Solved

Removing Redirect Virus and Hardware Error Messages (related to virus?)

Posted on 2012-03-15
6
580 Views
Last Modified: 2013-11-22
I have a Windows 7 computer that had several infections on it.  Malwarebytes and Trojan Remover took care of most of them.  I also slaved the hard drive to another computer running Malwarebytes again and TrendMicro and was unable to find anymore so I thought the computer was clean.  Turning the computer on, I'm now getting hardware error messages (could be separate from infection) and a redirect virus.

Event Viewer started producing a repetitive hardware error saying: "The driver detected a controller error on \Device\HardDisk0\DR0"

I booted the computer into CleanMode and found the original hardware error stopped but two other messages are popping up now:

"Name resolution for the name renewanadiaper.com timed out after none of the configured DNS servers responded" and "The file system structure on the disk is corrupt and unusable.  Please run the chkdsk utility on the volume"

The chkdsk runs keeps saying there are no errors found, ran it anyway and didn't see any issues, and disk management says the hard drive is healthy.

Windows Update isn't able to complete an update and Google search links redirect me to different sites.  I've also factory reset Internet Explorer, double checked the Hosts file for any random entries, and made sure TCP/IP settings are set to obtain automatically.

How can I get rid of this redirect virus?  And is there any way it could be affecting hardware error messages in Event Viewer?
0
Comment
Question by:LlewellynIT
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 30

Expert Comment

by:IanTh
ID: 37725248
run ipconfig /flushdns

Its in the local resource cache
0
 
LVL 30

Accepted Solution

by:
IanTh earned 500 total points
ID: 37725267
I would run a linux boot cd antivirus that gets away from windows as I have seen a lot of virus's that windows antivirus applications cannot delete as the virus is masquerading as a system file

see
http://www.techmixer.com/free-bootable-antivirus-rescue-cds-download-list/
0
 
LVL 8

Expert Comment

by:Tymetwister
ID: 37726218
You might want to give Kaspersky and/or Eset a try and see if they can pick anything else up. Malwarebytes is great but a lot of trojans are designed to avoid detection from it.

Also, you may want to run an sfc /scannow to replace/repair any system files that may have become damaged from the infection.
0
Threat Trends for MSPs to Watch

See the findings.
Despite its humble beginnings, phishing has come a long way since those first crudely constructed emails. Today, phishing sites can appear and disappear in the length of a coffee break, and it takes more than a little know-how to keep your clients secure.

 
LVL 69

Expert Comment

by:Callandor
ID: 37729138
You will want to run a rootkit detector to get rid of those viruses - TDSSKiller is recommended http://support.kaspersky.com/faq/?qid=208283363.  You also should run more than one malware program, since no single program catches all viruses.
0
 
LVL 12

Expert Comment

by:Grant1842
ID: 37734884
And all so get combofix.
http://www.combofix.org/download.php
0
 

Author Closing Comment

by:LlewellynIT
ID: 37739112
Thanks so much for that great link for the Rescue CDs!  AVG found several Trojans and Kaspersky found the RootKit that kept the computer from normal operation.  Don't see any hardware errors anymore either.
0

Featured Post

U.S. Department of Agriculture and Acronis Access

With the new era of mobile computing, smartphones and tablets, wireless communications and cloud services, the USDA sought to take advantage of a mobilized workforce and the blurring lines between personal and corporate computing resources.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The Windows functions GetTickCount and timeGetTime retrieve the number of milliseconds since the system was started. However, the value is stored in a DWORD, which means that it wraps around to zero every 49.7 days. This article shows how to solve t…
An introduction to the wonderful sport of Scam Baiting.  Learn how to help fight scammers by beating them at their own game. This great pass time helps the world, while providing an endless source of entertainment. Enjoy!
This Micro Tutorial will give you a introduction in two parts how to utilize Windows Live Movie Maker to its maximum editing capability. This will be demonstrated using Windows Live Movie Maker on Windows 7 operating system.
If you’ve ever visited a web page and noticed a cool font that you really liked the look of, but couldn’t figure out which font it was so that you could use it for your own work, then this video is for you! In this Micro Tutorial, you'll learn yo…

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question