Thanks Broni, I also was infected with this windows recovery virus/malware on my XP home edition machine. This forum was of great help. I was able to remove the virus, and was able to get the contents of all my file folders unhidden and visible again, I had the black desktop background with no icons, that was 99% restored, the only thing that did not come back was image I had selected for the background but that is easy to reset. The problem I have is that all of my program folders are still empty (start - programs -and I will see the programs names like "Google Earth" but every single one is empty. That includes the accessories and system tools as well.
The programs are still there, many of them had shortcuts on the desktop and I can start them with start run browse to program files and find them that way. So far to get them back I have tried unhide.exe (helped restore the hidden files but the not the programs). I ran regsvr32 /i shell32.dll, and rebooted, that did nothing.
I did run the system look file, and I have pasted the results below this.
I went into C:\Documents and Settings\user_name\Local Settings\Temp\smtmp\1 and there were all the names of the program folders that used to be on my start - programs, but each of those folders is empty with nothing in them, when I click on properties, it says the folder has zero bytes. I was reluctant to copy these over and have not done so yet. I noted in this thread you asked the other victim if they had deleted any temporary files. In the hours before I found this thread I ran registry mechanic and I think it cleaned out a ton of temporary files. Unfortunately, none are in the recycle bin so I can't tell if the empty folders actually had something in them before.
Do appreciate your help, thanks very much for your time
EDIT - a little while later - I managed to restore most of the programs. I had to run an undelete program to find all the temp files my registry mechanic deleted. I was then able to copy those that pertained to the start program menu into the folders recommended and voila, most, not all came back. For some reason the folder for accessories and system tools does not show up, and while they exist in the recovered undeleted files, those folders are empty. I looking at pasting in their locations from another computer I have..
ANOTHER EDIT - I got a little more of it back. I went start properties (right click) and switched from the classic view to the regular XP view. That brought my accessories folder back . The accessories folder now has everything except communications is empty, system tools is empty except for internet explorer, what it is doing there I have no idea. SO stll missing a bunch of tools notepad, system restore, etc.
C:\DOCUME~1\Owner\LOCALS~1\Temp\smtmp\1\Programs\Realtek d------ [00:41 25/05/2011]
C:\DOCUME~1\Owner\LOCALS~1\Temp\smtmp\1\Programs\Realtek\REALTEK GbE & FE Ethernet PCI-E NIC Driver d------ [00:41 25/05/2011]
C:\DOCUME~1\Owner\LOCALS~1\Temp\smtmp\1\Programs\Registry Mechanic d------ [00:41 25/05/2011]
C:\DOCUME~1\Owner\LOCALS~1\Temp\smtmp\1\Programs\ScanSoft PaperPort 9.0 d------ [00:41 25/05/2011]
C:\DOCUME~1\Owner\LOCALS~1\Temp\smtmp\1\Programs\Seagate d------ [00:41 25/05/2011]
C:\DOCUME~1\Owner\LOCALS~1\Temp\smtmp\1\Programs\Seagate\SeaTools for Windows d------ [00:41 25/05/2011]
C:\DOCUME~1\Owner\LOCALS~1\Temp\smtmp\1\Programs\Second Copy 2000 d------ [00:41 25/05/2011]
C:\DOCUME~1\Owner\LOCALS~1\Temp\smtmp\1\Programs\Skype d------ [00:41 25/05/2011]
C:\DOCUME~1\Owner\LOCALS~1\Temp\smtmp\1\Programs\Smada 6.0 d------ [00:41 25/05/2011]
C:\DOCUME~1\Owner\LOCALS~1\Temp\smtmp\1\Programs\Spybot - Search & Destroy d------ [00:41 25/05/2011]
C:\DOCUME~1\Owner\LOCALS~1\Temp\smtmp\1\Programs\Startup d------ [00:41 25/05/2011]
C:\DOCUME~1\Owner\LOCALS~1\Temp\smtmp\1\Programs\SUPER © Version 2010.bld.38 (May 2, 2010) d------ [00:41 25/05/2011]
C:\DOCUME~1\Owner\LOCALS~1\Temp\smtmp\1\Programs\WD SmartWare d------ [00:41 25/05/2011]
C:\DOCUME~1\Owner\LOCALS~1\Temp\smtmp\1\Programs\Windows Live d------ [00:41 25/05/2011]
C:\DOCUME~1\Owner\LOCALS~1\Temp\smtmp\1\Programs\Windows Media d------ [00:41 25/05/2011]
C:\DOCUME~1\Owner\LOCALS~1\Temp\smtmp\1\Programs\Windows Media\Utilities d------ [00:41 25/05/2011]
C:\DOCUME~1\Owner\LOCALS~1\Temp\smtmp\1\Programs\WinRAR d------ [00:41 25/05/2011]
C:\DOCUME~1\Owner\LOCALS~1\Temp\smtmp\1\Programs\WinTopo Pro d------ [00:41 25/05/2011]
C:\DOCUME~1\Owner\LOCALS~1\Temp\smtmp\1\Programs\WordPerfect Document Converter 5 d------ [00:41 25/05/2011]
C:\DOCUME~1\Owner\LOCALS~1\Temp\smtmp\1\Programs\WordPerfect Office X3 d------ [00:41 25/05/2011]
C:\DOCUME~1\Owner\LOCALS~1\Temp\smtmp\1\Programs\WordPerfect Office X3\Support d------ [00:41 25/05/2011]
C:\DOCUME~1\Owner\LOCALS~1\Temp\smtmp\1\Programs\WordPerfect Office X3\Utilities d------ [00:41 25/05/2011]
C:\DOCUME~1\Owner\LOCALS~1\Temp\smtmp\1\Programs\ZoneAlarm d------ [00:41 25/05/2011]
C:\DOCUME~1\Owner\LOCALS~1\Temp\smtmp\2 d------ [00:41 25/05/2011]
C:\DOCUME~1\Owner\LOCALS~1\Temp\smtmp\4 d------ [00:41 25/05/2011]
-= EOF =-
This post has been edited by frankthom: 25 May 2011 - 09:47 AM