BleepingComputer.com: Windows Recovery Virus

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
  • 3 Pages +
  • 1
  • 2
  • 3
  • You cannot start a new topic
  • This topic is locked

Windows Recovery Virus Windows Recovery Virus creates "empty" programs

#31 User is offline   Dmichael 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 20
  • Joined: 03-May 11

Posted 17 May 2011 - 07:53 AM

Hi Gringo,

I just followed all of the last steps. Thanks. I now have few questions:

1. Since all of my log's and the software we used is still on my computer, can I remove?

2. I tried to create a 'system restore' point, but if I go under 'programs/accessories/system tools' the 'system tools' folder is (empty). This is true on 90% of all my folders that I go to out of the 'start/all programs' menu. All of the shortcut executible files are gone. Do you know how I can restore these? The only way I can get into any of these programs is by going into C: drive and program files folder and find their 'exe.' files. I have used unhide.exe, but it doesn't restore the links. This includes all of my printer files, games files, start up files, itunes, etc... They all show as (empty). this is obviously very frustrating.

3. Can you tell me what of the following 'service updates' I can get rid of (if any) to free memory?

Microsoft .NET Framework 1.1
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 Service Pack 1
Microsoft .NET Framework 4 Client Profile

Microsoft Visual C++2005 Redistributable
Microsoft Visual C++2005 Redistributable
Microsoft Visual C++2005 Redistributable KB 2467175
Microsoft Visual C++2008 Redistributable ATL Update kb973924-x86 9.0.30729.4148
Microsoft Visual C++2008 Redistributable kb 2467174-x86 9.0.30729.5570
Microsoft Visual C++2008 Redistributable -x86 9.0.30729.17

Some of the above take up a decent amount of memory. It would be great to get rid of some outdated updates that might still be lingering.

I really appreciate everything you have done so far. If I can now get those executibles back so my 'all programs' menu is functioning, that would be awesome. If I have overstayed my welcome on this thread, I totally understand.

Thanks!

DM

#32 User is offline   gringo_pr 

  • Bleepin Gringo
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 85,462
  • Joined: 03-July 08
  • Gender:Male
  • Location:Puerto rico

Posted 17 May 2011 - 08:33 AM

Hello

1. Since all of my log's and the software we used is still on my computer, can I remove?
delete any that is still on the desktop

2. I tried to create a 'system restore' point, but if I go under 'programs/accessories/system tools' the 'system tools' folder is (empty). This is true on 90% of all my folders that I go to out of the 'start/all programs' menu. All of the shortcut executible files are gone. Do you know how I can restore these? The only way I can get into any of these programs is by going into C: drive and program files folder and find their 'exe.' files. I have used unhide.exe, but it doesn't restore the links. This includes all of my printer files, games files, start up files, itunes, etc... They all show as (empty). this is obviously very frustrating.

I want you to delete the unhide.exe you now have and redownload a new one from here - http://download.bleepingcomputer.com/grinler/unhide.exe

if it does not work then they are gone and you have to make new shortcuts or reinstall the programs

3. Can you tell me what of the following 'service updates' I can get rid of (if any) to free memory?

this I am not sure about - but can be asked in the windows forum as they should know

gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic


Please Only Copy And Paste Reports Into Topic - Do Not Attach

My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->Posted Image<-- Don't worry every little bit helps.

#33 User is offline   gringo_pr 

  • Bleepin Gringo
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 85,462
  • Joined: 03-July 08
  • Gender:Male
  • Location:Puerto rico

Posted 20 May 2011 - 02:22 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic


Please Only Copy And Paste Reports Into Topic - Do Not Attach

My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->Posted Image<-- Don't worry every little bit helps.

Share this topic:


  • 3 Pages +
  • 1
  • 2
  • 3
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users