Windows Restore Virus/Trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by ncroots, Apr 12, 2011.

  1. ncroots

    ncroots Private E-2

    Hi, I've been trying to fix my husband's laptop (Gateway, Windows Vista, 32bit) which got the Windows Restore Virus yesterday when he clicked on an email attachment that he, obviously, shouldn't have. I have followed ALL of your instructions to the letter I believe and the virus itself with the pop ups seems to be gone (it was only on his user account, not on my user account as administrator). I am having the same problem as Crimsoncuda though. His user account desktop is black and many of the icons are missing. My administrator account screens are fine. Everything else seems to be fine now.

    I had only one problem with one piece of software in the Malware instructions and that was with RootRepeal. It froze the computer up after only a few minutes. I deleted it, rebooted, reloaded and tried again with the same result. I deleted the program again and moved on to MGtools which worked fine.

    Thanks in advance for any further help you can provide. Nancy.

    Here are my logs:
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run the cleaning procedure on your husbands user account while logged into his account and without using Run As Administrator. What you did was effectively to run many of the scans on your user account. Attach new logs after doing this. SUPERAntiSpyware and Malwarebytes may or may not find anything this time, but we really need to see the logs to be sure. However ComboFix and MGtools being run either as administrator or from your user account are not that useful in addressing problems with your husbands user account. Change your husbands account to an administrator account and then run the scans.
     
  3. ncroots

    ncroots Private E-2

    OK, thanks Charles, I'll try it all again! I'll repost here when I finish.
    This is exhausting! :tired
     
  4. ncroots

    ncroots Private E-2

    Hi Charles, thanks for your patience. I made my husband's account an "administrator" account as you suggested and ran EVERYTHING from that account when I re-did this. Again though, RootRepeal again did not work. It froze up again about 10-15 minutes in. I didn't touch it though, I let it sit there for another hour to make sure. It was frozen.

    Anyway, attached are the new logs run just now. I don't see any more problems but I certainly don't profess to know how to read the reports. I'll leave that to you experts.

    By the way... I'd like to personally thank you and the rest of the gals and guys at MajorGeeks. I've been lucky to have had you there with me through these frustrating events since 2004. For a non-geek you are life savers, angels, and just downright good people who actually care about us knuckleheads getting our computers fixed right. I know that we don't always know what you are talking about when we try to follow your instructions (which are really very good) but we try. Your stickys are really great and I know that they were born out of your frustration with us, the general public, asking the same dumb question time after time. You've made it work and it is a great system you've set up. Thanks. Nancy.
     

    Attached Files:

  5. ncroots

    ncroots Private E-2

    The last log...
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome Nancy. :)

    Your logs are clean but let's just do the below to remove some leftovers before getting to final instructions.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
    O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)

    After clicking Fix, exit HJT.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
    You can also set your husbands user account back to limited user account now. ;)
     
  7. ncroots

    ncroots Private E-2

    Done, thanks again Charles!!!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds