System Restore Tab Missing

Discussion in 'Malware Help (A Specialist Will Reply)' started by chuckj, Mar 13, 2006.

  1. chuckj

    chuckj Private E-2

    This computer is running windows xp, sp2. When I right click "My Computer" and then Properties, there is no System Restore tab. If I go to "Start", "All Programs", "Accessories", "System Tools", "System Restore", I get the message:

    "System Restore has been turned off by group policy. To turn on System Restore, contact your domain Administrator".

    The System Configuration Utility, under the Services tab, indicates that System Restore Service is running. I am logged in with administrative privileges but don't have access to the System Restore function. I am trying to remove malware using the tutorial but some infection remains on the computer.

    I hope this post makes sense and I greatly appreciate any help. Thanks
     
  2. AbbySue

    AbbySue MajorGeeks Administrator

    Welcome to MajorGeeks chuckj.:)

    I moved your thread to the Malware forum as it is quite possible the malware you have/had is causing the issue with your system restore tab being missing. The malware fighters will be able to better assist you with this issue.

    If you have completed the steps in the READ & RUN ME FIRST Before Asking for Support please attach the scan results from the following so they can assess the problem:

    Bitdefender
    Panda Scan
    HijackThis
     
  3. chuckj

    chuckj Private E-2

    Scanned logs are attached. The Bitdefender scan is the first scan. A scan since then shows that infected files are in a restore directory. The Panda scan and HijackThis scan were completed a few minutes ago. Thanks. ChuckJ
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to attach the Bitdefender log.

    Why are you running with no antivirus and no firewall applications. This is very dangerous!!

    Please run the below procedure too:

    EGDAccess Removal

    After running the above some items from below may no longer exist. That's okay, just ignore and complete the steps.
    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [avnort] C:\WINDOWS\msmbw.exe
    O4 - HKLM\..\Run: [zzzHPSETUP] D:\Setup.exe \RESET
    O4 - HKLM\..\Run: [serpe] C:\WINDOWS\System32\serbw.exe
    O4 - HKLM\..\Run: [ltwob] C:\WINDOWS\System32\formatsys.exe
    O4 - HKLM\..\RunServices: [avnort] C:\WINDOWS\msmbw.exe
    O4 - HKLM\..\RunServices: [ltwob] C:\WINDOWS\System32\formatsys.exe
    O4 - HKLM\..\RunServices: [serpe] C:\WINDOWS\System32\serbw.exe
    O16 - DPF: {1CD49DC9-FD88-41FA-B892-47E037267D45} - http://akamai.downloadv3.com/binaries/EGDAccess/EGDACCESS_1059_XP.cab
    O16 - DPF: {BFC9677B-8006-4336-9D49-2C797AEFCB9E} - http://akamai.downloadv3.com/binaries/EGDAccess/EGDACCESS_1058_XP.cab
    O16 - DPF: {E3943A24-2F83-4505-9AE5-F705E81B50CB} - http://akamai.downloadv3.com/binaries/EGDAccess/EGDACCESS_1055_XP.cab

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\msmbw.exe
    C:\WINDOWS\System32\serbw.exe
    C:\WINDOWS\System32\formatsys.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  5. chuckj

    chuckj Private E-2

    The attachments are the HJT log after following the instructions in the previous message and a Bitdefender scan log also done after following the previous message instructions. The computer appears to be operating normally. However, I still don't have access to the "System Restore" tab. This computer is running windows xp, sp2. When I right click "My Computer" and then Properties, there is no System Restore tab. If I go to "Start", "All Programs", "Accessories", "System Tools", "System Restore", I get the message:

    "System Restore has been turned off by group policy. To turn on System Restore, contact your domain Administrator".

    The System Configuration Utility, under the Services tab, indicates that System Restore Service is running.

    Can you lead me in the right direction to get access to the "System Restore" function. It's as if I were logged in without administrative privileges. Thanks. Chuck J.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still see the below in your log. Did you forget to fix this? Try again:
    O4 - HKLM\..\Run: [zzzHPSETUP] D:\Setup.exe \RESET

    Is it gone now? Is the D drive your CD ROM?

    Not sure yet what is going on with System Restore tabs but can you access system restore via msconfig?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the below for the System Restore problem.

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixSR.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixSR.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
     
  8. chuckj

    chuckj Private E-2

    I cleaned up the line "O4 - HKLM\..\Run: [zzzHPSETUP] D:\Setup.exe \RESET" from the HJT log and yes, the D drive is a CD Rom drive. An updated HJT log is attached. I also used the script you sent to me and the Restore System tab was accessible when I right clicked My Computer and Properties. I turned System Restore off and rebooted. I did another Bitdefender scan and nothing was found. So it looks like the computer is clean now. However, when I looked for the Restore System tab to turn it back on, is wasn't there. I ran the fixSR.reg file again but the System Restore tab still does not appear. Do you have any further suggestions. My next steps are to install anti-virus and firewall software. Thanks so much for your help. Chuck J.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try this! First disable (or uninstall if necessary) both Windows Defender and SpySweeper. Then try running the registry patch again. Let me know what happens. If you get an error message, tell me the exact error message.
     
  10. chuckj

    chuckj Private E-2

    I re-ran the registry patch after uninstalling Windows Defender and Spy Sweeper. Still no System Restore tab. When accessing through My Computer - Properties, there is no tab. When accessing through Start - All Programs - Accessories - System Tools - System Restore, the following message appears: "System Restore is not able to protect your computer. Pleast restart your computer, and then run System Restore again." Otherwise, there is no error message. I have tried restarting with the same results. The computer appears to be operating normally. Chuck J.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you know whether System Restore is currently enabled or disabled?

    I think we are going to have to Disable the service and then rename the System Volume Information folder. Then reboot and then enable System Restore. This should create a new System Volume Information folder. I think yours is corrupted.


    To stop the service do the below.

    • Click Start, Run and enter services.msc and then click OK. This will bring up the Services window.
    • Scroll down to System Restore Service and double click on it.
    • In the next windows changed the Service status to Stopped by click the Stop button
    • The change the Service type: to Disable
    • Then Apply and OK
    • Now reboot your PC
    • After reboot (makes sure viewing of hidden & system files is enabled) and run Windows Explorer and locate the folder named System Volume Information Right click on the folder and select rename. Change the name to Old Restore
    • Now reboot again
    • No run services.msc again but this time set the System Restore Service Status to Started and set the Type to Automatic.
    Now let me know how things are looking. If this does not work, you will have to check what the guys in the Software Forum suggest. This is not a malware problem.
     
    Last edited: Mar 15, 2006
  12. chuckj

    chuckj Private E-2

    I followed the instructions given to me, but when I try to rename the System Volume Information folder, I get the following error message: "Error Renaming File or Folder. Cannor rename System Volume Information: Access is denied. Make sure the disk is not full or write-protected and that the file is not currently in use." The folder is set to Read Only, but I can not change it. Should I go on over to the Software section? If yes, thank you so very much for all the assistance you have given me. Chuck J.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is System Restore disabled?
    Has the Service been stopped and disabled?

    If you answer no to the above, you definitely will not be able to rename the folder.
     
  14. chuckj

    chuckj Private E-2

    I have stopped System Restore in services.msc and the Service status indicates stopped. Also, in the Startup type box, I have chosen Disabled, then Apply, then OK. The System Restore Service line in service.msc indicates Disabled. But I still cannot change the Read Only attribute of the System Volume Information file to enable me to change the name of the file. I unselect the Read Only box, click Apply and OK, but when I check afterward, the Read Only box is selected. Do you have any further suggestions? I surely appreciate your efforts. Thanks. Chuck J.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I think it may be best for you to try getting help on this in the Software Forum. At this point I'm not sure that trying to renamed the System Volume Information folder is even a good idea since other things besides System Restore are located there. Right now I'm not sure why the previous registry patch I had you apply did not work. I guess could be that the registy patch was not successful because various registry keys are not owned by you and thus you do not have premission to change them.

    Two more things to try and then I'm out of ideas:

    Idea 1
    • Download Registrar Lite and install it!
    • Copy and paste the below into the Address box of registrar lit and hit the Enter key.

      HKEY_LOCAL_MACHINE

      Then click the Security pull down ont the top menu and choose Take Ownership. Click OK in the next window to approve it.
    • Copy and paste the below into the Address box of registrar lit and hit the Enter key.

      HKEY_CURRENT_USER

      Then click the Security pull down ont the top menu and choose Take Ownership. Click OK in the next window to approve it.
    • Now exit Registrar Lite
    • Go back to message number 7 and reapply the registry patch.
    • Any change?
    Idea 2

    Only one more thing I can suggest before you go to the Software Forum, run services.msc, and changes the System Restore Services to be Started and Automatic. Then reboot and see if there is any change with the missing tab.
     
    Last edited: Mar 16, 2006
  16. chuckj

    chuckj Private E-2

    I tried the two ideas and neither of them worked. I will check with the software section to see if they can help. At least the computer seems to be clean now and that is so mush better than before and I thank you so much for all the help that you have given. Chuck J.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome and good luck! Let me know if you find out the solution. As I said in the past that registry patch as always worked so there is something different happening on your PC. You may need to run sr.inf in the C:\windows\inf folder. Someone in the Software section may mention this. I'm not sure if it would help or not right now.
     
  18. chuckj

    chuckj Private E-2

    I ran the sr.inf file and that took care of my problem. The System Restore tab is available in My Computer - Properties and I can access the System Restore Service through Start -All Programs-Accessories-System Tools-System Restore. Everything appears to be working normally now. Thanks so much for all the help you provided and your patience. Chuck J.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I glad I had one last trick up my sleave! ;)

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds