Got hit with Windows Recovery and now Anti Spyware 2012

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by keebler7, Jul 5, 2011.

  1. keebler7

    keebler7 Private E-2

    My desktop uses Windows XP service pack 3 and it was hit with the Windows Recovery Virus back in March of this year. I looked up removal guides and ended up downloading and using Malware to delete the virus or so I think. It was no longer blasting my screen with fake alerts but all of my programs and files were hidden and no matter how many times I did the steps to unhide my files nothing changed.

    Earlier today I was blasted with pop ups from XP Anti Spyware 2012 and it was doing basically the same thing as Windows Recovery. I did not download, register, or buy into it, I knew it was a virus right away. I am currently running my computer in safe mode because the virus and the residual effects from the first virus prevent me from using any of the virus removal programs like Malware.

    I did read the guideline posts like I was instructed to but because I am handicapped by the first virus I am unsure just where I should start. I would greatly appreciate any help!
     
    Last edited by a moderator: Jul 6, 2011
  2. thisisu

    thisisu Malware Consultant

    Hi! Welcome to Major Geeks!

    Can you please go into more detail on what happens when you try programs like SUPERAntiSpyware, MalwareBytes, ComboFix?

    Do the programs not launch at all after you attempt to open it?
    Do you get some type of error message after you attempt to open it?

    Are you still having issues with seeing your Desktop Icons, Start Menu, Program Files, etc?
    Is this why you can't run any programs?
     
  3. keebler7

    keebler7 Private E-2

    I can not run any programs in regular mode because the first virus has hidden everything so that the folders are "empty" so the programs won't run. Every time I try to unhide my files and programs nothing changes.

    I am running it in safe mode now and I can run MalwareBytes in safe mode. I don't know if that matters.

    I still have some of my icons on my desktop in regular mode but XP AntiSpyware 2012 will not let me run those.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download and save the below tool from Grinler @ bleepingcomputer to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it. Now see if you can find the items that seemed to be missing?

    If you have already done this, try this:

    You can restore the defaults for the Start Menu, Accessories and Administrative Tools as follows:

     
  5. keebler7

    keebler7 Private E-2

    I tried both of those tips and the second option help bring back the rest of my Accessories but when I go to to my programs from the Start Menu it still shows everything as empty and will not run. I went to C:/Program Files to run things like Mozilla Firefox, Sims 3, Leap Frog, Malware Bytes, and so on.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We need you to run the requested scans. If you can't run them in normal mode, try them in safe mode.

    Then attach the logs:
    SAS
    MBAM
    ComboFix
    RootRepeal -- if it runs.
    C:\MGLogs.zip
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run unhide.exe exactly as requested?
     
  8. keebler7

    keebler7 Private E-2

    Yes, I followed the instructions as listed
     
  9. keebler7

    keebler7 Private E-2

    Malwarebytes is the only program I have from your list so attached is the log for the scan.
     

    Attached Files:

  10. keebler7

    keebler7 Private E-2

    I just sat down at the computer a little bit ago and when I tried to open Firefox the XP virus popped up in safe mode. It would not allow me to run McAfee or Malwarebytes. I looked for any kind of program to run and I discovered that I do have ComboFix which I was able to run. I saved the log and tried to attach it but it said it's too big. I am still running in safe mode and able to get on the internet for the time being.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run MGtools.exe as requested in the instructions and attach the c:\MGlogs.zip file. It will automatically compress the ComboFix.txt log and put it into the ZIP file as long as the C:\ComboFix.txt log was properly created
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds