm fans on front, rear and top panels
    Cooling
    Corsair H110i GT liquid cooled CPU with 4 x 140" Corsair SP "push-pull" and 3 x 140mm fans
    Keyboard
    Thermaltake Poseidon Z illuminated keyboard
    Mouse
    Corsair M65 wired
    Internet Speed
    85MBps DSL
    Browser
    Chrome and Edge
    Antivirus
    Windows Defender, MalwareBytes Pro and CCleaner Pro
    Other Info
    Client of Windows Server 2012 R2 10 PC's, laptops and smartphones on the WLAN.

    1GBps Ethernet ports
TDSSKiller found nothing.

I did change his DNS settings in adapter properties to use Google for DNS. He has not had any issues in the day or so since I've done that. I am wondering if his router has been compromised, and is doing DNS misdirects. I'm going to give it another day or two before I reset his router.
 

My Computer

System One

  • OS
    Windows 8 Pro

My Computer

System One

  • OS
    Win 7 32, Win 7 64 Pro, Win 8.1 Pro
    Computer type
    PC/Desktop
    System Manufacturer/Model
    It's a Dell, Dude.
    CPU
    Intel Caffinated Core Duo
    Motherboard
    Father is bored too.
    Memory
    4 GB
    Graphics Card(s)
    NVidia something-or-another
    Monitor(s) Displays
    24" HD TV/Monitor/Alternative Dimensional Viewing Portal
    Screen Resolution
    Fuzzy after a couple drinks
    Hard Drives
    2 or 3, depending on if it's a night they're arguing about having a "split personality crisis" because I partitioned the drive.
    Case
    Don't get on my case....man
    Cooling
    Scotch on the rocks on the weekends..
    Keyboard
    Mad Catz Cyborg V7. Or maybe Cyborg Catz Are Mad At V7's??? I know it lights up...far out.
    Mouse
    currently being stalked by the cat...
    Internet Speed
    Never fast enough...
    Browser
    Defeated by Mario...wait...OH...BRowser...
    Antivirus
    Various
My friend's computer has been running without the misdirects and popups for 3 days now, since I started using Google DNS. He seems content to just let it be for now. I am not so sure.

If his computer's DNS cache had been poisoned, wouldn't setting it to use Google DNS have no effect?

Seems like it would have to be his router's DNS cache that is poisoned. Am I correct here?

I asked him if other computers in the house are having problems, he seems unsure about that.

Thanks
 

My Computer

System One

  • OS
    Windows 8 Pro
It is possible the router got compromised.

Cybercriminals compromise home routers to attack online banking users | PCWorld

I've seen multiple instances of this in 7 forums where people had the same problem your friend did (pop ups that won't go away, misdirections, etc.) & in most instances, flushing the DNS solved the problem. That's the reason I suggested it might be DNS poisoning. If you changed the settings to Google DNS, then it would set up new parameters that void the original DNS settings.

If everything is running fine, then you can either leave it or follow through with your plan & reset the router as well as flush the cache. Also check to see if there are any firmware updates for the router.

Your friend needs to let you know if the other PC's are indeed running fine. Malware (if present) can easily spread from one PC to the other.
 

My Computer

System One

  • OS
    Win 7 32, Win 7 64 Pro, Win 8.1 Pro
    Computer type
    PC/Desktop
    System Manufacturer/Model
    It's a Dell, Dude.
    CPU
    Intel Caffinated Core Duo
    Motherboard
    Father is bored too.
    Memory
    4 GB
    Graphics Card(s)
    NVidia something-or-another
    Monitor(s) Displays
    24" HD TV/Monitor/Alternative Dimensional Viewing Portal
    Screen Resolution
    Fuzzy after a couple drinks
    Hard Drives
    2 or 3, depending on if it's a night they're arguing about having a "split personality crisis" because I partitioned the drive.
    Case
    Don't get on my case....man
    Cooling
    Scotch on the rocks on the weekends..
    Keyboard
    Mad Catz Cyborg V7. Or maybe Cyborg Catz Are Mad At V7's??? I know it lights up...far out.
    Mouse
    currently being stalked by the cat...
    Internet Speed
    Never fast enough...
    Browser
    Defeated by Mario...wait...OH...BRowser...
    Antivirus
    Various
Back
Top