A couple months ago i came home to my computer and discovered hundreds of ad popups in mozilla firefox. I tried to close them but my computer started to heat up pretty bad and then it just shut down. Everyime I tried to boot it up over the next few days it would crash half way through the boot, so I found my knoppix disc and got linux up on my computer. I ran antivirus from knoppix and it deleted a bunch of stuff and then I was able to boot up in windows. I ran AVG in windows and it found a bunch of viruses and then I installed norton av and it found a bunch of stuff as well and deleted it. However, now firefox and google chrome are broken and reinstalls won't fix them. Embarrassingly I am making this thread by IE, as it is the only browser left on my pc that works. I get popups every now and then even when IE is not running and norton continually reports attacks on my computer named "HTTP Tidserv Request" from various websites, for example from ip address but they change everytime. The attack results form IEXPLORER.EXE
I've seen in other forums that continual HTTP Tidserv Requests from sites such as these indicate a rootkit, but I can't figure out how to fix it. I would rather not have to reinstall windows and I worry that my files might be infected if I put them back on my machine after a reinstall. Any help? Thanks!

Dani AI

Generated

A concise, practical plan to follow after the scans and symptoms reported by — building on the initial pointers from and .

First, stop using the PC on the network and make a full bit‑for‑bit image of the drive before you change anything. An image preserves the current state if a later step makes things worse or if you need to hand the disk to a helper. Work from a separate, known‑clean machine to prepare any tools or rescue media.

Next, run offline scans that operate outside Windows (these are the only reliable way to find malware that hides inside drivers, the boot area, or the kernel). Use a trusted bootable scanner rather than trying more in‑Windows scans first. Two vendor options commonly used for this kind of work are Microsoft Defender Offline and vendor rescue ISOs/KVRT — both let you scan and remove threats from outside the running OS. (Microsoft Defender Offline, Kaspersky Virus Removal/Rescue tools). (learn.microsoft.com)

If the offline scan removes items but problems continue, inspect persistence and live network activity before deleting things by hand. Use Sysinternals Autoruns to find autostart drivers, services, BHOs, AppInit DLLs and Winsock hooks, and use TCPView (or netstat) to map which processes hold suspicious outbound connections. Be cautious: anti‑rootkit output can include false positives; do not delete unsigned drivers or system drivers without verifying them. (Autoruns, TCPView). (learn.microsoft.com)

Repair what you can (for example, run sfc /scannow to restore protected system files) but if kernel/boot drivers are infected or removal leaves Windows unstable, plan a full clean install from known‑good media. Only restore personal documents (no *.exe or installers) and scan those files from a clean machine or with multi‑engine services before returning them. If any step is unclear, stop and get hands‑on help — rootkit cleanup can be risky and, when in doubt, a clean reinstall is the safest path. (How to use SFC /scannow). (support.microsoft.com)

Recommended Answers

All 3 Replies

Welcome to Daniwebb Now go here http://www.daniweb.com/forums/thread134865.html and follow instructions as close as possible then post new thread in that forum. Some one will be along soon to assist you. Please be patient as we are short on volunteers at this time Thank You. Later---

Typically documents and such are rarely infected. Its usually system files and such. Considering the problems you're experiencing it could be difficult to remove things. But malwarebytes is a good tool, there are some rootkit removal tools as well.

To attempt safebackup of your stuff, run a linux boot cd and copy your important stuff to a usb stick or usb hdd (i wouldnt recommend a network share). Avast antivirus can scan the stick/drive before booting up windows. so install that, then have it scan the drive before booting the OS.

please delete

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.