Chris,
I see that you've likely exhausted your cleanup options besides re-installing Windows, which in the case of multiple unknown infections is typically the best course of action anyway. So from here the point is to try avoiding the same problems in the future.
In the past I had played with various tools like the hosts file, though I avoided alternative browsers for the reason that any software added to a system simply adds to the potential vulnerabilities as well, since all software and especially browsers inherently
have these. Unfortunately, though a hosts file may deal with relatively static sites, it doesn't help with the dynamically changing websites from which many of the malicious items are delivered today.
Also note that the browser which Microsoft security applications protect most effectively is always the latest version provided with that operating system. Any 3rd-party browser will require the security add-ons which perform similar functions to those
included with Windows 7 such as SmartScreen Filter (anti-malware/phishing) and the close integration that Microsoft Security Essentials provides with Internet Explorer for scripting and downloads. All of this simply adds to the support burden, which may
be ok if it's your personal PC, but doesn't scale well when multiple PCs are being managed individually.
If you want to keep a Windows 7 system as tightly secured as possible, the best methods are to invoke the various built-in configuration items that Microsoft has chosen to keep lax for reasons of compatibility and simplicity for users. There are only a
handful of these, but they can have a great impact most especially on the security of the browser and downloads regardless of the source.
First, if the software normally installed on the PC is limited to the core Windows applications and major name software applications like Office or Adobe products, it should be possible to configure Windows - Data Execution Prevention to "Turn on DEP for
all programs and services except those I select". This setting is found under Control Panel, System, Advanced System settings, Performance Settings button, Data Execution Prevention tab.
This DEP setting is compatible with most recent software, but since it doesn't allow badly behaved software that attempts to execute code in data areas, some malware will be blocked by this setting as well.
The next setting can improve the security of Internet Explorer 11 on Windows 7, but only if it's the 64-bit version which you didn't specify above. This is the Enable Enhanced Protected Mode setting in the IE11 Internet Options, Advanced tab, security section.
Though this Enhanced Protected Mode (EPM) blog article was written when it was first released with Internet Explorer 10 on Windows 8, the descriptions and operation are functionally the same with IE11 on 64-bit Windows 7.
In general, the EPM setting runs everything in Internet Explorer in 64-bit mode by default, causing 32-bit add-ons to fail to run and blocking many things that are badly behaved due to various protections it includes which the article details. This causes
many of the less well written attacks on the browser to fail, which since malware is often written as quickly and simply as possible, is more common than you might think.
None of the above settings will stop a PC user from downloading or trying to install software either on purpose or due to social engineering, but they just might manage to block some of this from successfully installing or changing the system when they do,
especially the drive-by exploits often used to quietly install undesired software.
There's another pair of settings I use that blocks most of the advertising networks which are often used to deliver both the browser hijacker type of pop-ups, as well as some drive-by downloads, and operates similar to the popular AdBlock extension. This
uses the "Send Do Not Track requests to sites you visit in Internet Explorer" setting in Internet Options, Advanced tab, security, in tandem with the free to install EasyPrivacy Tracking Protection list in manage Add-ons.
Though this combination does aid in blocking some of the advertising network delivered malicious attacks including many of the seemingly random pop-ups, it of course also blocks much of the targeted advertising these same networks provide. So if your users
actually want these ads this may not be an effective method, but if they all use the same user account, then personalization may not matter and this also has the side effect of blocking many of these often annoying ads altogether or at least limiting them
to a single static box.
You might still want to try combining the MVP hosts file with some of these other protections, but since the above are either a one-time setting or in the case of the EasyPrivacy tracking protection list automatically updated by the IE11 browser itself,
they don't require any manual maintenance as is the case with the hosts file.
Rob