Vista Recovery Virus

Discussion in 'Software' started by TonyTronic, Jun 1, 2011.

  1. TonyTronic

    TonyTronic Private E-2

    Been fighting this Recovery virus that just popped up. Able to stop it and un hide my program files, but can't get my Office shortcuts back under the program folder. Any ideas??:cry
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    What Service Pack is your Vista or OS at?

    Are you completely sure you have no more malware on your PC? if you are not 99.9% sure then run the below as written.

    But if you are sure then I would run the Office Detect and Repair option (in Help menu or add/remove) or reinstall Office again, I've been a bit vague due to not knowing the actual version of Office you are using to give you precise location of repair.

    What version of Office and its Service Pack do you have?
     
  3. TonyTronic

    TonyTronic Private E-2

    Thanks for the help. I ended up having to just perform a system restore, more things were missing when I started using computer. Now going back to what this laptop was back when I first received it. Running Vista 64 office 2007. Did not think of what you mentioned, thanks again for the help.

    TT
     
  4. mcsmc

    mcsmc MajorGeek

    This appears to be a new rogue antivirus scam malware. I'm currently removing it from a friend's machine. Needless to say, he got it from browsing pr0n.
     
  5. thisisu

    thisisu Malware Consultant

  6. mcsmc

    mcsmc MajorGeek

    SAS removed the virus. However, it was more trouble than it was worth to completely rebuild the Start menu's Program .lnk files, as all of them were deleted (not hidden, like all personal files were). So, I saved the personal files (after removing the virus) and did a simple reinstall of the OS.
     
  7. thisisu

    thisisu Malware Consultant

    i've heard about that, surprised Grinler doesn't mention it in this specific tutorial, but he normally recommends people to disable their antivirus before running unhide.exe iirc. Something to do with the anti virus software... But i think even then there's a chance that it won't restore the start menu.
     
  8. TonyTronic

    TonyTronic Private E-2

    What I did wrong is run SpyBot Search and Destroy first, which deletes out temp folder and that is what did me in, This virus hides folders and moves all the stuff to temp folders. So first you kill it in Task Manager mine was (4560034.exe) Then you run MBAM, then you goto folders tools and show hidden files and folders so you can see everything, and try to undo the mess it creates. BTW I wasn't surfing porn I was reading Drudge Report and this just started running somehow. I've beefed up my security settings and updated Avast, and made new backups. I don't like leaving system restore on because seems viruses like to go there, so I make one image when running good then turn it off. Just try to think of it as a learning experience, now I have a few more tools that I didn't have before. Always have up to date backups.

    TT
     
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    A properly installed layered-protection setup/safe browsing habits/keeping your OS patched and software updated should allow System Restore to remain enabled without creating restore points of your OS that contain an infection.
    - a nice "Stop-gap" to have, in between creating full-system images.

    dr.m
     
    Last edited: Jun 7, 2011
  10. Rocktot

    Rocktot Private First Class

    A virus from Drudge? That would be big news. Like huge.
     
  11. satrow

    satrow Major Geek Extraordinaire

    Probably cross site scripting (XSS), an advert or image loaded from an outside server that's been infiltrated. Most of those can be prevented by running something like NoScript in the browser.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds