Windows XP Restore mess

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Pakuni, Jun 12, 2011.

  1. Pakuni

    Pakuni Private E-2

    Apologies if this has been covered, but I've searched around the forums a bit and while I've spotted several similar threads regarding this virus, my issues seem somewhat unique. Perhaps of my own doing, I'm afraid, but maybe someone smarter can me can be the judge of that.

    First, I'm running Windows XP home.

    Problems started yesterday when the Windows XP Restore virus reared its ugly head. I recognized if for what it was right away, didn't click on anything I shouldn't and ran an rkill followed by Malwarebytes full scan. Unfortunately, I was optimistic - overly so, it now seems - that this would solve the issue, so I didn't save the logs and can't get to them now (more on that later). MBAM found about 10 infected files, I had them removed/quarantined and then followed the instructions to reboot.
    So far, so good.
    On reboot, however, Windows popped up in a blue screen telling me to run a CHKDSK, which I did. After that ran, Windows came up but the vast majority of my desktop icons, programs and files were missing. I ran bleepingcomputer's unhide.exe, which returned what appeared to be all my files.
    I happily went about my business from there, thinking I'd resolved this when, a short while later, an icon for Windows XP Restore reappeared on my desktop. So, I repeated the steps above (again, didn't save the logs, sorry), MB found one infected file this time and I rebooted.
    Now here's where the real problems start. Upon reboot (after another CHKDSK) the Windows XP Restore remains, along with a couple other icons, but most icons and files are again missing. I'm getting Google redirects from IE, Firefox won't open (get a message telling me it's already running, which according to my task manager it isn't), I can't open/run any potential fixes (such as ComboFix, TDSSKiller) and IE won't allow me to download any of those potential fixes or open them off a CD. Also, even among the files that do appear, I can't open any ... thus I can't recover the old mbam or rkill logs.

    So, that's where I'm at. I've dealt with a couple of nasty viruses/malwares in the past and eventually figured it out , but this one has left me clueless and near hopeless. At this point, I'd take it if I could just recover my files, though I hope for better.

    At present, I'm on a work computer, so hopefully I can download any fixes here to run at home if need be, but again, it's not even letting me run programs off CDs. I'm putting them (Combofix, SAS, TDSSkiller, etc.) on a flash drive now, so maybe that will make difference.

    Any help/direction/advice would be much, much appreciated.

    Thanks and, again, apologies if this is something that's been dealt with previously.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try this first:
    You can restore the defaults for the Start Menu, Accessories and Administrative Tools as follows:
    READ & RUN ME FIRST. Malware Removal Guide
     
  3. Pakuni

    Pakuni Private E-2

    Thanks for responding, Tim.

    Unfortunately, I can't open or download that file. When I try to save it, I get a message reading "Internet Explorer cannot download accrestore.zip from www.winxptutor.com. Internet Explorer was not able to open this Internet site. The requested site is either unavilable or could not be found. Please try again later."

    When I attempt to open it, there's simply no respomse.

    Also, as I mentioned earlier, I was downloading various scans, etc. omto a flash drive. But now my computer won't recognize/open that drive. When I try to open, I get a message telling me to insert the drive. The drive is already inserted, obviously.

    Any other suggestions would be much appreciated.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try a different browser for the link which will not work for you?

    Then if the flashdrive method is not working, use a disk instead?
     
  5. Pakuni

    Pakuni Private E-2

    My other browser, FF, won't open, and my system won't let me save anything onto the hard drive or an external drive. The programs on the flash were downloaded while I was at work. I'm at home now.

    Thanks for responding.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What about safe mode with networking?
     
  7. Pakuni

    Pakuni Private E-2

    Maybe. I'd need someone who knows what they're doing to walk me through that.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  9. Pakuni

    Pakuni Private E-2

    OK, thanks for your patience.
    Just so I'm clear, when I restart in Safe Mode, I should then try to go about the steps listed below (i.e. restoring defaults then the malware removal steps)?
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  11. Pakuni

    Pakuni Private E-2

    Sorry for delay in getting back, but things have gone from bad to really bad.
    When I attempted to reboot in safe mode, I got the dreaded unmountable_boot_volume message and can do nothing at this point. I'm searching around for my XP reinstall disc (to no avail), hoping that can get Windows back up and running.

    I'll let you know how that goes.
    In the meantime, any suggestions?
    Thanks.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can try posting in the software forum to try to get the Unmountable boot issue addressed. If you can find your install CD, that would be helpful. Let us know how you make out.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds