Cleaning an infected Windows 7 PC


After work this evening, a family friend has presented me with a challenge. The challenge,![biohazard](http://www.blairkennedy.com/sites/blairkennedy.com/ files/biohazard.jpeg) that I have chosen to accept, is to clean and disinfect a brand new Toshiba Satellite L45 with Windows 7 operating system.&nbsp_place_holder; Once again, I continue to be floored at the rampant use of administrator rights and only relying upon UAC for protection within Windows.

Anyway, here is how I tackled it.&nbsp_place_holder;

Since the symptoms are recurring after a restart, it is either a bootsector issue or part of the Windows startup sequence.&nbsp_place_holder;&nbsp_place_holder;

  1. &nbsp_place_holder;Boot the system from a clean, trusted source.&nbsp_place_holder; I am using the Trinity Rescue Kit v3.3.&nbsp_place_holder; This is the version that I handy.
  2. Run a ClamAV scan, ‘virusscan’, and see what happens.
  3. Boot into Windows safe mode
  4. In looking at ‘msconfig’ in Windows, there is a program named 97688846 executing from c:\ProgramData\97688846\97688846.exe.&nbsp_place_holder; This looks like the old Security Tool trojan.
  5. Remove references in the registry under HKEY_LOCAL_MACHINE and HKEY_CURRENT_USER
  6. Delete the files associated with the trojan.
  7. Reboot the Windows into normal mode
  8. So far, so good.&nbsp_place_holder; The system starts normally now. The next step is to update the virus tools and signatures.&nbsp_place_holder; This will be a secondary verification that the system is clean.

The system passes a full scan with updated software and signatures.&nbsp_place_holder; Another security tool trojan removed.