Help with Windows Restore Virus on Win 7

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by etl13, Jun 10, 2011.

  1. etl13

    etl13 Private E-2

    Hello, I'm a newbie at this forum, but I suddenly encountered the windows restore virus earlier today. Upon seeing messages of hard drive failure, I contacted Dell (still in Warranty) and the chap, after much ado, indicated that it truly was a hardware failure, despite my initial description of Mcafee catching and disabling a trojan just prior to failure. After this diagnoses (and the possible loss of a lot of data), I started surfing and came upon a couple of sites that described this virus--exactly what i saw. The first site on Youtube showed how to remove the virus--which I did (involving deleting some files with strange names). Afterwards, I saw your threads and decided to follow your instructions (with the exception of two steps). I tried to follow closely all of the instructions in READ & RUN...The only steps that I had trouble with were Combofix--when I tried to install it(after disabling Mcafee), I got a message that the program was not for Win 7, so I skipped it. The other step was one that I forgot--I forgot to disable CD Emulation using Defrogger.
    I was able to run successfully (at least to me) SuperAntiSpyware, Malwarebytes, and MGTOOLS (seemed a bunch of errors in MGTOOLS).
    SuperAnti---found 4 instances of a virus and 360+ cookies--I quarantined them. Malware... didn't find anything and MGTOOLS went to the indicated end. I will tag the log files for the 3 programs I ran. I also Toggled system restore. Several Questions:

    1) I seem to have successfully gotten rid of the virus. However, there are a bunch of programs on the Start menu - Programs that Indicate empty files--however I can call up the program--ie, Microsoft Word--I can't see the program, but when I click on a doc file, it opens up in word... I also ran Unhide but this didn't help.

    2) Several directories are protected from me--I cannot get into them even when logged in as an Administrator---I fear the virus screwed around with protections. Is there any way to run a system restore to say 1 month ago--would that help?

    3) Finally, When I toggled System Restore, I saw the C drive and a Recovery Partition--I clicked on that and it was already toggled off. After rebooting, I restored the use of system restore to that partition. Was that correct or should I have designated the C: drive?

    I'm sorry that this is long and didn't follow completely your instructions. Any guidance to my cleanup problems would be welcomed. I'm seriously considering backing up all of my data and reinitializing the whole system--it is only one year old and not much was on it. I'd prefer not to, given i would lose some programs...

    Thanks for your help. Regards, Eric L.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. etl13

    etl13 Private E-2

    Hi TimW,

    Sorry it took a couple of days to respond, but I tried to follow your instructions:

    1) When I clicked on your Avenger link (after allowing download to my system), I got a blank screen. I then googled the avenger by swandog469 website and downloaded it directly from there.

    2) I then ran analyse and looked for the line you wrote out--with
    reference to UYhaQsSEGdkYay but it was not there--i searched thoroughly.

    3) I exited HJT and then created fixme.reg and ran it successfully. it added the script to the registry.

    4) Then ran Avenger and copied and executed the script u wrote. It ran successfully and asked for a reboot. Upon reboot, i searched the entire c drive for avenger.txt and couldn't find it. it was not in the root directory.
    NOTE-- my Mcafee software popped up and said they had removed a trojan.

    5) I the ran getlogs.bat and created the mglogs.zip. I have enclosed.

    6) I don't seem to have the virus. However, as before, a lot of programs on the start menu show as empty (although I can run them by clicking on a file with correct extension. I have unhidden everything i can. My last resort is that Dell is coming with a new hard drive with a factory image and i will start over, having backed up all files. Only thing is I must reinstall the programs that I added to this machine. Not so worried about doing this, but it is a pain. Have others experienced the same degradation in accessing programs?

    Regards, Eric L.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's see if we can get some of those programs back by having you do this:
    Please download and save the below to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it. Now see if you can find your Programs and how are the icons on the Desktop looking?

    Now, let's try with this:

    Download OTM by Old Timer and save it to your Desktop.




    Code:
    :Processes
    explorer.exe
    
    :Services
    houdl
    
    :Files
    C:\ProgramData\UYhaQsSEGdkYay.exe
    C:\yruxbfqh.txt
    C:\Windows\System32\drivers\houdl.sys
    C:\Windows\SysWOW64\drivers\houdl.sys
    
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\UYhaQsSEGdkYay]
    
    :Commands
    [purity]
    [ResetHosts]
    [createrestorepoint]
    [emptytemp]
    [start explorer]
    [Reboot]

    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.


    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * OTM log
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!

    If some of your program icons are not opening the programs, you may just need to re-install those programs. If everything is ok, then you should clean out these folders:
    C:\Users\home\Local Settings\TEMP
    C:\Windows\TEMP\
     
  5. etl13

    etl13 Private E-2

    Hi TimW,

    I performed the following steps:

    1) I ran Unhide (actually ended up running it 2). I did notice that some programs ended up on my desktop--they had been there before the virus and then had disappeared.

    2) I then ran OTM as suggested. I did not get to copy the results before the reboot and cannot find them. I have attached the log and the mgtools log.

    3) Upon reboot, 2 things (possibly unrelated) were noticed: When I clicked on Explorer on my toolbar, came back with a message that program had been removed and asked me if i wanted to remove it?? I pressed no, but the icon on the toolbar then disappeared. Also, noticed a message from Malwarebytes that something from Skype had been blocked --is it possible that this was the original source of the Malware? I don't remember seeing such a message from Macafee.

    4) Although I can pretty much run the programs on my pc, when i click on Start>All programs--when i click on numerous programs previously installed, they are indicated as EMPTY. Programs (such as Malwarebytes and SuperAntispyware ) that were installed after ridding myself of the virus are ok and visible. My best bet is a reinstall--that is going to be done today. I sincerely thank you for your efforts--I hope that some of the information I've given u helps in diagnosis for others.

    Regards,

    eric l.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you planning on doing a complete reformat and reinstall? Or are you just trying to do a repair install?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds