Windows Recover Virus, Check this Please

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by JClaytor, Apr 9, 2011.

  1. JClaytor

    JClaytor Private E-2

    When I turned my computer on this morning I had apparently got the WindowsRestore virus. I looked around all morning trying to find something to fix it. I have McAfee on my computer but apparently it bypassed it.

    First thing I tried was going into Safe Mode and running McAfee. I did this and it found a couple of track cookies and 1 bad file. Then I went back over to normal mode. When doing this the initial screen that showed up for the Recover Virus did not show up, the window that appeared to be a virus protection program. So I thought that had worked, however the Critical error warnings kept coming up. Then the computer automatically restarted.

    So then I went back into Safemode and searched for some more information. I ended up downloading the Malwarebytes Anti-Malware Software. I ran this while in Safe-Mode and it found some stuff. I will post the log at the end of this post so you all can look at it. I can understand some of it but I do not know a ton about this stuff, so I would like you all to review and let me know if everything is gone.

    I then switched back to normal mode. Since then it appears that the computer is running fine and I cant seem to find anything realy wrong other than the fact that on my computer (Dell Laptop with Windows 7) The top bar on the desktop is missing and I dont know how to bring it back. Other than that everything is running alright as of right now.

    Here is the Log for the Anti-Malware software. Please let me know what you think and if you think that I need to do anything else.

    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org

    Database version: 6320

    Windows 6.1.7600 (Safe Mode)
    Internet Explorer 8.0.7600.16385

    4/9/2011 12:55:18 PM
    mbam-log-2011-04-09 (12-55-18).txt

    Scan type: Full scan (C:\|D:\|E:\|)
    Objects scanned: 333713
    Time elapsed: 29 minute(s), 2 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 1
    Registry Data Items Infected: 2
    Folders Infected: 1
    Files Infected: 6

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\tfHEwclbGi (Trojan.FakeAlert) -> Value: tfHEwclbGi -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    Folders Infected:
    c:\Users\Claytor\AppData\Roaming\microsoft\Windows\start menu\Programs\windows restore (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    Files Infected:
    c:\programdata\tfhewclbgi.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    c:\Users\Claytor\AppData\Local\Temp\adobe_flash_player.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
    c:\Users\Claytor\AppData\Local\Temp\ldr7faa.tmp (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
    c:\Users\Claytor\AppData\Local\Temp\Low\tmp756D.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    c:\Users\Claytor\AppData\Roaming\microsoft\Windows\start menu\Programs\windows restore\uninstall windows restore.lnk (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    c:\Users\Claytor\AppData\Roaming\microsoft\Windows\start menu\Programs\windows restore\windows restore.lnk (Trojan.FakeAlert) -> Quarantined and deleted successfully.
     
    Last edited: Apr 9, 2011
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds