Link to home
Create AccountLog in
Avatar of Bruce Corson
Bruce CorsonFlag for United States of America

asked on

Strange malware issue with Win 7

A client's Win 7 Home laptop will not fully start in normal mode. It takes a very long time to get to the point where one is given a choice of user accounts. Also, at that point it starts playing music and news announcements, jumbled together.

In safe mode I have been able to run rkill, followed by Malwarebytes. I found just two things with that (sorry I didn't make note of what). Restarted, ran rkill and ESET online scanner. Found nothing. Then Roguekiller, then tdsskiller, then Superantispyware.

It is still slow-starting, does the music/news thing, and won't start in normal mode.

Suggestions?
Avatar of Haresh Nikumbh
Haresh Nikumbh
Flag of India image

with in month 3 machine infected with virus.

other ppls tried all the option but it fixed only after reinstalling os

please refer below link

https://www.experts-exchange.com/questions/28163786/Computer-plays-radio-stations-by-itself.html

https://www.experts-exchange.com/questions/28177082/My-Windows-7-lapop-started-playing-streaming-sound-ads.html

so i will suggest format and reinstalled OS .
(Just to) Try:

Malwarebytes Anti-Rootkit:

http://www.malwarebytes.org/products/mbar/ > and

Combofix:

http://www.bleepingcomputer.com/download/combofix/ >
Have you disabled all startup and Services items with msconfig to see if that will allow normal boot mode?
ASKER CERTIFIED SOLUTION
Avatar of nobus
nobus
Flag of Belgium image

Link to home
membership
Create a free account to see this answer
Signing up is free and takes 30 seconds. No credit card required.
See answer
Avatar of Bruce Corson

ASKER

Finally got it. I ran every malware solution I've got, including tdsskiller, and it still wasn't fixed, as of last night. The final try was ESET's system rescue program (you boot from that), and it appeared to get it, then the strange music and news came back. I uninstalled the existing Kapersky 2012 AV in preparation for installing ESET NOD32, and the music went away, but the system still froze in normal mode.

I then did a system restore to several weeks ago, booted to safe mode, ran tdsskiller, and it found something it hadn't found before, which was indeed a rootkit. I've now had it on for several hours and it is behaving. ESET NOD32 is finishing up an initial scan and all appears to be okay.

Thanks for all the advice.
tx for the feedback